Security Scanner for Agent Skills
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.
Vetix — Automated scanning, identification, and assessment of SKILL security risks.
Open-source AI security scanner for Codex, Claude Code, and ACP-compatible coding agents—kept current with OpenAI Codex Security.

Privacy Code Scanner and Dataflow Context Engine for AI coding agents
Prompt injection scanner for AI coding tools (Claude Code / Codex / etc). Runs DeBERTa/Llama transformers via Candle or ONNX in Rust

A security scanner for your LLM agentic workflows
Catch dangerous AI agent skills before they catch you. Zero-dependency security scanner for Agent Skills, SKILL.md and MCP configs.
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Cross-Code Organizer (formerly Claude Code Organizer): cross-harness config dashboard for Claude Code, Codex CLI, MCP servers, skills, memories, agents, sessions, security scanning, context budget, and backups.

The security-first skill manager for AI agents — every install runs a security scan. Manage skills & MCP servers across 87 agents. Zero-dependency CLI.
Trivy plugin for starting an MCP server
Security testing that runs inside the coding agent you already use. Source-available, not open source.
Static Code Analysis for security teams with Inter file taint analysis. Built for finding vulnerabilities, advanced structural search, derive insights and supports MCP
Agent Skills Evaluation Framework

Solidity Static Analyzer that easily integrates into your editor
Troubleshooting skills for Alibaba Cloud ECS
Collection of agent skills to find vulnerabilities inside your web/mobile apps.
MCP server for remediating hardcoded secrets using GitGuardian’s API. It detects over 600 secret types and prevents credential leaks before code is made public.
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.
A modular external attack surface mapping tool integrating tools for automated reconnaissance and bug bounty workflows.
AI-powered bug bounty hunting toolkit that works with or without subscription.
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.