nowfound

Alternatives

Products that do what Mugiwara Security does

Proves vulnerabilities before reporting them.

  1. 1

    Pentest and patch every deploy with AI

    Jun 2026

  2. 2

    Get a pentest done, today.

    Dec 2025

  3. 3
    ETHIACK133

    24/7 offensive security testing with 99% accuracy

    2023

  4. 4

    Real-time compliance & security validation for AI coding

    Dec 2025

  5. 5
    Tracea80

    Datadog for AI agents with traces, RCA, and team memory

    May 2026

  6. 6BP

    I've been researching the bot & proxies space for years. I slowly incubated a service to protect public forms, contents and APIs. It recenty reached a few million daily requests and I now dare to bring it to light. Truesign detects bots, proxies/vpns and fake emails, through a single request from the browser, without challenges or user interaction. It can block the request based on rules you choose, or grant a token with encrypted information about the visitor for you to decide. I created a few pages to showcase how it works: - https:/demo.truesign.ai/protected-form : a form…

    Oct 2025 · truesign.ai

  7. 7

    Catch secrets before they leak into Cursor & Claude

    Jul 2026 · heimwall.ai

  8. 8

    Security Scanner for AI-generated Code

    7d ago · scanity.dev

  9. 9

    The CI gate that says no to unapproved AI code

    18d ago · linebreakapp.com

  10. 10MS

    Hi HN, I've been building MCPSpec, an open-source CLI for MCP server reliability. Record sessions, generate mock servers, catch Tool Poisoning, and fail your CI build when something's wrong — without writing test code. There are ways to validate MCP servers today — the MCP Inspector, ad-hoc SDK scripts, unit tests for server internals — but nothing that handles regression detection, security auditing, mock generation, and CI pass/fail checks in one tool. MCPSpec does that: 1. Record a session against your real server, replay it after changes to catch regressions 2. Generate a standalone…

    Feb 2026 · light-handle.github.io

  11. 11CA

    Hello HN! I built a pre-commit code scanner that checks your staged changes for security vulnerabilities every time you run 'git commit'. I am an inexperienced programmer and this is my first personal project. Any feedback, positive or negative, big or small, relevant or not, would be greatly helpful and appreciated! The tool requires Gitleaks and Python to run, you will also need to use your own AI API key, which I understand is a big setup friction. You can check out my demo video instead if that is more convenient: https://youtu.be/ZYe5vWFRTus?si=9Fv8DhTHktwDK4mV Thank you…

    Jun 2026 · github.com

  12. 12

    Provenance scan for files sent to you — free, in seconds

    26d ago · seenpool.com

  13. 13TT

    Hey HN, this is deepan from trulytyped (https://trulytyped.com). I am building a document writing app which makes it extremely easy to figure out how a document was created. Now that any text can be AI generated, how do you tell if something was actually generated or composed. It is impossible to detect AI after a piece of text has been generated. No amount of watermarking, linguistic checks or vibe checks work consistently. The AI detectors that schools and journals use are easy to bypass. Why do we need to solve this problem - First of all, this is not an anti-AI stance. I have…

    May 2026 · trulytyped.com

  14. 14WS

    http://webscanner.tk/quickscan/ Hi! I made this project over the couse of a week to help teach myself more about Django and web app development. I am studying computer security in school and web security is one of my passions. It is a tool that helps web developers ensure that they have implemented helpful security mechanisms like HTTPOnly flags, X-Frame-Options, etc. There are hundreds of tools that offer to scan websites for things like cross-site scripting, mySQL injection, etc. This tool simply looks for information that is available via one or two GET requests (the headers, protocols,…

    2013

  15. 15

    Prove your agent actually did the work

    3d ago · provedone.gumroad.com

  16. 16IB

    For the last 6 months, I've been building ORUS Builder, an open-source AI code generator. My goal was to fix the biggest issue I have with tools like v0, Lovable, etc. – they generate broken, non-compiling code that needs hours of debugging. ORUS Builder is different. It uses a "Compiler-Integrity Generation" (CIG) protocol, a set of cognitive validation steps that run before the code is generated. The result is a 99.9% first-time compilation success rate in my tests. The workflow is simple: 1.Describe an app in a single prompt. 2.It generates a full-stack application…

    Nov 2025

  17. 17

    Scan AI-built apps. Get prompt-ready fixes.

    3d ago · codanopy.com

  18. 18

    Redact PII locally and in realtime before it leaks to GenAI.

    8d ago · dataanonymiser.com

  19. 19MR

    Hi HN, I'm Vlad. I've been building MCP servers and related tooling for a while now, and I kept hitting a class of bug that no unit test caught: someone on the team renames a tool parameter or tweaks a tool description, all the tests pass, but the AI agent that was calling that tool silently breaks. This happens because the model reads tool descriptions and parameter schemas to decide which tool to call and how, so a renamed parameter or a reworded description isn't just a cosmetic change — it directly affects the model's behavior. The MCP spec doesn't have tool versioning available yet, and…

    Mar 2026 · github.com

  20. 20

    Make any LLM find real bugs in your code, and prove them

    8d ago · redmirror.io

  21. 21KI

    Hey HN, As an AppSec engineer, I’ve spent a lot of time running and tunning open-source security scanners like Trivy, Semgrep, Gitleaks and Dojo. What I have found is that running them is easy, reviewing the results, not so much. Each tool outputs different JSON, false positives pile up, and CI either becomes noisy or blocks everything. So I built Kekkai (formerly Hokage), a small open-source CLI that wraps these scanners and focuses specifically on human triage. Kekkai runs the scanners in isolated Docker containers, normalizes their outputs into a single format, and provides an interactive…

    Feb 2026

  22. 22FO

    Hey HN, We built FireClaw because we kept watching AI agents get owned by prompt injection through web content. The agent fetches a page, the page says "ignore previous instructions," and suddenly your agent is leaking data or running commands it shouldn't. The existing solutions detect injection after the fact. We wanted to prevent it. FireClaw is a security proxy that sits between your AI agent and the web. Every fetch passes through a 4-stage pipeline: 1. DNS blocklist check (URLhaus, PhishTank, community feed) 2. Structural sanitization (strip hidden CSS, zero-width Unicode, encoding…

    Mar 2026 · github.com

  23. 23

    Test what your AI didn't.

    12d ago · marucheck.dev

  24. 24
    SPIF2

    Signed, tamper-evident provenance for AI outputs

    9d ago · github.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →