# Security and crypto packages

Security, identity, cryptography, password, signing, and certificate-related packages.

- **Packages:** 800
- **Protected tools:** 0
- **Approval gates:** 2
- **Non-low risk:** 224
- **Updated:** 2026-08-03

## Why this package group is here

Security and crypto packages currently includes 800 package catalog entries. 0 have protected-tool coverage, 2 have approval-gate metadata, and 224 have non-low Geiger classifier findings. The grouping comes from package metadata, so it can stay current as that metadata changes.

## Generated source

This hub uses the same local package data as individual package pages: Nucleus package metadata, Homebrew enrichment, Geiger classifier output, secret-handling manifests, and approval-gate seeds where available.

## Review model

Use the hub to find command families that need tighter secret injection, approval gates, or manual review before agents run them.

## Indexed package pages

- [mkcert](https://pkg.so/pkg/brew/mkcert/) - 4 approval-gate rules are present.
- [ffmpeg](https://pkg.so/pkg/brew/ffmpeg/) - 4 approval-gate rules are present.
- [deno](https://pkg.so/pkg/brew/deno/) - doc example: JavaScript runtime
- [mono](https://pkg.so/pkg/brew/mono/) - broad file, network, media, or database tool signal
- [nikto](https://pkg.so/pkg/brew/nikto/) - broad file, network, media, or database tool signal
- [nono](https://pkg.so/pkg/brew/nono/) - generalized runtime or code generation signal
- [crytic-compile](https://pkg.so/pkg/brew/crytic-compile/) - generalized runtime or code generation signal
- [ponyc](https://pkg.so/pkg/brew/ponyc/) - broad file, network, media, or database tool signal
- [rush](https://pkg.so/pkg/brew/rush/) - generalized runtime or code generation signal
- [pwncat](https://pkg.so/pkg/brew/pwncat/) - generalized runtime or code generation signal
- [vsh](https://pkg.so/pkg/brew/vsh/) - generalized runtime or code generation signal
- [proxify](https://pkg.so/pkg/brew/proxify/) - broad file, network, media, or database tool signal
- [wassette](https://pkg.so/pkg/brew/wassette/) - generalized runtime or code generation signal
- [rustcat](https://pkg.so/pkg/brew/rustcat/) - generalized runtime or code generation signal
- [dehydrated](https://pkg.so/pkg/brew/dehydrated/) - broad file, network, media, or database tool signal
- [gnutls](https://pkg.so/pkg/brew/gnutls/) - no executable entrypoint in the package index
- [p11-kit](https://pkg.so/pkg/brew/p11-kit/) - library-like package without higher-risk signals
- [gnupg](https://pkg.so/pkg/brew/gnupg/) - no executable entrypoint in the package index
- [nettle](https://pkg.so/pkg/brew/nettle/) - no executable entrypoint in the package index
- [libcap](https://pkg.so/pkg/brew/libcap/) - library-like package without higher-risk signals
- [openldap](https://pkg.so/pkg/brew/openldap/) - narrow executable package without higher-risk signals
- [nss](https://pkg.so/pkg/brew/nss/) - no executable entrypoint in the package index
- [pinentry](https://pkg.so/pkg/brew/pinentry/) - narrow executable package without higher-risk signals
- [bubblewrap](https://pkg.so/pkg/brew/bubblewrap/) - narrow executable package without higher-risk signals
- [gpgme](https://pkg.so/pkg/brew/gpgme/) - no executable entrypoint in the package index
- [cyrus-sasl](https://pkg.so/pkg/brew/cyrus-sasl/) - narrow executable package without higher-risk signals
- [llama.cpp](https://pkg.so/pkg/brew/llama-cpp/) - no executable entrypoint in the package index
- [xxhash](https://pkg.so/pkg/brew/xxhash/) - narrow executable package without higher-risk signals
- [srt](https://pkg.so/pkg/brew/srt/) - narrow executable package without higher-risk signals
- [sops](https://pkg.so/pkg/brew/sops/) - no executable entrypoint in the package index
- [chezmoi](https://pkg.so/pkg/brew/chezmoi/) - no executable entrypoint in the package index
- [libfido2](https://pkg.so/pkg/brew/libfido2/) - library-like package without higher-risk signals
- [gitleaks](https://pkg.so/pkg/brew/gitleaks/) - narrow executable package without higher-risk signals
- [libsecret](https://pkg.so/pkg/brew/libsecret/) - library-like package without higher-risk signals
- [argon2](https://pkg.so/pkg/brew/argon2/) - library-like package without higher-risk signals
- [semgrep](https://pkg.so/pkg/brew/semgrep/) - narrow executable package without higher-risk signals
- [gsasl](https://pkg.so/pkg/brew/gsasl/) - no executable entrypoint in the package index
- [trufflehog](https://pkg.so/pkg/brew/trufflehog/) - no executable entrypoint in the package index
- [gperf](https://pkg.so/pkg/brew/gperf/) - narrow executable package without higher-risk signals
- [zizmor](https://pkg.so/pkg/brew/zizmor/) - no executable entrypoint in the package index
- [aws-vault](https://pkg.so/pkg/brew/aws-vault/) - no executable entrypoint in the package index
- [certbot](https://pkg.so/pkg/brew/certbot/) - no executable entrypoint in the package index
- [libseccomp](https://pkg.so/pkg/brew/libseccomp/) - library-like package without higher-risk signals
- [bitwarden-cli](https://pkg.so/pkg/brew/bitwarden-cli/) - no executable entrypoint in the package index
- [docker-credential-helper](https://pkg.so/pkg/brew/docker-credential-helper/) - no executable entrypoint in the package index
- [jadx](https://pkg.so/pkg/brew/jadx/) - narrow executable package without higher-risk signals
- [tfsec](https://pkg.so/pkg/brew/tfsec/) - narrow executable package without higher-risk signals
- [linux-pam](https://pkg.so/pkg/brew/linux-pam/) - narrow executable package without higher-risk signals
- [ldns](https://pkg.so/pkg/brew/ldns/) - library-like package without higher-risk signals
- [xauth](https://pkg.so/pkg/brew/xauth/) - narrow executable package without higher-risk signals
- [pinentry-mac](https://pkg.so/pkg/brew/pinentry-mac/) - narrow executable package without higher-risk signals
- [istioctl](https://pkg.so/pkg/brew/istioctl/) - no executable entrypoint in the package index
- [cycode](https://pkg.so/pkg/brew/cycode/) - no executable entrypoint in the package index
- [kubelogin](https://pkg.so/pkg/brew/kubelogin/) - narrow executable package without higher-risk signals
- [libxmlsec1](https://pkg.so/pkg/brew/libxmlsec1/) - library-like package without higher-risk signals
- [ykman](https://pkg.so/pkg/brew/ykman/) - narrow executable package without higher-risk signals
- [snyk-cli](https://pkg.so/pkg/brew/snyk-cli/) - no executable entrypoint in the package index
- [opa](https://pkg.so/pkg/brew/opa/) - no executable entrypoint in the package index
- [dependency-check](https://pkg.so/pkg/brew/dependency-check/) - narrow executable package without higher-risk signals
- [openconnect](https://pkg.so/pkg/brew/openconnect/) - no executable entrypoint in the package index
- [md5sha1sum](https://pkg.so/pkg/brew/md5sha1sum/) - narrow executable package without higher-risk signals
- [talisman](https://pkg.so/pkg/brew/talisman/) - narrow executable package without higher-risk signals
- [subfinder](https://pkg.so/pkg/brew/subfinder/) - narrow executable package without higher-risk signals
- [step](https://pkg.so/pkg/brew/step/) - narrow executable package without higher-risk signals
- [saml2aws](https://pkg.so/pkg/brew/saml2aws/) - narrow executable package without higher-risk signals
- [yara](https://pkg.so/pkg/brew/yara/) - narrow executable package without higher-risk signals
- [oath-toolkit](https://pkg.so/pkg/brew/oath-toolkit/) - narrow executable package without higher-risk signals
- [libcap-ng](https://pkg.so/pkg/brew/libcap-ng/) - library-like package without higher-risk signals
- [gobuster](https://pkg.so/pkg/brew/gobuster/) - narrow executable package without higher-risk signals
- [minisign](https://pkg.so/pkg/brew/minisign/) - narrow executable package without higher-risk signals
- [bfg](https://pkg.so/pkg/brew/bfg/) - narrow executable package without higher-risk signals
- [sqlcipher](https://pkg.so/pkg/brew/sqlcipher/) - no executable entrypoint in the package index
