MCP security scanner — vet a Model Context Protocol server before you add it to Claude Code, Cursor, or Windsurf. Grades it A–F, catching credential theft, tool-poisoning, and install-script payloads
pranee54/AgentDoctorLocal CLI that audits coding-agent configuration for security, instructions, context, and MCP — no API key or code upload by default.
sgateway/s-gwLocal credential control for AI coding agents.
frangelbarrera/code-review-agent-mcpAI code review agent MCP server. Reviews code like a kernel maintainer: blunt, technical, no sugarcoating. Detects bugs + OWASP Top 10 security vulnerabilities. 4 harshness levels. Anti-RLHF.
proluct/skannaSecurity scanner for Claude Code skills, plugins, and MCP servers. A verdict before you install.
fengyincheng/ShellBridgeGive ChatGPT fast, safe, and auditable visibility into your VPS through MCP.
neomatrix369/tripwireSandboxed security scanning for AI skills and MCP servers — precise findings, heatmap posture, fail-closed agent guard. Multi-scanner security platform for AI skills and MCP servers, scan what the age
davidnichols-ops/trustcardCryptographic trust infrastructure for MCP servers — signed manifests, TOFU pinning, two-gate enforcement, and the "npm audit" scanner.
fncreator22/sentinel-mcpA 3-stage safety guardrail agent for LLM coding assistants (Claude Desktop, Cursor, CodeX) via MCP protocol.
TeodorMCP/universal-connector-mcpUniversal MCP server: connect any OpenAPI/Swagger, GraphQL, gRPC or SOAP API to AI agents. Security-first, local, token-efficient. Any API. One server.
sainitish1609/mcp-guard🛡️ Ultra-fast local security firewall, secret sanitizer, and context token compressor for Claude Code, Cursor, and MCP AI agents.
eltociear/mcp-auditScan MCP servers & AI-agent skills for malicious patterns (prompt injection in tool descriptions, credential exfil, download-and-execute). 17 patterns / 60 signatures, zero-dep. Measured over 196 publ
plusky/bugwardenSecurity-guarded MCP server for Bugzilla, written in Rust