Fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
Scan any agent skill — authored or compiled — for prompt injection, secrets, and malicious execution before it touches your agent. Or compile the long tail on the fly.
Published in CNCF Landscape: A MCP server for Kubernetes.
Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt injection, supply chain etc in a local dashboard. Agent agnostic (Claude, codex, langchain etc.)

Connect any AI model to 1200+ integrations (MCP, CLI, API)
A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/project, then run /bob-evaluate target.com
A Model Context Protocol (MCP) server that enables LLMs to run ANY code safely in isolated Docker containers.
Govern consequential AI agent actions in Docker with deterministic policy, human approval, and signed Decision Dossiers.
MCP server for interaction with Bitwarden.
MCP server for AI agents that need a phone number: order a private number in 200+ countries, read the SMS verification code, hand it back. The widest country coverage in the category, and you can check it with one API call.

Local, read-only audit for stale AGENTS.md, CLAUDE.md, and generic SKILL.md instructions.
Production-grade Agent Skills from Evil Martians — drop-in expertise for your AI coding agent
All-in-One Desktop Agent Skills Utility. Welcome to the Skill Zoo, where all your skills live!

All-in-One malware analysis tool.

The security-first skill manager for AI agents — every install runs a security scan. Manage skills & MCP servers across 87 agents. Zero-dependency CLI.
Code Execution Sandbox Platform Solution for Individuals and Small Teams with MCP
Security testing that runs inside the coding agent you already use. Source-available, not open source.
Desktop app that automatically scans and blocks malicious MCP traffic in AI apps like Cursor, Claude, VS Code and Windsurf.
Find and repair substance defects in AI-assisted prose, code, docs, and agent output. Reports defects, never authorship. Structural tests over model judgement, because LLM judges agree with human slop labels at chance.
The official Go SDK for Model Context Protocol servers and clients. Maintained in collaboration with Google.
Skills to transform AI Agents into GitOps Engineers
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
Write detections, investigate alerts, and query logs from your favorite AI agents
ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agents