Security

24,943 mods in this category, of every kind an agent can take. Each one carries what it costs per session, what the scan found, and whether it is the original.

trestle

1609

toro-guapo/trestle

MCP server Claude CodeCodexCursor +2

Detects leaked secrets (API keys, tokens, private keys) in source code. Runs locally from the @trestlescan/mcp npm package.

not rated 2 2mo ago A tokens not measured original Apache-2.0

registry

1610

PolicyLayer/mcp

MCP server Claude CodeCodexCursor +2

The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install. Remote server at api.policylayer.com.

not rated 2 2mo ago A tokens not measured original MIT

dns-doctor

1611

dnsdoctor/claude-plugin

Plugin Claude Code

Bundles 1 skill, 1 MCP server · 177 tokens together

Scan, fix, verify and monitor a domain's DNS: email authentication (SPF, DMARC, DKIM) with DMARC monitoring and evidence-based enforcement guidance, plus multi-region propagation, SPF include supply-chain audits, MX, DNS health, blacklists and domain/SSL expiry. Returns deterministic verdicts and copy-paste fix…

not rated 2 changed 3d ago A tokens not measured original Apache-2.0

xaps

1612

APMC1/xaps-sdk

MCP server Claude CodeCodexCursor +2

The Cognitive Circuit Breaker for Autonomous Agents. Runs locally from the xaps-sdk Python package. Needs 2 environment variables to run.

not rated 2 1mo ago A tokens not measured original MIT

agent-trust

1613

Garl-Protocol/garl

MCP server Claude CodeCodexCursor +2

One of 2 in server.json

Tamper-evident action receipts, trust scoring & capability tokens for AI agents. 29 MCP tools. Runs locally from the @garl-protocol/mcp-server npm package. Needs 3 environment variables to run.

not rated 2 6d ago A tokens not measured original Apache-2.0

secrets-management

1614

1clawAI/1claw-mcp

Skill Claude CodeCodex

Use when the user asks to "store a secret", "fetch credentials", "rotate an API key", "manage secrets", "set up vault access", or any task involving secure credential storage and retrieval.

not rated 2 yesterday A 0 tokens original MIT

kasbah-mcp

1615

Al-Adnane/Kasbah-Core

MCP server Claude CodeCodexCursor +2

Governance layer for agentic AI — signed, verifiable receipts for every agent action. Runs locally from the @yobekasbah/mcp-server npm package. Needs 2 environment variables to run.

not rated 2 3mo ago A tokens not measured original MIT

kernel

1616

Actenon/actenon-kernel

MCP server Claude CodeCodexCursor +2

Open proof-required execution kernel for consequential actions. Runs locally from the actenon-kernel Python package.

not rated 2 1mo ago A tokens not measured original Apache-2.0

code-review-agent

1617

GoodJobwilliam/aicraft

Skill Claude CodeCodex

Comprehensive code review with security, performance, and style analysis for Python, TypeScript, and Go. Detects OWASP Top 10 vulnerabilities, N+1 queries, race conditions, and logic errors before they reach production.

not rated 2 10d ago A 46 tokens original MIT

GDPRShiftLeftMCP

1618

KevinRabun/GDPRShiftLeftMCP

MCP server Claude CodeCodexCursor +2

GDPR Shift-Left Compliance MCP Server — Azure-first GDPR guidance, code review, and audit tools. Runs locally from the gdpr-shift-left-mcp Python package.

not rated 2 6mo ago A tokens not measured original MIT

sast-mcp-server

1619

Skyrxin/sast-mcp-server

MCP server Claude CodeCodexCursor +2

A standard MCP server for SAST/DAST tools (Bandit, njsscan, Bearer, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP) — scan code for security vulnerabilities from any AI agent. Runs locally from the sast-mcp-server Python package. Needs 4 environment variables to run.

not rated 2 2mo ago A tokens not measured original MIT

calllint

1620

calllint/calllint

Plugin Claude Code

Bundles 1 skill, 1 hook, 1 MCP server · 46 tokens together

Preflight risk linting for MCP & agent tools. Before you add or edit an agent-tool config, CallLint recommends scanning the blast radius — SAFE / REVIEW / BLOCK / UNKNOWN with evidence. Advisory and non-blocking; never executes the server it judges.

not rated 2 today A tokens not measured original Apache-2.0

ako2345/android-security-analyzer

MCP server Claude CodeCodexCursor +2

MCP server for static security analysis of Android source code. Remote server at android-security-analyzer.ako-labs.workers.dev.

not rated 2 6mo ago A tokens not measured

air-blackbox-mcp

1622

airblackbox/air-blackbox-mcp

MCP server Claude CodeCodexCursor +2

One of 2 in server.json

MCP server for EU AI Act compliance scanning with GDPR and bias detection - scan, analyze, remediate, and protect AI agent code. Runs locally from the air-blackbox-mcp Python package.

not rated 2 13d ago A tokens not measured original Apache-2.0

zzop

1623

eezz4/zzop

Plugin Claude Code

Bundles 1 command, 1 MCP server · 21 tokens together

Deterministic cross-repo contract analysis for AI agents: which frontend calls hit which backend endpoints (and which don't) — exact joins, disclosed blind spots, no guessing. TypeScript/JavaScript, Python, Java, C#, Rust, Go, Prisma, SQL natively; anything else via a documented adapter envelope. First install only…

not rated 2 changed 9d ago A tokens not measured original MIT

oss-boundary

1624

extralabs/octowatch-mcp-server

Cursor rule Cursor

Public OSS boundary — never leak secrets or proprietary source from private OctoWatch repos.

not rated 2 17d ago A 330 tokens original MIT

verify-before-checkout

1625

dimitrilaouanis-tech/onyx-mcp

Skill Claude CodeCodex

Pre-checkout verification for shopping agents. Before transacting with any storefront the user didn't explicitly type, fetch Ed25519-signed merchant facts (domain age, TLS age, brand-lookalike score, price deviation) from the Onyx oracle over x402, verify the signature, and surface the facts to the buyer. Use whenever…

not rated 2 1mo ago A 89 tokens original MIT

mcpampel

1626

MCPAmpel/mcpampel

MCP server Claude CodeCodexCursor +2

MCP security scanner plugin - scan your installed MCP servers with 16 engines. Runs locally from the mcpampel Python package. Needs 1 environment variable to run.

not rated 2 5mo ago A tokens not measured original Apache-2.0

qorami

1627

loicfontaine-max/qorami-sdk

MCP server Claude CodeCodexCursor +2

Check an email before an AI agent sends it: send / ask a human / block. Detects prompt injection. Runs locally from the qorami-mcp npm package. Needs 1 environment variable to run.

not rated 2 2mo ago A tokens not measured original MIT

aishield

1628

lm203688/aishield

Skill Claude CodeCodex

An AI and MCP security scanner aligned with the OWASP MCP Top 10, a list of common risks for tool-connected AI systems. It checks for issues such as prompt injection, command injection, poisoned tools, leaked secrets, unsafe permissions, supply-chain attacks, SSRF, and banned Chinese-language content.

not rated 2 today A 101 tokens original MIT

mcp-audit-proxy

1629

firatmio/mcp-audit-proxy

MCP server Claude CodeCodexCursor +2

Transparent audit proxy for MCP servers: logs every tool call, flags poisoning and rug pulls. Runs locally from the mcp-audit-proxy npm package.

not rated 2 1mo ago A tokens not measured original Apache-2.0

flagrix

1630

flagrix-io/flagrix-cli

MCP server Claude CodeCodexCursor +2

Scan GitHub repos and profiles for malware before cloning — commit-pinned risk verdicts for agents. Runs locally from the flagrix npm package. Needs 1 environment variable to run.

not rated 2 2mo ago A tokens not measured original MIT

dugganusa-cli

1631

pduggusa/dugganusa-cli

MCP server Claude CodeCodexCursor +2

Local STDIO MCP for DugganUSA threat intel. 1.13M IOCs. Read-only. npm: dugganusa-cli. Runs locally from the dugganusa-cli npm package. Needs 1 environment variable to run.

not rated 2 2mo ago A tokens not measured original MIT

zyrax-guard

1632

tiagosilva07/zyrax-guard

MCP server Claude CodeCodexCursor +2

Audit AI agent configs for prompt injection & rogue MCP servers; vet packages. Runs locally from the zyrax-guard npm package.

not rated 2 1mo ago A tokens not measured original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: