Search
owasp-mcp-scan
Security scanner for Model Context Protocol (MCP) servers. Audits running servers against the OWASP MCP Top 10 and outputs console, JSON, and SARIF reports. Runs as a CLI or as an MCP server itself.
...morejwt-lab
GitHub Actions
jwt-lab – A fast, secure, beautiful JWT CLI tool and MCP server for developers & AI agents. Encode, decode, verify, inspect, audit, and generate keys for JSON Web Tokens.
...moretrickle-cli
yiheinchai
Zero-code runtime observability for JS/Python + AI agent debugging. Traces LangChain, CrewAI, OpenAI, Anthropic, Gemini. Eval, security, compliance, cost tracking. Free, local-first.
...moreagentshield-sdk
chrisday91
The security standard for MCP and AI agents. 141 detection patterns, CORTEX threat intelligence, pre-deployment audit, intent firewall, flight recorder, and 390+ exports. Zero dependencies, runs locally.
...morelangchain-tollwarden
TollWarden <[email protected]>
TollWarden payment security for LangChain/LangGraph agents: scan x402 payments before settling, auto-tag provenance for prompt-injection detection, guard payment tools so blocked payments can never execute.
...moreuseagentguard
The Security & Cost Control Layer for AI Agents — Guard, Shield, and Sentinel tiers: budget control, per-agent credential isolation, OAuth scope enforcement, MCP policy enforcement, and compliance reporting.
...moreEcosystem Platform
turtir-ai
🚀 Ultimate Developer Productivity Suite - 11 specialized MCP servers for AI-powered code analysis, security scanning, browser automation, and workflow orchestration. FastAPI + React + TypeScript + Docker ready.
...morerakshakai
rakshakai
RakshakAI — AI-powered security scanner & chat. Scan 20+ languages, 150+ vulnerability patterns, 65+ AI models across 9 providers, multi-agent swarm, offline regex engine.
...morelangchain-paysafe
PaySafe payment security for LangChain/LangGraph agents: scan x402 payments before settling, auto-tag provenance for prompt-injection detection, guard payment tools so blocked payments can never execute.
...more@blacksandscyber/mcp-server-shield
Blacksands Cyber, Inc.
Blacksands Shield MCP Server — zero-trust security operations for AI agents. Installable in Claude Code (`claude mcp add shield -- shield-mcp`) and Claude Desktop (drag-and-drop .dxt).
...moredbgpt
csunny <[email protected]>
DB-GPT is an experimental open-source project that uses localized GPT large models to interact with your data and environment. With this solution, you can beassured that there is no risk of data leakage, and your data is 100% private and secure.
...moresuperred-target-dtap-scaffold
Shared scaffolding for the DecodingTrust-Agent (DTAP) superred targets: the agent-agnostic Target base, the security-domain forest, controllables/observables, env/MCP/Docker lifecycle, and the byte-faithful judge runner.
...morexploitscan-mcp
XploitScan
Model Context Protocol (MCP) server exposing the XploitScan security scanner as a tool Claude, Cursor, and other MCP clients can call. Scan AI-generated code from inside your AI coding agent.
...moreLocal First LLM Agent With MCP Tool Orchestration
GunaTeja777
A security-conscious, local-first LLM agent in Go powered by Ollama & Model Context Protocol (MCP). Features defense-in-depth sandboxing, tamper-evident audit logging, and MCP tool orchestration.
...moreCoWork OS
CoWork-OS
Operating System for your personal AI Agents with Security-first approach. Multi-channel (WhatsApp, Telegram, Discord, Slack, iMessage), multi-provider (Claude, GPT, Gemini, Ollama), fully self-hosted.
...moreAouda
thatrebeccarae
A security-first alternative to OpenClaw. Slack, Telegram, Gmail, Calendar, browser automation, RSS, n8n workflows, Claude Code /rc handoff. OWASP ASI-aligned, single-user, self-hosted.
...more@leing2021/pi-search
leing2023
Minimal Secure Evidence Gateway for Pi Coding Agent — search, web_search, web_fetch, research_search. Intent-based provider routing, quota fallback, dual-LLM research, 4-layer abuse prevention.
...morecalllint
saintw1022
Evidence-backed security verdicts for MCP servers and agent tools. Lint agent tool-call risk before tools run — SAFE / REVIEW / BLOCK / UNKNOWN, with evidence. Never executes the server it judges.
...moredeepseek-free-agent
readfor
AI coding agent powered by DeepSeek via browser automation — no API key needed. Performance-optimized (30-40% faster). New --headless parameter for interactive mode. Enhanced with comprehensive security.
...moreElromEvedElElyon/solanashield-mcp
AI-powered Solana smart contract security audit server with 40 vulnerability patterns and 12 MCP tools covering access control, CPI safety, PDA, tokens, arithmetic, and DeFi exploits.
...more