Sandbox
30 repos for app · Any agent · SecurityClear
appsecco/
pentesting-mcp-servers-checklist

A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.

40
appsecco/
vulnerable-mcp-servers-lab

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

277
stijnswapped/
Myrqen

Security testing that runs inside the coding agent you already use. Source-available, not open source.

158

MCPify is an AI enablement compiler that transforms existing applications into AI-native, agent-operable systems.

96

Remote approvals, policy checks, and execution evidence for unattended AI agents.

301
stacklok/
toolhive-studio

ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agents

163
utkusen/
sast-skills

Collection of agent skills to find vulnerabilities inside your web/mobile apps.

1.3k
decionis/
docker
decionis/dockerConnectors

Govern consequential AI agent actions in Docker with deterministic policy, human approval, and signed Decision Dossiers.

166
spring-ai-community/
spring-ai-playground

Safe local execution layer for AI agent tools. Build, validate, and publish MCP tools with a no-pass-no-run workflow — cross-platform desktop app powered by Spring AI.

137

MCP servers for the UniFi suite of applications, Network, Protect, Access, and Drive

803
nwiizo/tfmcpConnectors

🌍 Terraform Model Context Protocol (MCP) Tool - An experimental CLI tool that enables AI assistants to manage and operate Terraform environments. Supports reading Terraform configurations, analyzing plans, applying configurations, and managing state with Claude Desktop integration. ⚡️

371

List MCP Server configurations in your system used by AI applications like Cursor, Claude Desktop, VS Code and others

84

All-in-One Desktop Agent Skills Utility. Welcome to the Skill Zoo, where all your skills live!

110
deckflow/
deckprobe

ffprobe for documents — probe PDF, Microsoft Office, and Apple iWork files without opening them. Rust CLI + browser WASM SDK returning structured JSON with confidence, evidence, and measured I/O cost.

120
lensesio/
agentic-engineering-for-apache-kafka

AI agent skills for building, operating and troubleshooting Apache Kafka applications. Topic audit, consumer lag, schema review, security, connectors and DLQ

57

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 200+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.

4.4k
Agile-V/
agile_v_skills

Agent Skills for traceable requirements, independent verification, human approval gates, and auditable AI-assisted engineering. Supports Claude Code, Cursor, VS Code, and GitHub Copilot; ISO 9001/27001 aligned (design phase), GxP-aware.

53
astrid-runtime/
astrid
astrid-runtime/astridFrameworks & SDKs

Astrid is a portable, capability-secure operating system for composable software.

10k
onecli/onecliHarnesses

Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.

3.5k
TheLunarCompany/
lunar

lunar.dev: Agent native MCP Gateway for governance and security

491
runxhq/
runx

the governed runtime for agent skill workflows, off the leash but on the record

84

Security testing toolkit for AI Agent: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties

380
Robotti-io/
copilot-security-instructions

✨ A customizable copilot-instructions.md ruleset & prompts to guide GitHub Copilot toward secure coding defaults in Java, Node.js, C# and Python. Blocks risky patterns, teaches safe habits.

42