#sarif
GitHub repositories that have self-applied the topic "sarif" — a creator-tagged metadata that surfaces how AI projects describe themselves.
REPOS Repos for #sarif (top 15 by stars)
Find where agent-controlled intent reaches consequential actions without an authority check. Python + TypeScript + Go. Zero-dependency SAST for AI agents.
Renga154/agentriskZero-execution preflight scanner for untrusted AI-agent and MCP artifacts
FU-max-boop/statebind-guardCatch visible-but-unbound coding-agent handoffs: CLI + GitHub Action with proof, policy gates, SARIF, HTML, and benchmark cards.
guorunjie/agentic-workflow-guardStatic analysis for AI automation workflows. Find prompt-injection paths, overpowered tools, and write-capable agent jobs before they run.
sftrkr/sitepulseRust CLI and MCP server for technical SEO, sitemap audits, broken link detection, and AI agent readiness.
thedatakey/apollyonSource code security scanner for human-written and AI-generated projects. Rust CLI with explicit coverage, JSON/SARIF, and coding-agent integrations. Built by Tom Koentjes. Pre-alpha.
hamodywe/promptfenceStatic analysis for AI agents in GitHub Actions — finds where attacker-controlled text reaches an agent's prompt, and what that agent is allowed to do with it.
Gowrav-M/agentops-watchtowerLocal-first AgentOps flight recorder and capability firewall for MCP-based coding agents with OpenTelemetry traces.
EffortlessMetrics/riprStatic Mutation Exposure Analysis
Gowrav-M/agent-skillguardPolicy-as-code admission controller for AI agent skills and MCP tools. SkillBOM, lockfiles, and supply-chain baselines.
pierre-cheneau/planproofDeterministic proof that an AI coding agent built what the plan said it would.
JSiapoDEV/vibewardStops the insecure prompt before your AI agent runs it - and audits what it already shipped. Deterministic Claude Code guardrail (no LLM) catching "disable RLS" or "service_role in the frontend" in en/es/pt, plus a read-only scanner for exposed secrets, open Supabase RLS and Firebase leaks.
scooter-sensei/extantYour documentation makes claims. This checks whether they are still true, against git and the filesystem. Dead commit references, false merge claims, broken links, tags that never shipped, files that contradict each other. Works on the README you already have.
YoungsPlace/hookhoundRelease gate for agent plugins: sniff broken hooks, missing manifests, npm payload mistakes, and SARIF/CI issues before users do.
itsraghul/lockwardenAudit what your npm dependency tree can execute — lifecycle scripts, binding.gyp, AI-agent hooks, IDE tasks — and answer "am I hit?" in seconds during supply-chain incidents. Local-first, zero telemetry.
RELATED Other topics · full topics ranking →
#claude-code
1,555#ai-agents
1,156#llm
1,066#claude
936#python
802#ai
737#developer-tools
723#mcp
719#codex
517Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology