ZBS Index What actually exists in applied AI, with the source next to it

Security

Everything here was classified as security by keyword match against the maintainer's own description, so treat the grouping as a starting point rather than a verdict.

The list is ordered by the most recent commit, not by stars. A popular project that stopped in 2024 is not a better answer than a smaller one shipped last week.

Listed, not yet verified by us (60)

Published to the registry, but we have not yet checked its repository. Treat the entry as the maintainer’s claim only.

  • PCI DSS v4.0.1 Compliance Checker — v0.7.1
    PCI DSS v4.0.1 compliance scanner for Go payment services, delivered as an MCP server
  • io.github.silversurfer562/memdocs — v2.1.4
    Git-native project memory for AI assistants with enterprise-grade audit compliance
  • io.github.sinewaveai/agent-security-scanner-mcp — v2.0.1
    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
  • io.github.SirinivasK/chron — v0.1.7
    Timestamped audit log for every AI conversation — stored locally in SQLite, owned by you.
  • Reversecore MCP — v3.0.2
    Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
  • MCPProxy — v0.53.0
    Local-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savings
  • DBeast PostgreSQL MCP — v2.0.2
    PostgreSQL MCP server for schema, query, health, security, and performance analysis.
  • Snyk API & Web MCP Server — v1.1.2
    MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage
  • io.github.SolvoHQ/freshdeps-mcp — v1.0.0
    Live npm/PyPI dependency-health verdicts so AI agents stop recommending stale or CVE'd packages
  • SonarQube MCP Server — v1.21.0
    Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants.
  • MCP Shield — v1.0.7
    Security scanner for MCP servers. SSRF, path traversal, injection, auth, secrets. Grade A-F.
  • io.github.soufianetahiri/mception — v0.5.2
    Audits other MCP servers for security risks. Returns safe / caution / unsafe / inconclusive.
  • io.github.sparkvibe-io/GuardianShield — v1.2.1
    AI security layer: code scanning, PII detection, prompt injection, secrets, CVEs
  • QueryBear — v1.0.0
    Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
  • io.github.srbryant86/mcp-server — v1.2.2
    Sign AI output for EU AI Act + FRE 902 compliance, verify content authenticity provenance
  • HiveAudit Readiness — v1.0.0
    Multi-jurisdictional AI compliance readiness scoring with sourced penalty math.
  • Hive Log — v1.0.0
    Tamper-evident audit log service for agent-to-agent transactions
  • Hive Secrets — v1.0.0
    Encrypted secret store and rotation for autonomous agent credentials
  • io.github.starloghq/starlog — v0.9.0
    Vet a package (CVEs, license, maintenance) before your AI agent uses it, plus capability discovery.
  • Catalyst Governance — v1.0.1
    Governance middleware for AI agents: permission gates, approvals, compliance scanning, audit ledger.
  • io.github.SurfEther/trustsource — v0.1.6
    x402-paid domain verification for AI agents — trustscore, SSL, security headers, robots.
  • io.github.Sushegaad/iso27001-mcp — v0.8.4
    ISO 27001 compliance workspace for Claude. Risks, policies, SoA, evidence, and audit workflows.
  • io.github.SwikingSWE/conformy — v0.3.5
    EU AI Act & NIS2 compliance — classify AI systems, check obligations, draft docs.
  • io.github.SymbioticSec/mcp — v1.0.1
    Symbiotic CLI MCP Server for security scanning and analysis
  • CodeInspectus — v2.1.0
    Local-first MCP security scanner and CLI for AI-generated applications.
  • Zephex — v1.0.0
    MCP gateway with 10 tools for code analysis, architecture, package audit & security.
  • io.github.tb0hdan/wass-mcp — v1.0.4
    MCP server for web application security scanning
  • io.github.TeodorMCP/universal-connector-mcp — v0.2.0
    Security-first MCP server that connects any OpenAPI, GraphQL, gRPC or SOAP API to AI agents.
  • io.github.thegridwork/aiact — v1.0.0
    Scan codebases for AI usage, classify risk, generate EU AI Act compliance reports.
  • io.github.thegridwork/license — v1.0.0
    Scan dependencies for license compliance — copyleft conflicts, unknown licenses, risk.
  • io.github.thegridwork/privacy — v1.0.0
    Audit websites for GDPR, CCPA, and ePrivacy compliance — trackers, consent, and policies.
  • io.github.Thezenmonster/agentscore — v2.2.0
    MCP security trust layer: scan packages, inspect repos, check exposure, monitor changes.
  • io.github.threadlinqs-cmd/intelthreadlinqs-mcp — v7.1.3
    Threadlinqs threat-intelligence MCP — 49 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
  • Raziel — v1.9.6
    MCP server teaching AI agents to implement TideCloak: auth, E2EE, IGA, security analysis
  • io.github.tidynest/raven-nest-mcp — v0.2.9
    AI-driven penetration testing - 22 security tools behind safety-hardened MCP endpoints
  • ScriptDocs MCP — v0.3.1
    Real, live npm/PyPI docs and OSV.dev vulnerability data for AI coding agents. No fake data.
  • io.github.Toby-Self/asymptotic-ethics — v0.1.0
    MCP server for an Asymptotic Ethics governance simulation with a verified compliance oracle.
  • io.github.Toby-Self/federated-ai-commons — v0.1.1
    MCP server for a federated AI-commons governance simulation with a verified compliance oracle.
  • SiteVitals — v1.0.0
    Monitor website health, uptime, SEO, security and performance via your AI assistant.
  • io.github.torkjacobs/tork-governance — v1.5.1
    AI agent governance for MCP: PII detection, policy enforcement, compliance, and kill switch.
  • AgentSec MCP — v0.1.0
    Security intelligence via x402 on Base. CVE lookup, IP reputation, secret scanning.
  • Trusteed — v1.0.0
    CTEM for your Trusteed tenant: security summary, findings, compliance gaps, and scans via OAuth.
  • Mund — MCP Security Scanner — v0.1.12
    Scan for prompt injection, secrets, PII, and vet MCP servers before installation
  • io.github.uchit/mcp-regulated-ai-compliance — v0.2.3
    Regulated-industry AI compliance: EU AI Act, APRA, NIST AI RMF, ISO 42001, AU AI Safety.
  • Agent Abilities for MCP — v1.6.0
    Self-hosted WordPress MCP server with per-capability permission controls and a full audit log.
  • Docker Compose Audit — v1.0.0
    Security audit for docker-compose.yml — 25 checks: secrets, privileges, network, volumes, images.
  • Dockerfile Audit — v1.0.0
    Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene.
  • GitHub Actions Audit — v1.0.1
    GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
  • Kubernetes Manifest Audit — v1.0.0
    kube-linter audit for Kubernetes manifests — 63 checks: security, availability, RBAC, network.
  • io.github.VamsiSudhakaran1/release-gate — v0.8.4
    Pre-deploy security auditor for AI agent code — the risks generic SAST misses.
  • MCP-Bastion — v4.0.0
    Security middleware for MCP. Blocks prompt injection, PII leakage, and resource exhaustion.
  • Scout Security — v0.1.7
    Deterministic, zero-token security scanner your AI agent calls to find and re-verify issues.
  • Security Mcp — v1.0.0
    MCP server for Security
  • io.github.vdalhambra/siteaudit-mcp — v1.2.0
    SEO, performance, and security audits for any URL — no API keys required
  • AiEGIS — v1.0.0
    AI agent security and governance. Register, verify, scan, and monitor agents.
  • io.github.venomseven/nslookup — v1.6.0
    DNS lookups, health reports, SSL certs, security scans, GEO scoring, uptime checks
  • Aegis — v0.1.1
    Charter-bound defensive security copilot: secrets, obfuscation, deps, Dockerfile, IaC scans.
  • Attestix — v0.2.2
    AI agent identity, W3C credentials, EU AI Act compliance. 47 MCP tools.
  • Motiv Fleet — v1.0.0
    DeFi MCP fleet: oracle, security audit, treasury yield, QA attestation, and compute tools on Base.
  • Cookie Consent Compliance Scanner — v2.0.0
    Cookie consent scanner: GDPR, CCPA, GCMv2. PASS/FAIL compliance checklists with fix recommendations.

Page 11 of 13

How this page is ordered

Entries are grouped by whether anyone is still working on them, using the date of the most recent push to the repository. They are not ordered by stars, because a star is a bookmark somebody left once and never took back.

Where we have not checked an entry yet, it says so rather than being mixed in with the verified ones.