MCP server for EVM security analysis, gas profiling, compiler diagnostics, and transaction simulation. Provides autonomous coding agents with deterministic, schema-validated tools for Ethereum smart contract development.
★not rated 1 1mo agoA
tokens not measured
originalMIT
Payment firewall for AI agents: a signed, verifiable verdict on every money-moving action. Blocks wrong/lookalike payee, over-cap, and duplicate-invoice fraud before it settles. Non-custodial, local-first.
★not rated 1 1mo agoA
tokens not measured
originalApache-2.0
Screen names against the consolidated OFAC, EU, UK, and UN sanctions lists and resolve legal entities against GLEIF, fuzzy-matched offline over a local SQLite + FTS5 mirror. A screening aid, not a compliance determination.
★not rated 1 13d agoA
tokens not measured
originalApache-2.0
AI governance for agent tool calls: trust scoring, PII/harmful-content guardrails, hallucination detection, and compliance checks (NIST AI RMF, EU AI Act, ISO 42001) via 27 read-only MCP tools.
★not rated 1 2d agoA
tokens not measured
originalMIT
Know Your Agent: fail-closed eval (ALLOW | DENY | REQUIREAPPROVE), dual-plane host=ide|runtime, human approval. This plugin is a thin MCP gate — the control plane is the sole PEP.
★not rated 1 yesterdayA
tokens not measured
originalMIT
Zero-trust AI agent governance for Gemini CLI. Adds ORGA runtime, Cedar policy enforcement, SchemaPin tool verification, and cryptographic audit trails to your development workflow.
★not rated 1 todayB
tokens not measured
originalApache-2.0
A collection of workflows for finding security weaknesses in websites and services, including security-response programs, public testing programs, and bug bounties. The description does not provide enough detail about its individual tools or steps.
Free website privacy scanner to detect pre-consent cookies and trackers, CMP and consent controls, privacy policy, GDPR/ePrivacy and CCPA, and HTTPS/TLS signals.
Checks every Python file Claude writes, before you read it: syntax, lint, types, an AST security policy and a credential scan, with the exact fix when there is one.
★not rated 0 20d agoA
tokens not measured
originalMIT
Document fraud detection for manipulated, fake and AI-generated PDF and image documents, plus identity verification and KYC sessions, age verification, content moderation, face search, AutoDoc invitations, and webhook verification. Bundles the Bynn MCP server.
★not rated 0 13d agoA
tokens not measured
originalMIT
Preflight security for AI-agent development. Run holster guard . to get a RUN verdict and a SHARE verdict on a repo before you hand it to an AI agent, commit it, or share it — catches live API keys, MCP servers that run unpinned code, and credential files missing from .gitignore. Local-first; the repo never leaves yo.
★not rated 0 3mo agoA
tokens not measured
originalMIT
logi Agent Approval Gate — request human approval on a user's phone before an AI agent performs a high-risk action (budget changes, production deploys, payments, mass communications).
★not rated 0 1mo agoA
tokens not measured
originalMIT
Scores the blast radius of a shell command before your agent runs it — advisory, never blocking. Same command, opposite score depending on what it would actually hit.
★not rated 0 29d agoA
tokens not measured
originalApache-2.0
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: