nowfound

Alternatives

Products that do what Contract-Guard does

Free and local code, config, dependency and security scanner

  1. 1
    Warestack444

    Agentic guardrails for safe releases

    2025

  2. 2CG

    There is a growing problem with VSCode extensions: - they're not sandboxed (yet) - just like double-clicking an .exe file - they don't have a permission model - they auto update - they have built-in persistence - they are installed on developer machines with high-value credentials The recent CircleCI and LastPass incidents were both suspected to originate from a compromised developer machine - which is becoming every organization's Achilles heel in terms of cyber posture So I've been working on a way to help mitigate some of these risks Right now, only an MVP of a "CLI" is available: $ code…

    2023

  3. 3

    Discuss and understand your code base from within your IDE

    2022

  4. 4VD

    Did you know that VSCode extensions run with full access to your system—including file system, network, and credentials? Worse, dozens of malicious extensions have already made it into the marketplace, silently compromising devices. I am a security researcher and student developer who ran into this problem myself. To help tackle this, I built a 100% free tool (no login required) that scans VSCode (and Cursor/Windsurf) extensions for: - Hidden malware and obfuscated code - Dangerous permissions and API misuse - Vulnerable dependencies and suspicious network connections Users have already…

    2025 · vscan.dev

  5. 5

    An open source security scanner for Visual Studio Code

    2020

  6. 6FL

    Hi HN! We just launched Codacy Guardrails, an IDE extension with a CLI for code analysis and MCP server that enforces security & quality rules on AI-generated code in real-time. It hooks into AI coding assistants (like VS Code Agent Mode, Cursor, Windsurf), silently scanning and fixing AI-suggested code that has vulnerabilities or violates your coding standards, while the code it’s being generated. We built this because coding agents can be a double-edged sword. They do boost productivity, but can easily introduce insecure or non-compliant code. One recent research team at NYU found that 40%…

    2025

  7. 7

    Detect secrets in source code, public and private!

    2018

  8. 8

    Open-Source Security for Vyper Contracts

    Jul 2026 · vyper-web.vercel.app

  9. 9MS

    I noticed the growing security concerns around MCP (https://news.ycombinator.com/item?id=43600192) and built an open source tool that can detect several patterns of tool poisoning attacks, exfiltration channels and cross-origin manipulations. MCP-Shield scans your installed servers (Cursor, Claude Desktop, etc.) and shows what each tool is trying to do at the instruction level, beyond just the API surface. It catches hidden instructions that try to read sensitive files, shadow other tools' behavior, or exfiltrate data. Example of what it detects: - Hidden instructions…

    2025 · github.com

  10. 10

    Security for modern teams running software

    2017

  11. 11

    Open sourced application to detect security vulnerabilities.

    2020

  12. 12

    AI-powered code review, right in your commits.

    Jan 2026

  13. 13

    Instant AI legal analysis for founders & freelancers

    May 2026 · ai-contract-risk-analyzer-ncxs.vercel.app

  14. 14CB

    Hi HN, I’m experimenting with commit-based code review as an alternative to PR-based review. Instead of analyzing large PR diffs, this reviews each commit incrementally, while context is still fresh. It’s fully configurable and intentionally low-noise, high signal - focused on catching issues that tend to slip through and compound over time. The goal isn’t to replace CI or PR review, but to move some feedback earlier: risky changes hidden in small diffs architectural or consistency drift performance or security footguns Happy to answer questions

    Jan 2026 · commitguard.ai

  15. 15

    Track browser extension installations / threats in real-time

    2019

  16. 16DO

    I kept seeing every npm/pnpm/yarn/bun/uv supply chain post end with the same advice (set a minimum release age, turn off install scripts), and while I know cooldowns are "controversial", they do work. But even if you convince people that they should set cooldowns, it seems many don't end up following through, not sure why, maybe because it means hand-editing five config files in five formats with five different time units, or perhaps the "it won't happen to me" syndrome (or "I'll do it later, it seems complicated" where it's actually very simple). So I created a tool that…

    Jun 2026 · github.com

  17. 17AC
  18. 18

    Make Codex prove the diff before risky edits

    Jun 2026 · github.com

  19. 19IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  20. 20MS

    Hi HN! We kept seeing devs get pwned through MCP tools in ways that security scanners completely miss. So we built an open-source analyzer to catch these attacks. Our first OSS by Mighty team. The problem: At Defcon, we saw MCP exploits with 100% success rate against Claude and Llama. Three attack patterns: Hidden Unicode in "error messages" - Paste a colleague's error into Claude, your SSH keys get exfiltrated Trusted tool updates - That database tool you've used for months? Last week's update added credential theft Tool redefinition - Malicious tool redefines "deploy to prod" to run…

    2025 · github.com

  21. 21CM

    I use Claude Code across multiple projects with different conventions and some shared repos just as it so happens to be the real world. Managing the config files (.claude/rules/, mcps.json, settings.json) by hand got tedious, so I built a local web UI for it. This one started out as claude-config but migrated to coder-config as I'm adding others (Gemini, AG, Codex, etc). Main features: - Visual editor for rules, permissions, and MCP servers - Project registry to switch between codebases - "Workstreams" to group related repos (frontend + API + shared libs) with shared context -…

    Jan 2026 · github.com

  22. 22

    Detect Security Threats in Agent Skills

    Jan 2026

  23. 23

    Open source scanner for cross-tenant AI-agent security bugs

    12d ago · github.com

  24. 24

    Audit the VS Code extensions already running on your machine

    12d ago · extguard.pages.dev

Ranked by how close each launch is in meaning, then by votes. Refine with a description →