
AskLedger — Cut your AI spend, and prove the savings are real
扫描AI账单找出浪费支出,用防篡改证据证明节省成本。
@askrashidkhan · X
完整作品展
技术栈
16 projects

扫描AI账单找出浪费支出,用防篡改证据证明节省成本。
@askrashidkhan · X

监控外部攻击面,自动检测安全漏洞和暴露点。
@tugayakin34 · X
ThreatPort is an all-in-one Cyber Threat Intelligence & Attack Surface Management platform

免费的网站安全扫描器,检查 SSL、headers 和合规性,提供即时的信任分数和 AI 指导的修复。
@MrPenetratorTP · X
MrPenetrator helps businesses monitor their website’s trust, security and performance before problems affect their visitors.

Free SAST, DAST, and infrastructure vulnerability scanning with automated CMMC, HIPAA, SOC2, and ISO27001 compliance reports. Built for developers, security teams, and MSPs.
@AuditBastion · X
Built something worth testing? Scan it with

SecureWatch是一款免费网站安全扫描器,包含75+漏洞测试、WAF保护和SSL监控。
@rapidrewind0 · X
2nd link is still in development

使用硬件认证和OTP保护GitHub拉取请求。
jallmann · HN
> want without a PR process that requires hardware authentication or proof of presence Just curious, what do you use for this? I built OTP Guard [1] a few years ago for exactly this problem, although I haven't seen any alternatives in the space. Does GitHub have something built-in now? The original framing was more "local malware compromising your GitHub account" ... it never occurred to me that the malware could be a LLM. I really should update the page. [1] https://otpguard.com

使用AI增强的安全分析扫描代码和应用漏洞。
u/swifi_ai · Reddit
After 10 years of keeping this idea alive, I finally launched my AI security platform to beta After more than 10 years of keeping this idea alive in one form or another, I finally pushed Swifi live to beta: https://swifi.ai Swifi is an AI-augmented application security platform. The goal: combine traditional security scanning with AI so teams can understand risk across code, vulnerabilities, and production context without stitching together a dozen disconnected tools. Why now? AI change

监控你的 Supabase 日志,查找凭证填充和暴露的密钥等安全问题。
@DefencecorHQ · X
Your app has been live for months. Your last log check was launch day. Defencecore monitors your Supabase activity and surfaces what needs attention—so you don’t have to live in the logs. #vibecoding #ai #supabase

在攻击者利用前,发现你的 external attack surface 中的风险。
@OGVeilScan · X

Sift Q 是供人和编程代理共享的追踪工具,支持原子性声明和前置条件阻止。
u/Scary-Philosopher-77 · Reddit
Linear on crack! I had the issue where when I do dev work in a group, it feels like that I am moving slower when I do work alone. I tried to use linear but I still had issues with task orchestration and having to manually manage tickets created more issues. Over the course of a few month I built SiftQ which is what I wished Linear to be. It solves the pain of: Feel like you'd genuinely move faster if you just worked solo. Get overwhelmed by 100s of tickets and don't know what is

Etch: 追踪、重放和验证AI代理的决策,提供签名审计线索。
u/Funky_Chicken_22 · Reddit
OSS to SaaS positioning problem: when the user persona and the buyer persona are completely disjoint Founder here. Sharing a positioning problem I think a lot of OSS-to-SaaS founders hit and don't talk about publicly. Context: I have been running an OSS project (world-model-mcp) with ~2,500 monthly PyPI installs. Two weeks ago I opened up the hosted companion, Etch, at etch.systems. Launched publicly on Product Hunt at 12:00 PDT yesterday. The positioning problem: OSS user persona: in

输入网站 URL 进行安全扫描,获得漏洞评分和修复建议。
@korisecurity · X
What we have now: Vibe coding -> Vibe testing -> Vibe marketing -> Vibe users -> Vibe subscriptions. You may do all but don't Vibe Secure! Scan for those open ports, missing DKIMs or CVEs. Use a professional tool