v1.5.0 · MIT
AI coding assistant skills for building CrowdStrike Falcon Foundry apps: scaffolding, deployment, and best practices for API integrations, collections, functions, UI extensions, UI pages, and workflows.
— · MIT
Real-time secret-leak guardrails for AI coding agents (Claude Code, Codex), Git hooks, and CI.
— · MIT
27 scope-enforced AI agents that run the full pentest kill-chain (recon → exploit → post-ex → DFIR → report) as a one-command Claude Code plugin. Backed by 754 MITRE-mapped skills.
v2.4.13 · SEE LICENSE IN LICENSE
AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.
v1.9.1 · MIT AND Apache-2.0
Local-first usage, cost, quota, account, and forecast analytics for DeepSeek Harness Web, with coding-subscription OAuth sign-in (Grok Build, Codex, Kimi Code, Claude Code), an optional loopback API gateway, and opt-in local auth/usage monitoring
— · MIT
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
v0.1.10 · MIT
DeepSeek Harness 管理员验证网关插件 — 自起独立 HTTP 网关,密码登录 + 反向代理 + WebSocket/SSE 透传,防止未授权访问
— · MIT
Wassette: A security-oriented runtime that runs WebAssembly Components via MCP
v0.0.2 · MIT
Probe any ACP-compatible agent for its capabilities (models, modes, configOptions, prompt capabilities, auth methods, MCP transports). No real prompt required; no token cost.
— · MIT
Runtime guardrails for Claude Code. Auto-approve what's safe, gate what's risky, block what's dangerous. Dual enforcement, full audit trail. MIT.
— · GPL-3.0
All-in-One malware analysis tool.
— · Apache-2.0
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
— · MIT
AI-powered whitebox penetration testing plugin for Claude Code. 9 languages, 22 skills, 7 autonomous agents. STRIDE threat modeling, OWASP 2025 coverage, polyglot monorepo support.
v0.1.0 · MIT
Claude Code plugin that analyzes your project, asks 3 questions, and generates a complete payment integration (Stripe · Mercado Pago · Wompi · Lemon Squeezy + frontend + DB + signed webhook + customer portal + refund). Local-first, security-enforced via PostToolUse hooks. Bilingual ES/EN.
v4.4.9 · MIT
AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.
— · Apache-2.0
IAM Policy Autopilot is an open source static code analysis tool that helps you quickly create baseline AWS IAM policies that you can refine as your application evolves. This tool is available as a command-line utility and MCP server for use within AI coding assistants for quickly building IAM policies.
v1.25.0 · no license
Official SonarQube MCP Server for code quality and security in AI agents
— · Apache-2.0
The vendor-neutral protocol for AI agent safety & security — and the neutral benchmark that ranks the vendors.
v1.0.0 · Apache-2.0
CVE hunting harness for Claude Code - 20 skills, 5-agent team, systematic vulnerability research with false positive elimination
— · Apache-2.0
MCP server for JADX-AI Plugin
— · no license
Claude Code plugin for Java JAR security audit — 基于 jar-analyzer 的 Claude Code 安全审计插件,构建数据库,AI 深入分析
v0.1.3 · MIT License
Enables AI agents to perform passive security scans on domains, checking email spoofing (DMARC/SPF/DKIM), TLS weaknesses, security headers, exposed files, and subdomain-takeover risk without needing an API key.
— · MIT
Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)
— · MIT
Human-first AI Design Engineer with 8 specialized personas.