
Stashbase | Secrets management for developers
为应用和团队安全管理密钥和环境变量。
@radimhfer · X
i'm founder of Stashbase, designed to help builders
完整作品展
技术栈
60 projects

为应用和团队安全管理密钥和环境变量。
@radimhfer · X
i'm founder of Stashbase, designed to help builders

扫描AI应用发现安全和代码质量问题,自动生成GitHub修复。
@LaunchGuardHQ · X
I'm an HVAC installer, not a developer. Built LaunchGuard nights & weekends with AI coding tools. It scans AI-built apps for leaked API keys, wide-open databases, and vulnerable dependencies — then opens a real GitHub PR with the fix.

分析开源 GitHub 项目的健康指标、漏洞和质量数据。
Koimiao · V2EX
做了个小工具,可以从各个维度评估一个 GitHub 项目,想请大家拍砖 找开源项目时,我们常常会先看 Star 、README 和最近一次提交。如果你是独立开发者,正在维护自己的开源项目,也想知道怎么让自己项目更健康、被更多人看见,第一步该从哪里做起? 所以最近我做了一个小项目:TrustOSS http://trustoss.org 输入一个 GitHub 仓库链接,TrustOSS 会把这些公开信号整理成一份可读的仓库健康报告:活跃度、维护情况、社区、文档与成熟度评分;也可以进一步查看漏洞、CI 、真实依赖者、维护者集中度和 Star 异常情况。 想要评估一个开源项目,或者维护自己的开源项目,想知道短板在哪里,都可以直接试试(是免费的!

为GitHub仓库运行安全审计,检测密钥泄露、认证问题和部署漏洞。
@emanueldev4 · X
Building Preflight a simple way to catch issues before your website goes live.

自动扫描代码变更,发现安全问题和代码质量缺陷。
@RepoMend02 · X
Vibe-coded your MVP in a weekend? Cute. RepoMend reads every diff and hunts the secrets your AI forgot to redact. The auditor the AI forgot to build.

审计AI应用的安全漏洞,获取完整检测报告。
u/mrtrly · Reddit
I asked ChatGPT 20 different ways who could fix a half-built app. It never named my company once. I do codebase rescue for founders in exactly that spot, so that one stung. There are already plenty of tools that measure this kind of AI visibility, a CDN even ships one free, so I built mine mostly to see my own number, and it confirmed the bad news: near zero. The measuring turned out to be the easy part. What none of the tools do, and what I actually care about, is the fix: getting the mode

输入公司网址分析 WHOIS、SSL 等信号来生成信任评分。
@CoderJiii · X
🚀 Just launched Veris — a platform that helps verify company legitimacy using WHOIS, SSL, website, contact, social, and legal checks to generate a Trust Score & Risk Level. 🌐 #BuildInPublic #OpenSource #FullStack #React #NodeJS

Find security holes in your AI-built app before hackers do. StackSecured scans for exposed keys, injection flaws, CVEs and more — with copy-paste fixes.
@djdeepakjha · X
AI can build your startup in days. But who checks the security? Public configs. Weak APIs. Exposed secrets. If AI built your app, scan it before someone else does. 🔒 StackSecured — security assessment #CyberSecurity #VibeCoding #AppSecurity

VibeLint 为 AI 代理提供代码检查、权限控制和审批工作流。
@RElharrak39428 · X

使用 MonoCloud 为应用添加认证,支持通行密钥、SSO 和多因素验证。
roguetink · Product Hunt
MonoCloud for Startups One identity layer for your customers, APIs, and agents

检查AI代理输出和操作是否符合策略,获得批准、拒绝、重写或升级决定。
u/danielbaker06072001 · Reddit
Most AI agent SaaS is just bad security with a nice dashboard Give a new employee access to Stripe, GitHub, Slack, and your CRM on day one, and you’d call it reckless. Give the same access to an AI agent, and we call it “autonomous.” That isn’t innovation. It’s skipping basic security because the demo looks cool. Full disclosure: I’m building TrustLoopGuard around this problem, so I’m obviously biased. While testing one MCP connection, I realized I had decided what the agent could a

SlopStopper - 扫描应用的生产就绪问题,如安全性、功能性和可靠性。
u/jjd921 · Reddit
Production readiness checker With AI coding and the low barrier to entry now I see a ton of people publishing apps with serious issues. I tried to build something to help with this. It’s a tool that checks apps for production-readiness issues (security, functionality, reliability, accessibility, etc.) and creates a GitHub PR with the fixes. Automatic scans on every push/PR and deterministic auto-fixes are completely free. Do you see something like this being useful?: https://theslopstopper.c