Best tools for Security Auditing
Scanning code and infrastructure for vulnerabilities, compliance, and security best practices
102 tools
listing data updated September 24, 2026 · not a verification date
showing 6 of 102 tools
Sandbox any command with file, network, and credential controls
Zerobox is a security-focused command sandboxing tool that isolates command execution with fine-grained controls over file system access, network connectivity, and credential exposure. It wraps any shell command in a secure container that enforces policy restrictions, preventing unauthorized file reads, network calls, or environment variable leaks during execution.
Google's application kernel for container sandboxing and security
gVisor is Google's open-source container runtime sandbox that provides an additional layer of isolation between containerized applications and the host kernel. It implements a user-space application kernel that intercepts system calls, preventing container escapes and limiting the attack surface. Used in Google Cloud Run, GKE Sandbox, and other Google Cloud services. Over 18,000 GitHub stars.
NVIDIA's LLM vulnerability scanner and red-teaming tool
garak is NVIDIA's open-source LLM vulnerability scanner for red-teaming AI models and applications. Probes for prompt injection, data leakage, hallucination, toxicity, encoding-based attacks, and dozens of other vulnerability categories. Runs automated attack sequences against any LLM endpoint and generates detailed vulnerability reports. Features a modular probe/detector architecture that is extensible with custom attack patterns. Named after the Star Trek character known for deception.
Open-source diagnostic for AI operational misalignment
iFixAi is an Apache-2.0 diagnostic tool for scoring AI agents and models against operational-misalignment risks such as hallucination, manipulation, sabotage, sandbagging, and oversight evasion.
Google's vulnerability scanner using the OSV database
OSV-Scanner is Google's official open-source vulnerability scanner that checks your project's dependencies against the OSV.dev database — the largest open vulnerability database covering all major ecosystems. Written in Go, it supports lockfiles from npm, pip, Maven, Cargo, Go modules, and more, providing actionable remediation guidance and CI/CD integration for automated security scanning.
Static linter that catches production bugs in AI-generated code
prodlint is a zero-config static analysis tool with 52 rules targeting production bugs that AI coding tools consistently produce. It catches hallucinated npm imports, missing authentication checks, Prisma writes outside transactions, exposed secrets via NEXT_PUBLIC prefixes, and other patterns specific to code generated by Cursor, Claude Code, Bolt, and v0. Runs in one second via npx with no configuration needed.
FAQ
How do automated security auditing pipelines combine SAST, DAST, and SCA to detect vulnerabilities?
Static analysis (Semgrep/CodeQL) scans source ASTs for injection flaws, SCA (Snyk/Trivy) checks dependency CVEs, and DAST (OWASP ZAP) probes running endpoints, correlating findings into centralized SARIF reports.
How do AI guardrails detect and mitigate direct and indirect prompt injection attacks in LLM apps?
Dual-boundary classifiers scan user inputs and retrieved RAG context for injection payloads, while output sanitizers verify that model responses do not leak system instructions or sensitive credentials.
What automated controls prevent secrets, private keys, and API tokens from entering git history?
Pre-commit hooks and CI gates run Gitleaks and TruffleHog with real-time API verification, blocking commits containing high-entropy strings and valid credentials.