Agent Skills

Security

202 servers.

Browse

phantom-secretsashlrai16Stop AI coding agents from leaking your API keys. Local proxy + MCP that swaps real secrets for phm_ tokens — works with Claude Code, Cursor, Windsurf, and Codex.mcp-hangarmapyr16MCP policy enforcement plane — deterministic policy on every Model Context Protocol call: identity, RFC 8707 audience binding, tool schema digest pinning, full audit trail. Python, self-hosted, MIT.mcp-hangarmcp-hangar16MCP policy enforcement plane — deterministic policy on every Model Context Protocol call: identity, RFC 8707 audience binding, tool schema digest pinning, full audit trail. Python, self-hosted, MIT.pre-production-checklistFarzamHabibi15Pre-production checklists for solo founders. 4,394 items, 87% portable to any stack, 26 stack supplements — plus AI/agent security and the bugs AI coding assistants actually write.mitre-mcpMontimage15A Model Context Protocol (MCP) server that provides tools for working with the MITRE ATT&CK framework using the mitreattack-python library and the official MCP Python SDK.reasongatecgrtml15Explainable security gate for LLM apps — blocks prompt injection with an auditable reason for every decision.requestrepo-mcphofill15A requestrepo MCP.prodlintprodlint15Your vibe-coded app has hardcoded secrets, missing auth, and hallucinated imports. Find out in under a second.s-gwsgateway15Local credential control for AI coding agents.automox-mcpAutomoxCommunity14An MCP server implementation for AutomoxSuricataMCPMedinios14SuricataMCP is a Model Context Protocol Server that allows MCP clients to autonomously use suricata for network traffic analysis. It enables programmatic interaction with Suricata through tools like get_suricata_version, get_suricata_help, and get_alerts_from_pcap_file.aegisgetaegis14Credential isolation for AI agents. Local-first transparent proxy — your agent never sees your API keys.OsqueryMcpServerkousen14MCP wrapper and Claude Code Skill for osquerypeacpeacprotocol14Portable signed records for automated interactions.platformsidclawhq14The approval and accountability layer for agentic AI. Identity → Policy → Approval → Trace. Try: npx sidclaw-democow-mcpComplianceCow13This repository contains the MCP servers for ComplianceCow. It leverages four specialized servers—Rules, Insights, Workflow, and Assistant—to automate GRC tasks, execute compliance rules, and visualize security posture through the Compliance Graph. These MCP servers can be seamlessly integrated with MCP hosts such as Claude Desktop and Goose.heliogethelio13Governance proxy for MCP: block or hold AI agent tool calls on their arguments, route approvals with the arguments shown, enforce rules the model cannot argue with, require prerequisites, cap cumulative spend across tools and servers, and audit every call. No changes to agent code or MCP servers.ida-pro-mcpgrecandrei13Local-first, deterministic MCP server for IDA Pro/Home: 109 strict-schema reverse-engineering operations, evidence-backed findings, and policy-gated IDB edits.ntobjmanager-mcplupingQAQ13A Model Context Protocol (MCP) server that gives AI agents live, stateful Windows RPC attack-surface research, built on James Forshaw's NtObjectManager (NtCoreLib).mcpvanguardprovnai13Open-source security gateway for MCP agents and tools. Inspect tool calls before execution, enforce policy, block risky operations, and emit audit-ready evidence.vaaravaaraio13Accountable Autonomy: open-source evidence layer that gates every AI agent tool call against your policy and writes a hash-chained record an auditor verifies offline, without trusting you. Root-agnostic; binds to TPM 2.0 / SEV-SNP when present. Your environment, no SaaS, no telemetry. AGPL-3.0.bomly-clibomly-dev12Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.tap-ossholonym-foundation12Credential isolation for AI agents — stop leaking secrets to your agents. TAP is a credential proxy: agents never see secret values; optional human approval on sensitive calls. By human.tech (Apache-2.0).identarkidentArk12Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.infrabrokerluisgf12Infrastructure access broker for AI agents — SSH & Kubernetes. Per-operation ephemeral credentials minted by a separate signer; the model never touches one. MCP stdio / HTTP+OIDC.sast-skillsmstfknn12Collection of agent skills that turn your AI coder into a SAST scannerpqc-toolsquantakrypto12Open-source post-quantum readiness tooling by quantakryptoreptor-mcpslvnlrt12MCP server for reptor/SysReptorProject-Komaswnotmetal12Lightweight, agent-friendly AI security toolkit for Node.js & TypeScript. Check if your agent has loaded the skill, Stop prompt injection, audio hallucinations, and RAG data scraping. Zero dependencies. MITcrypto-mcp159590162411A Model Context Protocol (MCP) server for encrypting/decrypting/algorithm/hashshieldAperionAI11Local guardrails for AI coding agents. Wraps any MCP server and blocks destructive tool calls — DROP TABLE, rm -rf, force-push, unscoped UPDATE/DELETE — before they execute. Free, open-source, runs entirely on your machine.pkgxrayadamsjack711-ux11Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.illumio-mcp-serveralexgoller11The first MCP server for cybersecurityvulnicheckandrasfe11Python vulnerability scanner & MCP security toolkit. Real-time dependency checking via OSV/NVD/GitHub Advisory DBs, Docker analysis, secrets detection, MCP config validation, LLM-powered risk assessment & interactive security audits. Full CVE details, CVSS scores & remediation guidance.mcp-eu-ai-actark-forge11MCP EU AI Act Compliance Scanner - Open source tool to detect EU AI Act violations in codebasescontrolkeelaryaminus11Agent control plane for governed AI coding: validate changes, enforce policy gates, track findings, proofs, and evals based on your habits.bawbel-scannerbawbel11Open-source CLI scanner for agentic AI components such as skills, MCP servers, system promptsscannerbawbel11Open-source CLI scanner for agentic AI components such as skills, MCP servers, system promptsjoesandboxMCPjoesecurity11MCP for Joe Sandbox Cloudfortinet-mcp-serverpaoloamato211A complete Model Context Protocol (MCP) server for Fortinet FortiOS 7.6.6assayrul1an11Open evidence profile for MCP tool actions. Enforce configured tool-call policies and record decisions and observations in offline-verifiable bundles. Optional Linux kernel controls. No hosted backend required.aletheia-mcpvikasny3011Model Context Protocol (MCP) server for Aletheia: Sub-millisecond runtime safety & scope creep (S3) filter for AI agent tool callshacktricks-mcp-serverXplo8E10Bring HackTricks pentesting knowledge into Claude Desktop. Search 1000+ security techniques, exploits, and payloads without leaving your AI assistant. MCP-powered, npx-ready.vaultmcpaxiler-lab10Encrypted credential vault and remote MCP gatewaysecretctlforest651110The simplest AI-ready secrets manager. Local-first, single-binary CLI & Desktop app with MCP integration. Never expose secrets to AI agents.bug-bounty-intelligence-mcpholistis10MCP server that scans Solidity repos through a 7-gate verification framework (Al-Mizaan) to cut LLM false positives, benchmarked against Slither; free pattern-search from 1,032 reconciled Sherlock findings, paid full scan via x402 (USDC/Base).stackhawk-mcpstackhawk10An MCP server that provides interaction with StackHawk's security scanning platform.indexstarloghq10Vet a package before your AI coding agent uses it — authoritative facts (CVEs, license, maintenance) via an MCP server + CLI. Local, no account.scopeblind-gatewaytomjwxf10Active development continues at ScopeBlind/scopeblind-gateway. - Security gateway for MCP servers. Cedar policy engine, Ed25519-signed receipts, per-tool enforcement. IETF Internet-Draft. 4 patents pending. npx protect-mcpmcpvulncheck-oss10Official VulnCheck MCP Server

Search skills and MCP servers

Fuzzy search across 23,137 skills and servers