16,215 packages matching “hardcoded-secrets”
sealight
v0.1.4 · 1 year ago
CLI tool to detect hardcoded secrets and sensitive data in codebases.
No known vulnerabilities
codedrift
v1.2.12 · 5 months ago
Guardrails for AI-assisted development - Detects IDOR, missing input validation, hardcoded secrets, and other critical bugs in AI-generated code
No known vulnerabilities
rakshak-cli
v1.2.0 · 27 days ago
Open-source vulnerability scanner for your code. Detects SQL injection, XSS, hardcoded secrets, command injection, and more across 20+ languages. Fully offline with zero external API calls.
No known vulnerabilities
@j0kz/security-scanner-mcp
v1.1.1 · 8 months ago
Security Scanner MCP - Detect vulnerabilities, hardcoded secrets, SQL injection, XSS, and OWASP Top 10 issues. Works with Claude Code, Cursor, Windsurf, Roo Code, and any MCP-compatible editor.
No known vulnerabilities
@gourav094/secret-scan
v2.0.1 · 4 months ago
CLI tool to scan for hardcoded secrets, API keys, tokens, and passwords
No known vulnerabilities
kafkacode
v1.5.0 · 2 months ago
Open-source, local-first privacy code scanner for PII leaks, hardcoded secrets, GDPR/CCPA compliance, SARIF, and CI/CD
No known vulnerabilities
vibe-to-docker
v5.2.2 · 8 months ago
Fully automated Docker containerization for AI-generated projects. One command handles container setup, dependency installation, and security fixes. 24 features addressing 82% dependency conflicts, 60-70% environment mismatches, 48% hardcoded secrets in L
No known vulnerabilities
@m8t-jacob/mcp-guard
v0.1.0 · 29 days ago
Static security scanner/linter for MCP (Model Context Protocol) servers: detects tool poisoning, prompt-injection surfaces, hardcoded secrets, command injection, and excessive permissions in server source code and tool manifests. CLI + GitHub Action, SARI
No known vulnerabilities
@rtwsvj/skill-switch
v0.10.0 · 25 days ago
Security audit for AI agent skills & MCP configs (reverse shells, exfiltration, dangerous MCP servers, hardcoded secrets) → SARIF/code-scanning; plus cross-agent skill governance for Claude Code, Cursor, Gemini CLI, Windsurf, Zed.
No known vulnerabilities
shieldline
v0.1.9 · 3 months ago
Security scanner for vibe-coded apps — catches hardcoded secrets, unprotected routes, weak JWT secrets, unverified webhooks, and more before you deploy
No known vulnerabilities
@akshitkrnagpal/env-doctor
v0.2.1 · 4 months ago
A .env file auditor for developers — detect unused vars, missing vars, hardcoded secrets, env drift, and more
No known vulnerabilities
pinocscan
v1.3.2 · 4 months ago
Security scanner for agent skill files - detects command injection, unsafe file operations, hardcoded secrets, and code injection risks
No known vulnerabilities
secretsaudit
v1.0.0 · 4 months ago
Zero-config CLI that scans node_modules for hardcoded secrets, API keys, tokens, and passwords
No known vulnerabilities
@pulumi/esc-sdk
v0.14.0 · 1 month ago
NodeJS SDK for Pulumi ESC
No known vulnerabilities
secretscan
v1.0.2 · 1 year ago
A CLI tool to scan for hardcoded secrets
No known vulnerabilities
@aws-sdk/client-secrets-manager
v3.1108.0 · 1 hour ago
AWS SDK for JavaScript Secrets Manager Client for Node.js, Browser and React Native
No known vulnerabilities
@buildbench/mcp-security-scanner
v1.1.0 · 2 months ago
Static security scanner for Model Context Protocol (MCP) servers. Detects tool-description poisoning, exfiltration cues, hidden-unicode payloads, arbitrary command execution, SSRF surface, hardcoded secrets, and rug-pull risk. Runs locally for Cursor and
No known vulnerabilities
sast-scan
v2.1.0 · 4 months ago
A lightweight, extensible Static Application Security Testing (SAST) tool for JavaScript. Detects vulnerabilities like XSS, SQL injection, hardcoded secrets, prototype pollution, and more — with CWE references, severity ratings, and context-aware reportin
No known vulnerabilities
@azure/keyvault-secrets
v4.11.2 · 3 months ago
Azure Key Vault Secrets
No known vulnerabilities
@felix-neuro/eslint-plugin-routeguard
v0.1.1 · 2 months ago
ESLint plugin for Node.js API security — detects BOLA/IDOR, mass-assignment, SSRF, SQL injection, command injection, path traversal, open redirect, and hardcoded secrets across Express, Fastify, and NestJS.
No known vulnerabilities