ai-security

91 servers · 8,157★ total

ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

1,446★

ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.

Consequence firewall for machine actions. EMILIA Gate verifies exact authority before money, code, permissions, infrastructure, or regulated state changes; the open protocol makes the evidence independently verifiable.

Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.

CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.

ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agents

Agentic AI research papers, benchmarks, frameworks, and tools curated across 24 domains.

See what your AI agents can access. Scan MCP configs for exposed secrets, shadow APIs, and AI models. Generate AI-BOMs for compliance.

Governance gateway for AI agents — bounded, auditable, session-aware control with MCP proxy, shell proxy & HTTP API. Works with Cursor, Claude Code, Codex, and any MCP-compatible agent.

Testing and observability for multi-agent delegation, MCP tools, permissions, sandboxed actions, prompts, and workflow replay.

44 plug-and-play skills for OpenClaw — self-modifying AI agent with cron scheduling, security guardrails, persistent memory, knowledge graphs, and MCP health monitoring. Your agent teaches itself new behaviors during conversation.

RedTeam-Agent: AI-Powered Autonomous Red Team Framework via Model Context Protocol. AI红队与内网渗透自动化框架,支持 gogo, fscan, httpx, nuclei, impacket, playwright 等 15+ 渗透工具,让 LLM 直接化身安全审计黑客。

MCP Security Solution for Agentic AI — real-time proxying, behavior analysis, and malicious tool detection

Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.

Security control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.

Advanced Shodan-based scanner for discovering, verifying, and enumerating Model Context Protocol (MCP) servers and AI infrastructure tools over HTTP & SSE.

Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.

MCP security testing framework for evaluating Model Context Protocol server vulnerabilities

Runtime visibility for Python MCP servers. Captures tool calls, session lifecycle, module imports (SHA-256), and subprocess execution as structured NDJSON. No code changes.

MCP server with 55 security intelligence tools — CVE/KEV, MITRE ATLAS+D3FEND, Sigma detection rules, email security posture (SPF/DMARC), domain & web intel, threat intel.

Security scores for 800+ MCP servers. 9 analyzers scan for prompt injection, toxic flows, and attack surface risks. Updated daily. 🛡️

🔐 50+ MCP Security Servers for AI-Powered Pentesting | Integrate Nmap, Burp Suite, Nuclei, Shodan, BloodHound, Semgrep, Trivy | Model Context Protocol for Cybersecurity

Discover, govern and control access to MCP servers and agent skills across your organization

Offensive MCP server auditor: detects tool poisoning, credential leaks, RCE vectors, SSRF, session hijacking, and supply chain vulnerabilities across stdio, HTTP, and SSE transports.

Demo agents showcasing CapiscIO Agent Guard and MCP Guard — trust badges, identity verification, and tool-level authorization for A2A and MCP protocols

An AI-driven dynamic protocol fuzzer for the Model Context Protocol (MCP). Prove runtime exploitability by discovering state violations, transport crashes, and application-layer logic flaws (SSRF, LFI) before your AI agents do.

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a clear, actionable baseline for securing MCP deployments , whether you're shipping an internal tool or a customer-facing AI agent.

23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.

Security scanner for AI agent tool definitions

Python SDK for accurate and verifiable agent tool use. Agents verify that answers came from the right source and were not changed. Downstream agents detect 100% of errors and retry to achieve a 50% jump in answer accuracy.

Open-source AI security platform providing perimeter defense for LLMs and AI agents through swarm analysis, policy enforcement, adversarial testing, and real-time threat detection.

The ultimate OWASP MCP Top 10 security checklist and pentesting framework for Model Context Protocol (MCP), AI agents, and LLM-powered systems.

🛡️ The security firewall for AI agent tools & MCP servers (Claude, GPT-5.6, Gemini 3.7, Antigravity, Cursor, Codex, Hermes). Catch command injection, secret theft & toxic flows in <50ms. 100% offline Rust SAST + 1-click auto-fix + SARIF.

LLM guardrails & prompt injection detection for Python. Auto-instruments LangChain, CrewAI, OpenAI, LiteLLM + 8 more frameworks. PII masking, toxicity detection, policy CI/CD. One line, zero code changes.

Local credential control for AI coding agents.

Multi-engine security scanner for AI agents, MCP servers & plugins — 13 engines, one report.

MCP server for AI-powered network scanning with Nmap. Port scanning, service detection, OS fingerprinting, and vulnerability scanning for AI agents. By Vorota AI.

Heddle — The policy-and-trust layer for MCP tool servers. Turn YAML configs into validated, policy-enforced MCP tools.

Open-source security gateway for MCP agents and tools. Inspect tool calls before execution, enforce policy, block risky operations, and emit audit-ready evidence.

The Open-Source MCP Firewall & Security Gateway for AI Agents. Inspect, redact, and control tool calls. Proxy mode (universal) and Inline SDK mode (Go).

Comprehensive security scanner for Model Context Protocol (MCP) servers

Burp MCP Security Analysis Toolkit

MCP security scanner by Helixar

Security scanner for Model Context Protocol (MCP) with capability graph analysis. Detects emergent attack chains across multi-server AI agent deployments that no individual tool scan can find.

Open-source governed memory for AI agents: prompt-injection-resistant writes, purpose-bound retrieval, provenance, and tamper-evident audit.

The trust and intelligence layer between AI agents and your database. Read-only by architecture, semantic knowledge graph + audit log, MCP-native.

Activation-probe security scanner for AI agent tooling. Reads a model's internal activations to detect poisoned MCP servers, skills, and packages before install.

10 intentionally malicious MCP servers that exploit protocol features to attack AI clients. For security research and defense testing.

29 free, open-source plugins for Claude Code & Cowork — Google Drive, WhatsApp, YouTube, WordPress, Apollo & more. Built on the SOSA™ security framework.

MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.

AI-powered security testing for Claude Desktop. MCP server integrating 6 essential pentesting tools (nmap, nikto, sqlmap, wpscan, dirb, searchsploit) in a secure Kali Linux Docker container. Perform ethical security assessments through natural conversation.

Python

AI-driven pentest orchestration that hands Claude the full PTES methodology over real MCP tool calls. 80+ tools, 33 verification probes, scope guard on every request. Python orchestrator + React/Ink TUI.

Discover and audit MCP servers for security vulnerabilities across Claude Code, Cursor, VS Code, and more

Policy-as-code enforcement and observability for MCP tool calls. Wraps AI agent sessions with cryptographic integrity checks, argument-level CEL policies, and a full audit trail.

Agentic security control plane for MCP and AI agent tool calls. MCP-native policy gateway with topology discovery and audit.

Runtime security proxy for MCP: lockfile enforcement, drift detection, artifact pinning, Sigstore/Ed25519 signing, CEL policy, OpenTelemetry tracing. Works with Claude Desktop, LangChain, AutoGen, CrewAI.

Agent Identity Protocol -- verifiable, delegable identity for AI agents across MCP and A2A. IETF Internet-Draft. PyPI: agent-identity-protocol

🛡️ Automated security scanner for MCP (Model Context Protocol) servers — 52 rules for prompt injection, credential exposure, SSRF & tool poisoning. pip install mcp-safeguard

Security for AI agents & MCP — map how MCP servers, skills, and memory chain into exposure paths. Toxic-flow detection, cross-surface graph, drift & policy-as-code. Local-only, no telemetry.

Reliability & security proxy for the Model Context Protocol (MCP). Self-healing connections, runtime tool-poisoning/shadowing defense, and NIST AI RMF + OWASP LLM Top-10 audit trails for any MCP server. Works with Claude, Cursor, Cline, Windsurf.

Assay — a canary-oracle benchmark for MCP security: a frozen task set scored by a recomputable HMAC-canary oracle (structural-zero false positives), not an LLM judge. Maintained by Verosek.

Offensive security framework for AI agents and MCP servers.

Collateralized execution engine for AI agents: bond-and-slash accountability with Ed25519 identities, bounded exposure, and progressive trust tiers.

A deep, visual, source-grounded guide from LLMs and agent architectures to secure agentic AI systems.

Runtime policy enforcement and audit control plane for MCP tool execution. Deterministic, non-AI policy engine that intercepts MCP tools/call requests before execution.

Agents change faster than audits. Ancilis discovers what agents can do, classifies the data they touch, activates the right controls, and continuously proves compliance. Trust your agents in production.

Authorization, delegation, provenance, and verifiable-audit engine for AI agents. MCP adapter published.

A local proxy that wraps your MCP servers and checks each tool call against policy and live state before it runs - allow, block, or request a refresh, with a reason the agent can act on.

AgenticStore: The secure toolkit for AI agents. Instantly equip Claude Desktop, Cursor, and Windsurf with 27+ MCP tools, persistent memory, and SearXNG search, all protected by a built-in PII prompt firewall to protect your data from being exposed to AI agents.

Comprehensive security scanner for MCP (Model Context Protocol) servers. 12+ analyzers, 117 YARA rules, ML-powered threat detection, dual scoring system. Detects prompt injection, tool poisoning and more

Belay is an open-source, local-first security layer for AI coding agents (Claude Code, Codex, Cursor, OpenClaw, Hermes Agent and MCP) that blocks dangerous commands, secret leaks, and prompt injection at the tool-call boundary in under 100ms — no LLM in the decision path by default, no cloud, no phone-home.

A local-first permission firewall and approval layer for AI agent tool calls.

MCP server that gives AI agents a local security scanner before they install or trust third-party tools.

Official SupraWall MCP (Model Context Protocol) Security Plugin. Enforces deterministic guardrails, least-privilege tool access, and PII interception for AI agents.

Open Agent Security Fabric — red-team agentic AI, MCP firewall SDK, action oracles & SARIF CI gates. Assure, Enforce & Govern. Python + TypeScript. OWASP LLM/Agentic/MCP Top 10.

OpenTelemetry + Wireshark + Cloudflare for AI Agents. Monitor, inspect, secure, replay, and optimize all traffic between Users, AI Agents, LLMs, and MCP Servers.

Sunglasses for AI agents. Protection layer + neighborhood watch.

Terraform-style plan/apply for agent systems: versioned YAML for agents, tools, workflows, and policies; local-first SQLite state; MCP & HTTP tools; structured traces.

The guardian layer for AI agents — identity, secrets, audit via MCP. Gate + Vault + Watch.

Security scanner for Model Context Protocol servers. Catch tool poisoning, prompt injection, and supply-chain attacks before your AI agent runs them.

Sandbox any MCP server in one line. Firecracker microVM isolation for Claude Desktop, Cursor, Windsurf, and every MCP client.

Deterministic MCP Security Architecture. FrozenNamespace as Root of Trust for Model Context Protocol tool verification

Command-line interface for Declaw — security-first sandboxing for AI agents

Prompt-injection defenses for Claude Code. A PreToolUse Bash hook blocks compositional credential-exfiltration shapes (secret read plus network, env dump to network, remote script to shell, reverse shells). A sanitizing MCP server wraps untrusted URLs and files in sentinels, strips invisible unicode, flags jailbreaks.

Security scanner and developer toolkit for MCP servers used by AI agents.

MCP server for secure AI agent authentication — lets Claude, Claude Code, and other LLM agents call APIs without exposing raw tokens or credentials to the model

Security proxy for MCP servers. Catches indirect prompt injection attempts before they reach your AI agent.

Description: Local-first pre-commit policy guard for AI-agent repositories. Website: https://pypi.org/project/aigenguard/

OWASP MCP Top 10 security scanner for Model Context Protocol servers

A Roslyn analyzer that catches prompt-injection and tool-poisoning in C# Model Context Protocol (MCP) server tool descriptions at build time. MCPGxxx diagnostics, code fixes, and a CI gate.