Security layer for AI coding agents. Works with Claude Code, Cursor, Windsurf, Gemini CLI, OpenCode, Pi Agent and more.

Local, read-only audit for stale AGENTS.md, CLAUDE.md, and generic SKILL.md instructions.
Prompt injection scanner for AI coding tools (Claude Code / Codex / etc). Runs DeBERTa/Llama transformers via Candle or ONNX in Rust
List MCP Server configurations in your system used by AI applications like Cursor, Claude Desktop, VS Code and others
Catch dangerous AI agent skills before they catch you. Zero-dependency security scanner for Agent Skills, SKILL.md and MCP configs.
π¦ The API and AI Gateway

OWASP Foundation web repository
MCP server for JADX-AI Plugin

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST β powered by Radare2, YARA, LIEF, Capstone, and more.
Security testing that runs inside the coding agent you already use. Source-available, not open source.

Privacy Code Scanner and Dataflow Context Engine for AI coding agents
Desktop app that automatically scans and blocks malicious MCP traffic in AI apps like Cursor, Claude, VS Code and Windsurf.
ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agents
Let AI agents investigate and operate infrastructure through declared actions, bounded by policy and host-side checks. Approvals when required, with an audit trail. By Protectorate.
Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.
Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.
The Proxmox MCP you can hand the keys. All four products: PVE, PBS, PMG, PDM.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw β 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface β from SQLi to shellcode, EDR evasion to exploit development.
ffprobe for documents β probe PDF, Microsoft Office, and Apple iWork files without opening them. Rust CLI + browser WASM SDK returning structured JSON with confidence, evidence, and measured I/O cost.
Credential gateway for AI agents. Log in once via Oauth2 or API Key. Every agent stays authenticated β headless, no SaaS, agents never see your credentials.
Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
π Lagune is your security copilot as you build, your Blue Team when you audit, whether you're a developer or not (no API key needed).