Search
eslint-plugin-no-process-env
btraut
ESLint plugin that bans direct process.env access in application code
infai-tech/vulnfeed-mcp
Dependency vulnerability scanner with EPSS exploit probability scoring. Scans lockfiles (npm, pip, Go, Cargo, Ruby, Composer, Gradle, NuGet, Mix), prioritizes by real-world exploit likelihood, recommends fix versions. 9 MCP tools for scanning, monitoring, and alerting. Free tier + x402 micropayments. `pip install vulnfeed-mcp`.
...moreaiossh
Asynchronous SSH client library with connection pooling, SSH tunneling, encrypted session storage, parallel file transfer, session recording/replay, and input validation.
...moreair-trust
Jason Shotwell <[email protected]>
Universal compliance trust layer for AI systems. One install, any framework. HMAC-SHA256 audit chain, agent identity, policy enforcement, CSA Agentic Trust Framework (ATF) conformance, verify CLI.
...morecforge
CLI for Context Forge allowing seamless management of local or hosted MCP and A2A resources.
@appforgeapps/shieldforge-types
appforgeapps
Shared TypeScript types for ShieldForge authentication library
ddg-agent-services-mcp
Daedalus Development Group <[email protected]>
Payment-aware MCP wrapper and AI-agent distribution/readiness surface for DDG Agent-Payable Services
@depup/azure__storage-blob
Microsoft Corporation
Microsoft Azure Storage SDK for JavaScript - Blob (with updated dependencies)
@weave_protocol/domere
tyox-all
The Judge Protocol - Thread identity, intent verification, and blockchain anchoring
express-recon
GitHub Actions
Offline-first Express, Fastify, and NestJS route inventory, auth audit, OpenAPI reconciliation, and GitHub organization discovery.
...moreprod-analyzer
onrcan
Fail-fast CI guard for dangerous production misconfigurations across Spring Boot, Node.js, and .NET with custom policy engine
...more@simple-csrf/next
infinity_atom
CSRF protection middleware and components for Next.js applications
Tenuo
Capability-based authorization for AI agents. Task-scoped tokens with offline verification, proof-of-possession binding, and native LangChain/LangGraph integration. 
...moreagent-tripwire
Ilpo Vaatainen
Safety checks an AI agent runs before it acts: is this package malware/typosquat, is this shell command destructive, does this text leak a secret. CLI + MCP server.
...moreis-unsafe
amitgupta
Zero-dependency, DOM-free, pure predicate for detecting unsafe strings across HTML, XML, SVG, SQL, SHELL, and REGEX contexts
...morellmasking
biaoge123
Mask sensitive data before it reaches an LLM, restore it after — including in SSE streams where a placeholder is split across chunk boundaries. Zero runtime dependencies.
...morenetlify
netlify-bot
Netlify command line tool
express-brute-store-sequelize
ortex
Sequelize store for module express-brute
@code-pushup/coverage-plugin
GitHub Actions
Code PushUp plugin for tracking code coverage ☂
cloak-cli
CLOAK contributors
Local CLI for safer LLM workflows: redact code before pasting, generate verified obfuscated copies, enforce policy from your repo.
...more