— · no license
SAIL V2 (Secure AI Lifecycle) as an agent skill — the full 91-risk catalog for AI/agent gap assessments, security roadmaps, and compliance checklists. Installs on Claude Code, Codex, ChatGPT, Antigravity, and any SKILL.md-compatible agent.
v4.4.9 · MIT
AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.
— · MIT
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
— · no license
🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️
v0.0.1 · Apache-2.0
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
— · no license
Enables hands-on exploration of common MCP security vulnerabilities through locally runnable vulnerable and fixed servers with accompanying exploits and a dashboard.
v2.4.0 · AGPL-3.0
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
v1.4.0 · MIT
Security auditor for AI agent configurations. Scans Claude Code setups for vulnerabilities, misconfigs, and injection risks.
v1.0.5 · MIT
Complete reverse-skill (85 SKILL.md) as a DeepSeek Harness (dsh) Cordis plugin — reverse engineering, authorized pentesting and security research skill pack.
— · MIT
Audit and fix your Mac's security in one command. No agent, no signup, open source.
v0.2.0 · MIT
DeepSec — AI Security Offense & Defense Platform. Shield audits AI-generated code for hallucinated packages, missing safeguards & AI pattern errors in real time. Spear automates authorized penetration testing with 40+ skill packs, from recon to PoC.
v2.0.0 · Apache-2.0
Deterministic Runtime Execution Governance & Security Circuit-Breaker for DSH & Multi-Agent Workstations
v0.2.1 · MIT
Read-only security & compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and local configuration audit with redacted, reproducible reports.
v2.4.13 · SEE LICENSE IN LICENSE
AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.
— · MIT
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
v1.25.0 · no license
Official SonarQube MCP Server for code quality and security in AI agents
— · Apache-2.0
The vendor-neutral protocol for AI agent safety & security — and the neutral benchmark that ranks the vendors.
— · no license
Claude Code plugin for Java JAR security audit — 基于 jar-analyzer 的 Claude Code 安全审计插件,构建数据库,AI 深入分析
— · MIT
lunar.dev: Agent native MCP Gateway for governance and security
— · MIT
Multi-plugin marketplace for Claude Code offensive security plugins
— · Apache-2.0
A security scanner for your LLM agentic workflows
— · MIT
A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.
— · MIT
🪝 Claude Code hooks + an installable plugin marketplace: safety, cost, observability, productivity.
v0.12.0 · Apache-2.0
Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.