Security

25,252 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

eudi-wallet-mcp

3313

CSOAI-ORG/eudi-wallet-mcp

MCP server Claude CodeCodexCursor +2

EUDI Wallet MCP — EU Digital Identity Wallet under eIDAS 2.0 for AI agent authentication. ISO 18013-5 (mDoc) + W3C VC 2.0 + OID4VC + OID4VP. By MEOK AI Labs. Runs locally from the eudi-wallet-mcp Python package.

not rated 0 2mo ago A tokens not measured

CSOAI-ORG/firmware-attestation-mcp

MCP server Claude CodeCodexCursor +2

Firmware Attestation MCP — hardware trust layer for sovereign AI. Scan firmware, check NSA-ANT-class persistence indicators (BIOS/SMM/HPA/boot-ROM), HMAC-signed firmware attestation, gate AI inference on verified hardware trust. Runs locally from the firmware-attestation-mcp Python package.

not rated 0 3mo ago A tokens not measured original MIT

iso-42005-impact-mcp

3315

CSOAI-ORG/iso-42005-impact-mcp

MCP server Claude CodeCodexCursor +2

ISO/IEC 42005:2025 AI Impact Assessment MCP — runs full lifecycle impact assessment across 6 phases × 7 impact categories. Cross-walks to EU AI Act + ISO 42001. By MEOK AI Labs. Runs locally from the iso-42005-impact-mcp Python package.

not rated 0 3mo ago A tokens not measured original MIT

CSOAI-ORG/csoai-cra-annex-iv-classifier-mcp

MCP server Claude CodeCodexCursor +2

EU Cyber Resilience Act product classifier MCP. Classifies PDEs into CRA hierarchy (default / Class I / Class II / Annex IV per Implementing Reg 2025/2392), audits the 15 Annex I cybersecurity requirements, generates Annex VIII technical docs skeleton, emits HMAC-signed classification certs. Built for 11 Dec 2027…

not rated 0 2mo ago A tokens not measured original MIT

owasp-agentic-mcp

3317

CSOAI-ORG/owasp-agentic-mcp

MCP server Claude CodeCodexCursor +2

OWASP Top 10 for AI Agents security assessment tools. Capabilities: full agent security scan, prompt injection detection, tool poisoning check, excessive agency, data leakage. Built by MEOK AI Labs. Runs locally from the owasp-agentic-mcp Python package.

not rated 0 10d ago A tokens not measured original MIT

compuute-scan

3318

Compuute/compuute-scan-api

Skill Claude CodeCodex

Scan a public GitHub MCP-server repository for security issues before installing or connecting to it. Calls the hosted compuute-scan API at scan.compuute.se and returns severity counts, a 0-100 score, the most severe findings, and an honest triage disclaimer. Use BEFORE recommending or installing an unfamiliar MCP…

not rated 0 20d ago A 122 tokens original MIT

creedspace-mcp-server

3319

Creed-Space/creedspace-mcp-server

MCP server Claude CodeCodexCursor +2

Constitutional-AI safety guardrails for any LLM — personas, constitutions, adjudication. Runs locally from the @creedspace/mcp-server npm package.

not rated 0 1mo ago A tokens not measured original MIT

obsify

3321

Formative-Sum41/obsify

MCP server Claude CodeCodexCursor +2

Local, privacy-preserving PII toolkit over MCP — the model reasons on shape, deterministic local code touches substance, only masked results return. Runs locally from the obsify Python package.

not rated 0 25d ago A tokens not measured original MIT

mailtype

3322

GSterlingPress/mailtype-api

MCP server Claude CodeCodexCursor +2

Email-domain intelligence: MX capability, provider, disposable status, SPF, DMARC, and MTA-STS. Remote server at mailtype-api.onrender.com.

not rated 0 yesterday A tokens not measured

nel-veil

3323

NELPROINC/nel-veil-mcp

MCP server Claude CodeCodexCursor +2

Free passive security scanning - check any domain's DMARC, TLS, headers, and exposures. Runs locally from the nel-veil-mcp npm package. Needs 1 environment variable to run.

not rated 0 11d ago A tokens not measured original MIT

paceproof

3324

RudrenduPaul/PaceProof

MCP server Claude CodeCodexCursor +2

Verifies Ed25519-signed attestation records and builds audit reports via MCP tools. Runs locally from the paceproof-cli npm package.

not rated 0 yesterday A tokens not measured original MIT

shimguard

3325

RudrenduPaul/ShimGuard

MCP server Claude CodeCodexCursor +2

Verify that a GitHub issue closed as "fixed" actually has a merged fix. Catches security issues marked fixed whose PR was never merged. Runs locally from the shimguard-cli Python package.

not rated 0 yesterday A tokens not measured original MIT

tenantguard

3326

RudrenduPaul/TenantGuard

MCP server Claude CodeCodexCursor +2

PyPI wrapper for TenantGuard, a tenant-isolation security-audit CLI for self-hosted multi-tenant AI-agent platforms. Downloads and runs the official prebuilt Go binary from GitHub Releases, Sigstore-verified on first run. Runs locally from the tenantguard-cli Python package.

not rated 0 20d ago A tokens not measured original Apache-2.0

cryptair-mcp-server

3327

Syronius/cryptair-mcp-server

MCP server Claude CodeCodexCursor +2

Tamper-evident attestation tools for AI agents — on-chain receipts on Hedera Hashgraph mainnet. Runs locally from the @cryptair/mcp-server npm package. Needs 3 environment variables to run.

not rated 0 4mo ago A tokens not measured original MIT

weave-browser

3328

Tyox-all/Weave_Protocol

Skill Claude CodeCodex

Use this skill when the user is building, securing, or auditing a browser-based AI agent (Playwright, Puppeteer, Stagehand, browser-use, or custom browser automation). Triggers on requests to "secure my browser agent", "detect prompt injection in web pages", "block my agent from visiting bad URLs", "scan this page for…

not rated 0 21d ago A 144 tokens original Apache-2.0

dockerfile-audit

3329

UnbearableDev/dockerfile-audit

MCP server Claude CodeCodexCursor +2

Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene. Remote server at unbearable-dev--dockerfile-audit.apify.actor.

not rated 0 3mo ago A tokens not measured

docker-compose-audit

3330

UnbearableDev/docker-compose-audit

MCP server Claude CodeCodexCursor +2

Security audit for docker-compose.yml — 25 checks: secrets, privileges, network, volumes, images. Remote server at unbearable-dev--docker-compose-audit.apify.actor.

not rated 0 3mo ago A tokens not measured

github-actions-audit

3331

UnbearableDev/github-actions-audit

MCP server Claude CodeCodexCursor +2

GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection. Remote server at unbearable-dev--github-actions-audit.apify.actor.

not rated 0 3mo ago A tokens not measured

iac-audit-pack

3332

UnbearableDev/iac-audit-pack

MCP server Claude CodeCodexCursor +2

Four IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks. Remote server at unbearable-dev--iac-audit-pack.apify.actor.

not rated 0 3mo ago A tokens not measured

k8s-manifest-audit

3333

UnbearableDev/k8s-manifest-audit

MCP server Claude CodeCodexCursor +2

MCP server "k8s-manifest-audit", hosted remotely at unbearable-dev--k8s-manifest-audit.apify.actor, as configured in UnbearableDev/k8s-manifest-audit.

not rated 0 3mo ago A tokens not measured

mcp-server

3334

Whoisjson/mcp-server

MCP server Claude CodeCodexCursor +2

WHOIS, DNS, SSL, and domain availability lookups for AI assistants. Runs locally from the @whoisjson/mcp-server npm package. Needs 1 environment variable to run.

not rated 0 5mo ago A tokens not measured

clawvault-mcp-server

3336

andrewszk/clawvault-mcp-server

MCP server Claude CodeCodexCursor +2

AI agent payment security - spending limits, whitelists, and human approval. Runs locally from the clawvault-mcp-server npm package. Needs 1 environment variable to run.

not rated 0 6mo ago A tokens not measured

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: