Security
Everything here was classified as security by keyword match against the maintainer's own description, so treat the grouping as a starting point rather than a verdict.
The list is ordered by the most recent commit, not by stars. A popular project that stopped in 2024 is not a better answer than a smaller one shipped last week.
Listed, not yet verified by us (59)
Published to the registry, but we have not yet checked its repository. Treat the entry as the maintainer’s claim only.
-
EU Compliance Tools (pay-per-call, x402)
— v1.1.0
Agent bookkeeping, sanctions, KYB, VAT and e-invoice checks - pay per call in USDC
-
io.github.pdaxt/pqvault
— v2.1.0
Post-quantum secrets manager for AI agents. ML-KEM-768 + X25519 + AES-256-GCM.
-
Dredd MCP
— v1.0.0
Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
-
UniFi Gateway
— v0.16.1
Safe-by-default UniFi MCP: Network + Protect + Access, multi-site, dry-run, audit log.
-
Guarded WhatsApp
— v0.1.0
Security gate for agent-driven WhatsApp: allowlist, secret scan, rate limit, audit log.
-
Agrus.ai — Enterprise AI Agency
— v0.2.0
AI consulting agency for regulated industries. Scope a PoC, query compliance, request a proposal.
-
OWASP ZAP MCP Server
— v1.1.0
MCP server for OWASP ZAP vulnerability scanning with Docker management
-
Macvendors
— v0.1.0
macvendors.com MCP — MAC address (OUI) → hardware manufacturer lookup.
-
nvd
— v0.1.0
NVD MCP — wraps the NIST National Vulnerability Database API (free, no auth)
-
Osv Dev
— v0.1.0
OSV.dev — Google's open-source vulnerability database
-
Securitytrails
— v0.1.0
SecurityTrails MCP — wraps SecurityTrails API (securitytrails.com)
-
Ukhsa
— v0.1.0
UK Health Security Agency (UKHSA) data dashboard MCP — keyless.
-
AgentEconomy Compliance API
— v1.0.0
Paid KYC, AML, and regulatory risk assessment over MCP via x402 USDC micropayments on Base.
-
Pretorin Compliance
— v0.28.0
Access Pretorin compliance systems, controls, evidence, and narratives from your AI tools.
-
io.github.privacyplaybook/sops-mcp
— v0.10.1
MCP server for creating and managing SOPS-encrypted secrets
-
prodlint
— v0.9.5
Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.
-
AgentSecurityLens MCP Security Trust Check
— v0.1.12
MCP security trust-check for agents before installing MCPs, Skills or tools.
-
LeakRank Guard
— v0.2.3
Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.
-
io.github.raportagent/raportagent-mcp
— v0.1.2
Sourced market and compliance research for Claude Desktop, Claude Code and Cursor.
-
SpineFrame
— v1.1.2
Governance runtime for AI agents with signed provenance, compliance audits, and OSINT.
-
io.github.RCOLKITT/vaspera-hardening
— v1.0.2
Enterprise certification for codebases with multi-agent security, reliability, and quality audits
-
io.github.revsmoke/promptrejectormcp
— v1.0.1
Security gateway for AI agents: detects prompt injections, jailbreaks, and common vulnerabilities.
-
io.github.rezearcher/cve-triage
— v1.0.0
x402 CVE triage MCP: EPSS + CISA KEV -> exploit priority, $0.01 per query.
-
io.github.rezearcher/tech-risk
— v1.2.0
x402 MCP for agents: crypto prices, funding, DeFi yields, Polymarket, Base RPC + MCP security.
-
AI2Human
— v0.1.2
Dispatch human-execution tasks with proof verification, local checks, and compliance reviews.
-
io.github.rijul170/qualys-mcp
— v0.1.0
Full Qualys portal management over MCP: VMDR, PC, WAS, Cloud Agent, Container Security & more
-
io.github.rijul170/sophos-central-mcp
— v1.1.0
MCP server for Sophos Central — endpoint security, XDR/MDR, and MSSP multi-tenant ops
-
io.github.rikocr8orh8/regulatory-signals
— v0.1.2
Audit GitHub repos for security, compliance, and EU AI Act exposure from Claude or Cursor.
-
io.github.rog0x/dep
— v1.0.1
License check, outdated deps, security for AI agents
-
DocVerdict
— v1.0.0
PDF, photo, email, and file comparison evidence checks with plain-language reports.
-
Wolfpack Intelligence
— v2.1.0
On-chain security and market intelligence for trading agents on Base.
-
io.github.rom-baro/arcwall-security
— v1.0.1
Security scanning for AI coding tools. Detects secrets, threat models, and runs pre-commit checks.
-
MCP OpenClaw Extensions
— v3.3.0
138-tool MCP server for AI agent firms: security, A2A, Hebbian memory, fleet mgmt
-
io.github.rootsbymenda/cannabis-regulatory
— v1.0.2
Cannabis compliance: US state testing, INCB, Health Canada, EU precursors. Free.
-
klaws — Korean compliance risk scanner
— v0.1.6
Scan code for Korean compliance risks — PIPA/개인정보보호법, Network Act, Credit Info. Not legal advice.
-
vuln-intel
— v1.0.1
Hosted CVE + bug-bounty-mechanic MCP: exploitation-first ranking, CVE fact-check, mechanic transfer
-
io.github.rsdouglas/janee
— v0.8.5
Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.
-
Askew x402
— v0.1.0
DeFi yields, staking routing, semantic research & security intel via x402 micro-payments on Base
-
io.github.rudraneel93/mcp-guardian
— v2.3.21
Security, cost, and health governance proxy for MCP infrastructure
-
io.github.Rumblingb/agentpay-sentinel-mcp
— v1.0.0
Security guardrails for AI agent payments
-
io.github.runsec-io/mcp
— v1.0.127
RunSec MCP server for workspace security scanning and remediation workflows.
-
io.github.runyourempire/4da-mcp-server
— v4.6.0
Dependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.
-
io.github.S2TConsulting/accelerators
— v1.4.2
36 tools for AWS infrastructure, security compliance, AI workflows, and ACI governance.
-
io.github.sairam0424/mindforge
— v11.5.1
Read the MindForge engine over MCP: knowledge graph, project health, and audit log.
-
Agentic SDLC MCP
— v1.9.0
Agentic SDLC governance and security controls for AI coding agents working with GitHub.
-
io.github.salrad22/code-sentinel
— v0.2.6
Code quality analysis MCP server - detects security issues, deceptive patterns, and placeholders
-
io.github.sathergate/lockbox
— v0.1.1
Encrypted secrets for Next.js. AES-256-GCM with no vault needed.
-
Security Intel MCP
— v2.0.0
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
-
io.github.sentrysurface/sentrysurface
— v1.0.0
Cybersecurity MCP server for URL scanning, threat intelligence, and domain reputation.
-
io.github.SergioRico1/thrd
— v0.1.5
Thrd MCP: agent email tools for events/threads, safe send/reply, usage, trust and security.
-
Abnormal Security MCP
— v0.1.0
Abnormal Security email threats, cases, and reporting in your terminal and your AI agents.
-
Action1 MCP
— v0.1.0
Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations.
-
CyberLens
— v1.0.0
Security scanning for websites, public repositories, and Open CLAW skills.
-
GhostFree
— v0.2.0
MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.
-
io.github.shieldly-io/mcp
— v1.0.1
AI-Powered AWS security analysis: scan IAM policies and CloudFormation for risks and escalation.
-
Google Workspace Admin Security-Audit MCP
— v0.10.0
MCP server for Google Workspace security auditing — login audit, external sharing, daily brief
-
io.github.shotwellj/air-blackbox
— v0.1.2
EU AI Act compliance scanner for Python AI agents — scan, analyze, and remediate
-
Shrike Security
— v1.1.1
AI agent security scanner — prompt injection detection, SQL injection, PII isolation, threat intel.
-
AgentGuard — security checks for AI agents
— v0.1.2
Secret, CVE and dependency-vulnerability scanning for AI agents (free, OSV.dev).
Page 10 of 13
How this page is ordered
Entries are grouped by whether anyone is still working on them, using the date of the most recent push to the repository. They are not ordered by stars, because a star is a bookmark somebody left once and never took back.
Where we have not checked an entry yet, it says so rather than being mixed in with the verified ones.