Alternatives

Tartufo alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Tartufo

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

84
Quality
88
Trust
513
Stars
#1

Nuclei

Similarity 128Trust 98Excellent 100

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.

29K starsJun 13, 2026 pushsecurityGoSecurity
$ npx skills add projectdiscovery/nuclei
#2

Zaproxy

Similarity 127Trust 95Excellent 100

The ZAP by Checkmarx Core project

15K starsJun 11, 2026 pushsecurityJavaSecurity
$ npx skills add zaproxy/zaproxy
#3

Bandit

Similarity 123Trust 94Excellent 100

Bandit is a tool designed to find common security issues in Python code.

8.1K starsMay 25, 2026 pushsecurityPythonSecurity
$ npx skills add PyCQA/bandit
#4

Artemis

Similarity 120Trust 92Excellent 100

A modular vulnerability scanner with automatic report generation capabilities.

1.2K starsJun 13, 2026 pushsecurityPythonSecurity
$ npx skills add CERT-Polska/Artemis
#5

Zap Extensions

Similarity 118Trust 86Excellent 87

ZAP Add-ons

932 starsJun 13, 2026 pushsecurityHTMLSecurity
$ npx skills add zaproxy/zap-extensions
#6

Wpscan

Similarity 117Trust 93Excellent 100

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com

9.6K starsJun 12, 2026 pushsecurityRubySecurity
$ npx skills add wpscanteam/wpscan
#7

Changeme

Similarity 116Trust 84Excellent 85

A default credential scanner.

1.5K starsJul 8, 2025 pushsecurityPythonSecurity
$ npx skills add ztgrace/changeme
#8

Kube Score

Similarity 116Trust 94Excellent 100

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your Kubernetes YAML and Charts. Static code analysis for Kubernetes.

3.1K starsMay 20, 2026 pushsecurityGoSecurity
$ npx skills add zegl/kube-score
#9

Caringcaribou

Similarity 116Trust 86Excellent 87

A friendly car security exploration tool for the CAN bus

918 starsJun 12, 2026 pushsecurityPythonSecurity
$ npx skills add CaringCaribou/caringcaribou
#10

Oxo

Similarity 114Trust 86Excellent 85

OXO is a security scanning orchestrator for the modern age.

574 starsJun 12, 2026 pushsecurityPythonSecurity
$ npx skills add Ostorlab/oxo
#11

Solhint

Similarity 114Trust 94Excellent 100

Solhint is an open-source project to provide a linting utility for Solidity code.

1.1K starsJun 12, 2026 pushsecurityJavaScriptSecurity
$ npx skills add protofire/solhint
#12

Linux Malware Detect

Similarity 114Trust 91Excellent 100

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring, quarantine, and multi-channel alerting

1.4K starsMay 24, 2026 pushsecurityShellSecurity
$ npx skills add rfxn/linux-malware-detect
#13

Raccoon

Similarity 114Trust 93Excellent 100

A high performance offensive security tool for reconnaissance and vulnerability scanning

3.6K starsApr 21, 2026 pushsecurityPythonSecurity
$ npx skills add evyatarmeged/Raccoon
#14

MetaRadar

Similarity 112Trust 91Excellent 93

A tool for BLE environment monitoring. Find and track Bluetooth devices around, and get notified when the target device is detected.

1.4K starsJan 22, 2026 pushsecurityKotlinSecurity
$ npx skills add BLE-Research-Group/MetaRadar
#15

Doublepulsar Detection Script

Similarity 112Trust 85Strong 70

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

1.0K starsFeb 3, 2020 pushsecurityPythonSecurity
$ npx skills add WithSecureLabs/doublepulsar-detection-script
#16

Web Cache Vulnerability Scanner

Similarity 111Trust 86Excellent 92

Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).

1.2K starsJan 21, 2026 pushsecurityGoSecurity
$ npx skills add Hackmanit/Web-Cache-Vulnerability-Scanner

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Tartufo if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.