# chaitin/veinmind-tools

veinmind-tools 是由长亭科技自研，基于 veinmind-sdk 打造的容器安全工具集

Repository: https://github.com/chaitin/veinmind-tools
Canonical: https://ross.abutalabs.com/products/veinmind-tools
Homepage: https://veinmind.chaitin.com/docs/
Language: Go
License: MIT
License Family: permissive
Topics: docker, security, image-security, containerd, container-security, cloud-native, cloud-security
Last push: 2024-01-10T09:08:31+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1667, "days_push": 966, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1652, forks 186 (observed 2026-08-28T04:05:17.048407+00:00)

## What it is
veinmind-tools is a container security toolkit by Chaitin Tech built on the veinmind-sdk, providing scanners for malicious files, weak passwords, known vulnerabilities (log4j2, minio), sensitive information, backdoors, and suspicious shell history in container images. It runs as a parallel container via Docker and can generate HTML, CLI, or JSON reports, with optional OpenAI-based analysis of scan results.

## Use cases
- scan docker images for malware and malicious files
- detect weak passwords inside containers
- find log4j2 vulnerabilities in container images
- scan images for leaked secrets and sensitive information
- detect backdoors in container images
- audit suspicious shell history in images
- generate security scan reports in html or

## When to choose
- you need to scan local docker/containerd images and containers for security risks before deployment
- you want a plugin-based container security scanner that runs as a sidecar/parallel container
- you need CI-friendly scan reports in multiple formats

## When to avoid
- you need runtime security monitoring of live clusters rather than image scanning
- you require a full commercial container security platform with admission control and compliance policies
- your environment has no docker or containerd runtime available

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, vulnerability-scanning, cli, developer-tools
- domain: security, cloud-computing, developer-tools
- platform: go, cli
- tags: container-security, image-scanning, docker, containerd, cloud-native, malware-detection, weak-passwords, sensitive-info, openai-analysis, containers, devops, linux

## Member repositories
- chaitin/veinmind-tools (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:17.048407+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:44:59.848593+00:00, confidence not recorded.
  - readme: https://github.com/chaitin/veinmind-tools (fetched 2026-08-28T04:05:17.048407+00:00, sha bfe072e3cb3e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
