Sandbox
365 repos for security · SecurityClear
openziti/
mcp-gateway

Zero trust gateway for MCP servers. Aggregate, filter, and securely access MCP tools from anywhere without VPNs, open ports, or exposed endpoints. Built on OpenZiti, zrok, and Agora with cryptographic identity, mTLS, per-client isolation, and tool-level permission control.

48
NVIDIA/
SkillEvaluator

Multi-tier framework for evaluating AI agent skills with quality gates, semantic overlap detection, synthetic evaluation dataset generation, and live agent evaluation that measures how skills affect agent behavior.

424
Cyreslab-AI/
shodan-mcp-server

A Model Context Protocol server that provides access to Shodan API functionality

47
utkusen/
sast-skills

Collection of agent skills to find vulnerabilities inside your web/mobile apps.

1.3k
agentrhq/
authsome

Credential gateway for AI agents. Log in once via Oauth2 or API Key. Every agent stays authenticated — headless, no SaaS, agents never see your credentials.

88
w0h1v/
mcp-shodan

MCP server for Shodan — search internet-connected devices, IP reconnaissance, DNS lookups, and CVE/CPE vulnerability intelligence. Works with Claude Code, Codex, Gemini CLI, and Claude Desktop.

166
GRCEngClub/
claude-grc-engineering

Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.

398

Local-first MCP password and credential manager for AI agents. Use passwords, API keys, SSH identities, and TOTP without exposing hidden plaintext to the model.

125
PatrikFehrenbach/
h1-brain

MCP server that connects AI assistants to HackerOne for bug bounty hunting

350

Connect any AI model to 1200+ integrations (MCP, CLI, API)

3.4k

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida, proxy/VPN/frp/P2P networking, MCP/Agent, 160+ APIs, designed for multi-device clusters and engineered deployments.

8.3k
GitGuardian/
ggmcp

MCP server for remediating hardcoded secrets using GitGuardian’s API. It detects over 600 secret types and prevents credential leaks before code is made public.

37
ADScanPro/
Claude-AD

Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay, delegation), with per-technique OPSEC/telemetry notes. Drives netexec, impacket, certipy, bloodyAD, BloodHound CE.

193

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

95
ctxray/
ctxray

See how you really use AI — X-ray your AI coding sessions locally

46

Prompt injection scanner for AI coding tools (Claude Code / Codex / etc). Runs DeBERTa/Llama transformers via Candle or ONNX in Rust

45
appsecco/
vulnerable-mcp-servers-lab

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

277

Containment for AI agents - user isolation, sandboxed execution, network controls, backup/rollback. TLA+ verified.

173

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

1.5k