ZBS Index What actually exists in applied AI, with the source next to it

Security

Everything here was classified as security by keyword match against the maintainer's own description, so treat the grouping as a starting point rather than a verdict.

The list is ordered by the most recent commit, not by stars. A popular project that stopped in 2024 is not a better answer than a smaller one shipped last week.

Worked on in the last 90 days (60)

Someone pushed a commit recently. This is the shortlist worth trying first.

  • Avalara E-Invoicing & Live Reporting — last commit 2026-07-30, v1.0.0
    Provides access to Avalara E-Invoicing and Live Reporting APIs for document statuses and compliance
  • Avalara Returns — last commit 2026-07-30, v1.0.1
    Provides access to Avalara Global Returns API for tax returns, filing calendars, and compliance data
  • TridentChain Security — last commit 2026-07-29, v0.1.5
    Local supply-chain CVE scanner via OSV/NVD. Scans deps and IDE extensions. No upload.
  • io.github.Achilles1089/pentagonal-mcp — last commit 2026-07-27, v1.0.1
    AI smart contract forge — 8-agent security audits, generation, and compilation across 8 chains
  • io.github.bch1212/queryshield — last commit 2026-07-27, v1.0.1
    Secure SQL proxy for AI agents — NL→SQL, AST safety, per-agent RLS, audit log.
  • DDG Agent Services — last commit 2026-07-27, v0.5.0
    Pay-per-call x402 gateway: agent tools, OpenAI-compatible LLM, market data, RPC, security audits.
  • io.github.CSOAI-ORG/watermarking-authenticity-mcp — last commit 2026-07-26, v1.2.3
    EU AI Act Article 50 watermarking + C2PA 2.1 compliance. NEW: 2 December 2026 deadline (compress...
  • io.github.Bishop81/domainintel-mcp — last commit 2026-07-24, v1.0.2
    Domain intelligence for agents: WHOIS, DNS, SSL/TLS, security headers, reputation, subdomains.
  • io.github.denial-web/agent-immune — last commit 2026-07-24, v0.2.2
    AI agent security: prompt injection detection, semantic memory, output scanning, prompt hardening
  • io.github.goklab/guardvibe — last commit 2026-07-23, v3.31.0
    Deterministic security layer your AI can't be. 462 rules, 39 tools, CLI + doctor + host audit.
  • com.oksigenia/checker-mcp — last commit 2026-07-22, v0.1.1
    Domain security & privacy checker as an MCP server. 17 live checks, 0-100 score, local-first.
  • io.github.H129hj/checkmcp — last commit 2026-07-22, v0.5.0
    Audit any MCP server's security & quality — OWASP MCP Top 10 + explainable 0-100 MCP Score
  • Phantom Secrets — last commit 2026-07-22, v0.6.0
    Stop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm_ tokens.
  • io.github.atef-ataya/depwire — last commit 2026-07-21, v1.8.7
    Dependency graph + 23 MCP tools. Impact analysis, simulation, security, agent coordination
  • UML Forge — last commit 2026-07-21, v0.1.9
    Architecture intelligence, security analysis, and living docs. 13 Mermaid tools.
  • loudcheck — last commit 2026-07-21, v0.3.1
    Loudness compliance verdicts (EBU R128, ATSC A/85): pass/fail with exact ffmpeg remediation.
  • cloud-audit — last commit 2026-07-21, v2.0.1
    AWS security scanner with attack chain detection, IAM privilege escalation, and fixes
  • MikroMCP — last commit 2026-07-21, v1.8.0
    MCP server for MikroTik RouterOS: typed tools, dry-run, RBAC, audit logs, and rollback.
  • io.github.dir-ai/voyager-browser — last commit 2026-07-20, v0.7.0
    Voyager's web-page sense: safe read-only observation of one live URL (structure, security, a11y).
  • Ansvar: EU Compliance & Legal Intelligence — last commit 2026-07-20, v1.0.b661c6dc
    Cited EU & global law, regulations & security frameworks via Ansvar Gateway. OAuth, free + paid.
  • Ansvar: Threat Intelligence — last commit 2026-07-20, v1.0.70ca253c
    CVE intelligence, STRIDE, OWASP test cases via Ansvar Gateway. Cited, OAuth + paid.
  • com.secdim/mcp — last commit 2026-07-20, v1.0.1
    Personalised developer security learning pathways from SecDim's challenges and courses.
  • io.github.Braynexservices/nigeria-nigsac-sanctions — last commit 2026-07-19, v0.1.1
    Screen a name vs Nigeria's NIGSAC sanctions register. Best-effort signal, not compliance-grade.
  • io.github.0xsims/rubric-protocol — last commit 2026-07-19, v2.0.2
    AI compliance attestation for EU AI Act, SR 11-7, HIPAA. Free local tier, no key required.
  • GDPR Scanner API — last commit 2026-07-19, v1.1.0
    Scan website GDPR compliance: consent, privacy policy, trackers. Score 0-100. x402.
  • HTTP Headers Analyzer API — last commit 2026-07-18, v1.1.0
    HTTP header analysis — security headers, cache, server detection. x402 micropayment.
  • io.github.feelyday/kadlint — last commit 2026-07-18, v0.1.1
    Korean ad-compliance linter for cosmetics and health-food marketing copy
  • Black Duck Security Scanner — last commit 2026-07-17, v1.1.8
    AI-powered security scanning using Black Duck Signal for vulnerability detection.
  • Grasp — Code Architecture & Dependency Analysis — last commit 2026-07-17, v3.21.0
    Codebase analysis: dependency graphs, security scanning, and refactor plans for GitHub and GitLab.
  • Cinderfi — Retirement Planning — last commit 2026-07-16, v1.0.1
    Retirement planning for Canada & US. CPP/OAS, Social Security, RRSP/TFSA, 401k/IRA, Monte Carlo.
  • Cybersecurity Threat Intelligence MCP — last commit 2026-07-16, v1.0.0
    CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
  • Regulatory & Compliance Intelligence MCP — last commit 2026-07-16, v1.0.0
    Regulatory compliance, FDA recalls, federal register, enforcement actions & comment deadlines.
  • Toolcall — last commit 2026-07-16, v1.0.0
    30 pay-per-call APIs for AI agents: compliance, trade, safety, web, data. USDC on Base via x402.
  • io.github.codespar/mcp-niubiz — last commit 2026-07-16, v0.1.0
    MCP server for Niubiz — Peru card acquirer: security token, session, authorize, reverse
  • Facture Électronique France — last commit 2026-07-15, v0.8.0
    MCP server for French e-invoicing (XP Z12-013). Manages invoices, validation and compliance.
  • Mailbuttons (mbag.ai) — last commit 2026-07-15, v0.1.2
    Governed email for AI agents (Mailbuttons / mbag.ai): sandbox inboxes, policy gate, audit log.
  • mcp-erid — last commit 2026-07-14, v0.1.4
    Russian ad marking (38-FZ) checker: erid validation, ad-page audit, compliance hints.
  • mcpwall — last commit 2026-07-13, v0.1.2
    iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything.
  • io.github.aristiun/aribot — last commit 2026-07-13, v1.0.0
    Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
  • io.github.Easton-OU/rootpilot-ssh-diagnose — last commit 2026-07-13, v0.1.2
    Read-only SSH server diagnostics via a fixed 38-command whitelist; secrets redacted, no write path.
  • io.github.datahogo/datahogo — last commit 2026-07-12, v0.1.3
    Scan a project for security issues locally with the open-source Data Hogo engine.
  • Touchstone — last commit 2026-07-10, v1.1.0
    Bitcoin-anchored, tamper-evident audit log for AI agents — record, disclose and verify actions.
  • io.github.attestd-io/attestd-mcp — last commit 2026-07-09, v0.2.1
    CVE and supply chain checks for MCP clients. Covers infrastructure, PyPI, and npm packages.
  • Purify Security Feeds — last commit 2026-07-09, v1.0.1
    Query CISA KEV / EPSS vulnerability feeds with full per-record provenance and auditable versions
  • io.github.cx-anand-nandeshwar/dlp-mcp — last commit 2026-07-08, v1.0.0
    The DLP MCP provides the compliance violation in the one drive, google drive documents.
  • OnchainDiligence — last commit 2026-07-08, v1.1.0
    Pay-per-call compliance via x402: wallet sanctions, OFAC name, UK + US company verification.
  • io.github.100xPercent/pop-pay — last commit 2026-07-07, v0.5.7
    Runtime security for AI agent commerce. CLI + MCP server blocks hallucinated purchases.
  • ThinkNEO Control Plane — last commit 2026-07-06, v1.29.0
    Enterprise AI Control Plane: governance, guardrails, spend tracking, compliance & smart routing.
  • Bawbel Scanner — last commit 2026-07-05, v1.1.1
    Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
  • Bawbel Scanner — last commit 2026-07-05, v1.2.3
    Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
  • HTTP — last commit 2026-07-04, v0.1.0
    HTTP/REST client with saved collections, env secrets, and SSRF-safe host allowlisting.
  • Compuute MCP Security Scanner — last commit 2026-07-03, v0.3.0
    Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
  • io.github.AIWerk/mcp-server-vault — last commit 2026-07-03, v0.2.1
    Bitwarden/Vaultwarden for agents: list tagged items, TOTP codes, one-time Sends, save new secrets.
  • Tripwire — last commit 2026-07-02, v0.2.5
    MCP for Roblox Studio and Open Cloud: drive Studio, run headless tests, and review game security.
  • Aguara MCP — last commit 2026-07-01, v0.2.0
    Security scanner for AI agent skills and MCP servers
  • ai.marchward/mcp-server — last commit 2026-07-01, v0.2.4
    Runtime authority for AI agents: credential mediation, spend cap, approval gates, audit log.
  • io.github.fpetitit/mcpcheckup — last commit 2026-06-28, v0.1.0
    Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.
  • io.github.CSOAI-ORG/eu-ai-act-compliance-mcp — last commit 2026-06-27, v1.8.12
    Eu Ai Act Compliance MCP Server by MEOK AI Labs
  • io.github.CSOAI-ORG/mica-crypto-mcp — last commit 2026-06-26, v1.0.7
    Markets in Crypto-Assets (MiCA) Regulation (EU) 2023/1114 compliance for EU crypto-asset issuers...
  • io.github.CSOAI-ORG/cra-compliance-mcp — last commit 2026-06-26, v1.3.15
    EU Cyber Resilience Act (Regulation 2024/2847) compliance for AI agents. Product classification...

Page 2 of 13

How this page is ordered

Entries are grouped by whether anyone is still working on them, using the date of the most recent push to the repository. They are not ordered by stars, because a star is a bookmark somebody left once and never took back.

Where we have not checked an entry yet, it says so rather than being mixed in with the verified ones.