AI Dev Impact Lab JA
← Topics ranking · 2026-08
GITHUB TOPIC

#sarif

GitHub repositories that have self-applied the topic "sarif" — a creator-tagged metadata that surfaces how AI projects describe themselves.

15
tagged repos
14
top 15 stars
5
with tool sigs
15
shown

REPOS Repos for #sarif (top 15 by stars)

Actenon/actenon-scan

Find where agent-controlled intent reaches consequential actions without an authority check. Python + TypeScript + Go. Zero-dependency SAST for AI agents.

Python 4 AI 70
Renga154/agentrisk

Zero-execution preflight scanner for untrusted AI-agent and MCP artifacts

TypeScript 2 AI 70
FU-max-boop/statebind-guard

Catch visible-but-unbound coding-agent handoffs: CLI + GitHub Action with proof, policy gates, SARIF, HTML, and benchmark cards.

Python 2 AI 60 Solo live ↗
guorunjie/agentic-workflow-guard

Static analysis for AI automation workflows. Find prompt-injection paths, overpowered tools, and write-capable agent jobs before they run.

JavaScript 1 AI 70 Solo 4 sig live ↗
sftrkr/sitepulse

Rust CLI and MCP server for technical SEO, sitemap audits, broken link detection, and AI agent readiness.

Rust 1 AI 70
thedatakey/apollyon

Source code security scanner for human-written and AI-generated projects. Rust CLI with explicit coverage, JSON/SARIF, and coding-agent integrations. Built by Tom Koentjes. Pre-alpha.

Rust 1 AI 70 4 sig
hamodywe/promptfence

Static analysis for AI agents in GitHub Actions — finds where attacker-controlled text reaches an agent's prompt, and what that agent is allowed to do with it.

TypeScript 1 AI 60
Gowrav-M/agentops-watchtower

Local-first AgentOps flight recorder and capability firewall for MCP-based coding agents with OpenTelemetry traces.

TypeScript 1 AI 45
EffortlessMetrics/ripr

Static Mutation Exposure Analysis

Rust 1 AI 20 2 sig live ↗
Gowrav-M/agent-skillguard

Policy-as-code admission controller for AI agent skills and MCP tools. SkillBOM, lockfiles, and supply-chain baselines.

TypeScript 0 AI 100
pierre-cheneau/planproof

Deterministic proof that an AI coding agent built what the plan said it would.

Python 0 AI 70
JSiapoDEV/vibeward

Stops the insecure prompt before your AI agent runs it - and audits what it already shipped. Deterministic Claude Code guardrail (no LLM) catching "disable RLS" or "service_role in the frontend" in en/es/pt, plus a read-only scanner for exposed secrets, open Supabase RLS and Firebase leaks.

TypeScript 0 AI 70 Solo live ↗
scooter-sensei/extant

Your documentation makes claims. This checks whether they are still true, against git and the filesystem. Dead commit references, false merge claims, broken links, tags that never shipped, files that contradict each other. Works on the README you already have.

Python 0 AI 70 1 sig
YoungsPlace/hookhound

Release gate for agent plugins: sniff broken hooks, missing manifests, npm payload mistakes, and SARIF/CI issues before users do.

TypeScript 0 AI 70 Solo live ↗
itsraghul/lockwarden

Audit what your npm dependency tree can execute — lifecycle scripts, binding.gyp, AI-agent hooks, IDE tasks — and answer "am I hit?" in seconds during supply-chain incidents. Local-first, zero telemetry.

TypeScript 0 AI 70 Solo 1 sig live ↗

RELATED Other topics · full topics ranking →

#claude-code

1,564

#ai-agents

1,160

#llm

1,071

#claude

943

#python

806

#ai

741

#developer-tools

728

#mcp

727

#codex

521

Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology