Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.
Rust MCP server for comprehensive code intelligence - 90 tools, 32 languages, security scanning, call graphs, and more

A security scanner for your LLM agentic workflows
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
Evidence-grounded repository audit CLI - deterministic scanner, MCP server, live dashboard, and a GitHub Action that posts PR diffs.
The AI security agent guards your code.
Security testing that runs inside the coding agent you already use. Source-available, not open source.
Agent Skills Evaluation Framework
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
Troubleshooting skills for Alibaba Cloud ECS
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.
A modular external attack surface mapping tool integrating tools for automated reconnaissance and bug bounty workflows.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.
Multi-tier framework for evaluating AI agent skills with quality gates, semantic overlap detection, synthetic evaluation dataset generation, and live agent evaluation that measures how skills affect agent behavior.
Find and repair substance defects in AI-assisted prose, code, docs, and agent output. Reports defects, never authorship. Structural tests over model judgement, because LLM judges agree with human slop labels at chance.
Turn existing CAE files into structured text an agent can use — COMSOL, Abaqus, Fluent, HFSS, Icepak, FloTHERM — plus solver detection, script linting, and live solver sessions. Strong coverage for electronics thermal and advanced packaging.
Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt injection, supply chain etc in a local dashboard. Agent agnostic (Claude, codex, langchain etc.)