Search
@atofinite5/sork-cli
atofinite5
Sorkcloud CLI — AI-powered security pipeline for Node.js projects. Scans, triages, fixes, verifies, and supports multiple AI agents (Claude, OpenAI, Codex, Gemini, Mistral, Llama). Works with BYOK or sorkcloud.space-managed keys.
...more@maheshwarimrinal/react-native-agents
GitHub Actions
Expert React Native agents for build failures, implementation, performance, security, code quality, accessibility, testing, native modules, and release — plus a deterministic bundle-size analyzer. Portable across Claude Code, Cursor, Windsurf, Copilot, Co
...moremcpdone-audit
Static security + correctness audit for MCP server repos. Ships four checks. v0.5 fixes a v0.4 false-positive family where list-concatenation (e.g. `["kubectl"] + args + ["get"]`) was misclassified as string-interpolation in command_injection.
...moredepguard-cli
jorgemorais
MCP security server for AI coding agents. Static code analysis, behavioral detection, pre-install guardian, AI hallucination guard, dead dependency detection, vulnerability audit, CycloneDX SBOM generation. 12 tools. Zero dependencies.
...morewatchmyagents
minedor
Security observability + real-time policy enforcement for AI agents. Local-first NDJSON capture, Shield CLI that blocks policy violations live (with policies pulled from Fortress cloud), anonymizer producing signals-only payloads, and bidirectional sync w
...moreWP Hunter
xeloxa
WP-Hunter is a WordPress plugin/theme reconnaissance and static analysis (SAST) tool. It is designed for security researchers to evaluate the vulnerability probability of plugins by analyzing metadata, installation patterns, update histories, and performing deep Semgrep-powered source code analysis.
...moreapisec-ai-surface
APIsec <[email protected]>
Map your application's AI attack surface from source: MCP servers (with security audit), agent frameworks, LLM call sites, model gateways, AI infrastructure, provider keys, and HTTP/OpenAPI endpoints. Local, static, CI-friendly, with a visual UI.
...morePureClaw
puretensor
Enterprise-grade agentic AI framework. 8 LLM backends, declarative security policies, audit trails, SSRF protection, credential redaction, local GPU inference on NVIDIA Blackwell, Telegram/Discord/WhatsApp/Email channels, 16 autonomous observers.
...more@emfirge/mcp
Ansh Sonkar
Privacy-first AWS security in your AI. Trace attack paths from the internet to your sensitive data, check CIS/SOC2, and prove fixes before applying - Emfirge clones your infra graph, mutates it, and re-runs every rule. Resource IDs are tokenized locally,
...morenorpagent
xingluosama121
Pluggable component-based agent framework: modular architecture layers with address functions, np() single-call startup, 9 layers / 29 hooks, norpagent.safe() decoupled security, process-level plugin isolation, ready-to-use preset modes
...moreShipworthy
Vimalk0703
Open source Claude Code plugin — 52 invisible engineering skills turn vibe coding into production-ready software. Auto specs, TDD, security hooks, quality gates, self-improving retrospective. 97% vs 41% on blind benchmark.
...more@yangyixxxx/skill-guard
yangyixxxx
Local-first security scanner for AI Skills (Anthropic Skill bundles, Niuma, OpenClaw, MCP, GPTs Actions). Catches malicious code, supply-chain attacks, and prompt injection — pure static analysis, sub-2s, zero LLM cost.
...moremcpaudit
Security scanner for MCP servers — Python + TypeScript/JavaScript + Go, zero dependencies, 57+ rules, SBOM generation, remediation playbooks, regression detection, plugin system, live scanner, fleet scanning, policy engine, OWASP Agentic Top 10
...moremeok-mcp-hardening-mcp
MEOK MCP Hardening MCP — automated security red-team for any MCP server. Maps OWASP LLM Top 10 (2025) + 5 MCP-specific risks to a 0-100 hardening score with HMAC-signed reports. By MEOK AI Labs.
...more@muhammad-adil-code/mcp-forge
Muhammad Adil
Any API → a tested, secure, monetizable, deployable MCP server. One CLI. Turn any OpenAPI/Swagger spec into an MCP server AI agents (Claude, ChatGPT, Cursor) can use — inspect, scan, test, monetize, generate, and serve, all in one tool.
...moregitee-ai-employee
wangbobo1225
Gitee/GitHub AI 员工:issue 里 @ 机器人自动开发并提 PR;v1.2 新增代码安全扫描——配置仓库地址后按内置/自定义提示词扫描漏洞,去重后提交 issue。An issue-driven AI developer for DeepSeek Harness (Gitee & GitHub) with optional static security scanning (dedup + issue reporting).
...more@allenwu06/mcpaudit
allenwu06
Static pre-install security scanner for MCP (Model Context Protocol) servers — `npx mcpaudit <path>` flags command injection, credential/env exfiltration into LLM-visible output, over-broad filesystem/tool scope and dynamic eval before you wire a server i
...morecontract-auditor-mcp
contract-auditor
Security quick-scan for smart contracts, as an MCP tool and a pay-per-call x402 endpoint. Given an address+chain (or Solidity source) it fetches the Sourcify-verified source, reads live on-chain state (upgradeable proxy? owner an EOA or renounced?) and sc
...morenostr-nsec-seedphrase
vveerrgg
A comprehensive TypeScript library for Nostr key management with BIP39 seed phrases, supporting both ESM and CommonJS. Implements NIP-01, NIP-06, NIP-19, and NIP-26 with key generation, event signing, bech32 encoding/decoding, and secure cryptographic ope
...moreboto3-refresh-session
Mike Letts <[email protected]>
A drop-in replacement for boto3.Session named RefreshableSession. It automatically refreshes temporary AWS credentials, caches clients, and natively supports MFA providers. It also supports automatic temporary AWS security credential refresh for STS, IOT Core, and custom credential callables.
...more