v2.0.0 · Apache-2.0
Deterministic Runtime Execution Governance & Security Circuit-Breaker for DSH & Multi-Agent Workstations
— · Apache-2.0
IAM Policy Autopilot is an open source static code analysis tool that helps you quickly create baseline AWS IAM policies that you can refine as your application evolves. This tool is available as a command-line utility and MCP server for use within AI coding assistants for quickly building IAM policies.
— · MIT
Multi-plugin marketplace for Claude Code offensive security plugins
v1.0.0 · no license
Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
— · MIT
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
— · MIT
Wassette: A security-oriented runtime that runs WebAssembly Components via MCP
— · GPL-3.0
All-in-One malware analysis tool.
— · Apache-2.0
The vendor-neutral protocol for AI agent safety & security — and the neutral benchmark that ranks the vendors.
v0.7.0 · MIT
Tu equipo de desarrolladores en un plugin. 10 agentes, 11 skills planas, 18 comandos /alfred-dev:*. Memoria persistente, quality gates con evidencia y MCP local.
v0.5.6 · MIT
装插件前,先体检:第三方插件 = 进程内全权限代码,这个工具让'盲装'变成'知情安装'——恶意模式、越权路径、未检查依赖,一目了然。Static heuristic vetting for third-party DeepSeek Harness plugins: exfiltration, credential access, over-privileged paths, unvetted dependencies.
v0.2.0 · MIT
DeepSec — AI Security Offense & Defense Platform. Shield audits AI-generated code for hallucinated packages, missing safeguards & AI pattern errors in real time. Spear automates authorized penetration testing with 40+ skill packs, from recon to PoC.
v0.1.3 · AGPL-3.0
Rust MCP server and CLI for Tailscale devices, users, keys, policies, and auth.
v0.2.1 · MIT
Read-only security & compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and local configuration audit with redacted, reproducible reports.
— · MIT
Real-time secret-leak guardrails for AI coding agents (Claude Code, Codex), Git hooks, and CI.
— · Apache-2.0
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
v4.4.9 · MIT
AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.
v1.25.0 · no license
Official SonarQube MCP Server for code quality and security in AI agents
— · MIT
Human-first AI Design Engineer with 8 specialized personas.
v1.4.9 · no license
Don't let AI destroy your hard work! HardStop is a rock-solid protection for AI-generated commands. Pre-execution safety validation for Claude Code, Claude Cowork. Catches dangerous commands before they run: whether from AI mistakes, hallucinations, prompt injection, or misunderstood instructions. Seatbelts for the agentic AI era.
v0.2.2 · no license
Score agent manifests, generate CI workflows, and pull Clarx scan findings into your IDE.