Search
tripwire-mcp
bonesdefi
Security gateway for MCP agents: blocks prompt-injection-driven tool calls (poisoned payments, fabricated results) with cryptographic receipts, value-provenance enforcement, and multi-model consensus. The verification layer no syntactic MCP firewall has.
...moreCstrike
culpur
CStrike v2.6 — Offensive Security Platform. 35+ tools, 9-container Docker stack, self-update system, parallel port scanning, VPN kill-switch. Dual-arch (amd64/aarch64) VM distribution.
...morepyaigis
killertcell428
The open-source firewall for AI agents. Block prompt injections, jailbreaks, and data leaks before they reach your LLM. Multi-layer defense, agent-era security (MCP/Capability), US/CN/JP/EU compliance. Zero-dependency core.
...moreai-sentinel
aman-diwakar
OpenClaw plugin for prompt injection detection. Drop-in security scanning that hooks into message, tool call, and tool result lifecycle events using heuristic pattern matching. For the full SDK with ML classification, custom rules, and audit logging, see
...moreAuditor Skill
solanabr
Claude Code / agentic security skill for Solana programs and software. Full audit-firm lifecycle, executable PoC + fix-patch delivery, a Rust pre-scanner + cross-audit memory, 1,346 checks across 20 checklists, and 131 real-world attack vectors.
...moreBlackwall Llm Shield Python
vpdeva
Blackwall LLM Shield is an open-source AI security toolkit for JavaScript and Python that protects LLM apps from prompt injection, sensitive data leaks, unsafe tool calls, and hostile RAG content with prompt sanitization, PII masking, output inspection, policy enforcement, and audit trails.
...moreSecureMCP
makalin
SecureMCP is a security auditing tool designed to detect vulnerabilities and misconfigurations in applications using the [Model Context Protocol (MCP)](https://modelcontextprotocol.io/introduction). It proactively identifies threats like OAuth token leakage, prompt injection vulnerabilities, rogue MCP servers, and tool poisoning attacks.
...moreZiran
Open-source security testing framework for AI agents. Discovers dangerous tool chain compositions via graph analysis, detects execution-level side effects, and runs multi-phase trust exploitation campaigns. 
...more@turingpointde/cvss.js
GitHub Actions
A tiny library to work with cvss vectors
eslint-plugin-no-secrets
nickdeis
An eslint rule that searches for potential secrets/keys in code
chalawa
wildpointer0310
a package for applying encryption at transit state
web-secure-encryption
rrishuyadav
A encryption library for ReactJS and React Native Web
rn-secure-storage
taluttasgiran
Secure Storage for React Native (Android & iOS) - Keychain & Keystore
security-skill-compiler
jeyasingh237
Compile stack-aware, harness-ready security audit skills for any repository.
@bam.tech/react-native-app-security
julienc6
Easily implement usual security measures in React Native Expo apps
@paloaltonetworks/n8n-nodes-prisma-airs
jroberts2600
n8n community node for Prisma AIRS (AI Runtime Security) API integration
@bdzscaler/n8n-nodes-aiguard
bd-devrel
n8n community node for Zscaler AI Guard (AI Runtime Security) API integration
@jackietreeh0rn/homebridge-blink-security
jackietreeh0rn
Homebridge plugin for Amazon Blink security cameras
next-strict-csp
guydumais
Hash-based Strict CSP for Next.js
Awesome OpenClaw Papers
REAL-Lab-NU
A curated collection of academic papers, security reports, datasets, and tools for the OpenClaw AI agent ecosystem.