Search
express-csp-header
frux
Content-Security-Policy middleware for Express
aws-security-mcp
jowhee
MCP Server for AWS security scanning
@xrift/code-security
sawa-zen
Code security analyzer powered by acorn
industrialxpl-forge
IndustrialXPL-Forge (IXF) — OT/ICS/SCADA/HMI/IIoT Security Assessment & Exploitation Framework. Python-First, 631+ modules, 79 MITRE ATT&CK for ICS, 26 malware TTPs, 50+ vendors, 50+ protocols, SAST/LLM.
...moreexpress-openapi-security
jsdevel
Express middleware to handle openapi security.
@kevyn-castelo/vibeaudit
kevyn-castelo
Agent skills (SKILL.md) that find and fix the five security failures AI-generated code leaves behind most often: missing RLS, frontend-only authorization, IDOR, exposed secrets, unvalidated input. Works in Claude Code, Codex, OpenCode, Antigravity, Devin,
...more@nemesis-shield-autogon/edge
obiebukadavid
Nemesis Shield — Edge SDK for Deno / Cloudflare Workers / Vercel Edge / Supabase Edge Functions. Positive-security: learns your app's normal behavior and blocks off-baseline requests (auth bypass, path traversal, scanners) in enforce mode. Web-standard (R
...morecaspian-security
caspianexplorer
Security scanner for VS Code AND a standalone `caspian` CLI you can run anywhere (PowerShell/cmd/bash, no VS Code needed) — 295+ rules covering code and infrastructure (Dockerfile, Terraform, Kubernetes), intra-file taint tracking, SSRF/XXE/SSTI/deseriali
...morehookwarden
adelinalipsa
Webhook security audit CLI — finds signature-verification bugs in JavaScript, TypeScript, and Python codebases. Local, deterministic, zero-network. Ships rules for Stripe, GitHub, Shopify, Slack, Twilio, and Square; JSON / SARIF 2.1.0 output for CI and Gi
...more@rigour-labs/mcp
erashu212
MCP server for AI code governance — OWASP LLM Top 10 (10/10), real-time hooks, 25+ security patterns, hallucinated import detection, multi-agent governance. Works with Claude, Cursor, Cline, Windsurf, Gemini. Industry presets for HIPAA, SOC2, FedRAMP.
...more@jordanmgsoftware/seo-cli
mgsoftwarebv
SOTA SEO CLI for MG Software projects: crawl, audit, link graph, anti-spam (March 2026), GEO/AEO, programmatic SEO checks, plus dedicated security & privacy audits (HTTP headers, TLS, cookies, dependency vulns, takeover, GDPR/PII). Runs on production URLs
...moregirste/mcp-cybersec-watchdog
🐍 🏠 🐧 - Comprehensive Linux server security audit with 89 CIS Benchmark controls, NIST 800-53, and PCI-DSS compliance checks. Real-time monitoring with anomaly detection across 23 analyzers: firewall, SSH, fail2ban, Docker, CVE, rootkit, SSL/TLS, filesystem, network, and more.
...moreGUCCI-atlasv/skillssafe-mcp
[glama](https://glama.ai/mcp/servers/dneiil7zph) 📇 ☁️ - Free AI agent skill security scanner. Scan SKILL.md, MCP configs, and system prompts for credential theft, prompt injection, zero-width character attacks, and ClawHavoc indicators. Supports OpenClaw, Claude Code, Cursor, and Codex. No signup required.
...moreembedxpl
Embedded & Perimeter Security Assessment Framework — 3000+ modules, 600+ CVEs, 80+ vendors. Unified from FirewallXPL-Forge, ISF OT/ICS protocol clients, and deep ExploitDB/Metasploit coverage. v2.4.0 adds Mirai/Condi reference analysis (string decoder, orchestrator), GPON scanner, C2 beacon detector, CnC simulation lab.
...moreSkill Security Auditor
burakseyman
Comprehensive security auditor skill for Claude Code - analyzes skills and MCP servers for malicious patterns, suspicious behaviors, and security vulnerabilities
...morealberthild/shieldapi-mcp
[glama](https://glama.ai/mcp/servers/@alberthild/shield-api-mcp) 📇 ☁️ 🍎 🪟 🐧 - Security intelligence for AI agents: password breach checks (900M+ HIBP hashes), email/domain/IP/URL reputation, prompt injection detection (200+ patterns), and skill supply chain scanning. Pay-per-request via x402 USDC micropayments or free demo mode, no API key needed.
...morearcis
Inside-the-app security middleware for Python. One install protects FastAPI, Flask, and Django against XSS, SQL injection, CSRF, SSRF, HPP, prompt injection, bot traffic, rate limiting, and 20+ more attack types. Includes prompt-injection signature library, LLM token-budget middleware, and a 646-pattern bot corpus with consistent API across the Node and Go SDKs. The CLI ships separately at npm install -g @arcis/cli.
...moremsaad00/agent-bom
Wagdy Saad <[email protected]>
[glama](https://glama.ai/mcp/servers/@msaad00/agent-bom) 🐍 🏠 ☁️ 🍎 🪟 🐧 - AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.
...moreonedionys-content-security-policy-generator
onedionys
One Dionys (Content Security Policy Generator) - A utility for generating and deploying content security policies in web applications, improving application security.
...more@infinitestudios/opentrust-client
blackjadesoul
TypeScript SDK for verifying and auditing MCP tool passports — OpenTrust trust registry client