prompt-injection
52 servers · 2,014★ total
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
44 plug-and-play skills for OpenClaw — self-modifying AI agent with cron scheduling, security guardrails, persistent memory, knowledge graphs, and MCP health monitoring. Your agent teaches itself new behaviors during conversation.
Security control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.
Local-first security scanner, MCP protocol inspector, dynamic fuzzer, Docker sandbox, and report generator for Model Context Protocol servers.
Open standard for Provenance & Intent Contracts (PIC) in AI agents. Verify intent, provenance, and evidence before high-impact tool calls.
Security scores for 800+ MCP servers. 9 analyzers scan for prompt injection, toxic flows, and attack surface risks. Updated daily. 🛡️
MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a clear, actionable baseline for securing MCP deployments , whether you're shipping an internal tool or a customer-facing AI agent.
Security scanner for AI agent tool definitions
Python SDK for accurate and verifiable agent tool use. Agents verify that answers came from the right source and were not changed. Downstream agents detect 100% of errors and retry to achieve a 50% jump in answer accuracy.
Open-source AI security platform providing perimeter defense for LLMs and AI agents through swarm analysis, policy enforcement, adversarial testing, and real-time threat detection.
Agentic SAMM - An OWASP SAMM Extension for AI-Driven Development
A trustless MCP server that replaces the generic shell tool with validated, sandboxed, purpose-built execution tools for AI coding agents.
LLM guardrails & prompt injection detection for Python. Auto-instruments LangChain, CrewAI, OpenAI, LiteLLM + 8 more frameworks. PII masking, toxicity detection, policy CI/CD. One line, zero code changes.
Forensic auditor for local AI coding agents (Claude Code, Codex CLI, OpenClaw) and project-surface scanner for repos containing skills, plugins, and MCP manifests. Reads session logs, configs, and instruction files, detects known-bad patterns using 296 bundled rules in total.
Multi-engine security scanner for AI agents, MCP servers & plugins — 13 engines, one report.
🔪 Open-source safety firewall for AI agents. Intercepts tool calls before they execute, enforces YAML policies, and kills dangerous operations in real-time. Works with OpenAI, Anthropic, LangChain, and MCP. She doesn't guard. She kills.
Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.
Token-lean web microfetch for LLM agents: any URL → clean markdown via CLI, MCP server, and Claude Code plugin. Real browser-cookie auth, passkeys, anti-bot reach, on-by-default prompt-injection defense, plus on-device multimodal ASR/OCR. A single Rust binary — not a browser.
Zero-auth, security-hardened cross-domain research MCP server: web, academic, GitHub, news, weather, macro/finance, SEC, biomedical, Bluesky, YouTube. SSRF and prompt-injection defenses.
Open-source governed memory for AI agents: prompt-injection-resistant writes, purpose-bound retrieval, provenance, and tamper-evident audit.
Activation-probe security scanner for AI agent tooling. Reads a model's internal activations to detect poisoned MCP servers, skills, and packages before install.
MCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Policy-as-code enforcement and observability for MCP tool calls. Wraps AI agent sessions with cryptographic integrity checks, argument-level CEL policies, and a full audit trail.
Secure email proxy for AI agents — content filtering, PII redaction, and prompt injection detection over MCP
🛡️ Automated security scanner for MCP (Model Context Protocol) servers — 52 rules for prompt injection, credential exposure, SSRF & tool poisoning. pip install mcp-safeguard
Security for AI agents & MCP — map how MCP servers, skills, and memory chain into exposure paths. Toxic-flow detection, cross-surface graph, drift & policy-as-code. Local-only, no telemetry.
Reliability & security proxy for the Model Context Protocol (MCP). Self-healing connections, runtime tool-poisoning/shadowing defense, and NIST AI RMF + OWASP LLM Top-10 audit trails for any MCP server. Works with Claude, Cursor, Cline, Windsurf.
Offensive security framework for AI agents and MCP servers.
Runtime policy enforcement and audit control plane for MCP tool execution. Deterministic, non-AI policy engine that intercepts MCP tools/call requests before execution.
Comprehensive security scanner for MCP (Model Context Protocol) servers. 12+ analyzers, 117 YARA rules, ML-powered threat detection, dual scoring system. Detects prompt injection, tool poisoning and more
Belay is an open-source, local-first security layer for AI coding agents (Claude Code, Codex, Cursor, OpenClaw, Hermes Agent and MCP) that blocks dangerous commands, secret leaks, and prompt injection at the tool-call boundary in under 100ms — no LLM in the decision path by default, no cloud, no phone-home.
Generate a local MVP, then catch hollow tests before review. Free, receipt-backed proof for AI-assisted code.
MCP server that gives AI agents a local security scanner before they install or trust third-party tools.
A QuickBooks MCP server built for real books. Exposes QuickBooks Online as callable tools over the Model Context Protocol, with every create, update and delete gated behind human approval and a plain-English summary, and all QuickBooks text treated as untrusted input rather than instructions.
A standalone agent harness in Rust: a provider-agnostic loop, MCP tools, a path jail and prompt-injection interlock, sandboxed shell, scheduled triggers, and an eval rig that grades the trace.
Open Agent Security Fabric — red-team agentic AI, MCP firewall SDK, action oracles & SARIF CI gates. Assure, Enforce & Govern. Python + TypeScript. OWASP LLM/Agentic/MCP Top 10.
OpenTelemetry + Wireshark + Cloudflare for AI Agents. Monitor, inspect, secure, replay, and optimize all traffic between Users, AI Agents, LLMs, and MCP Servers.
Sunglasses for AI agents. Protection layer + neighborhood watch.
Intercept & tamper proxy for MCP traffic — X-ray and rewrite the JSON-RPC between an AI agent and its MCP servers. Burp Suite for AI agents. Authorized testing only.
An AI organism - the human-AI interface layer. A safety reflex that refuses known lethal actions even when the model is fooled, and a memory that only keeps what actually worked. For code, research, writing, or a fleet of agents. 100% local.
Security scanner for Model Context Protocol servers. Catch tool poisoning, prompt injection, and supply-chain attacks before your AI agent runs them.
Zero-trust security sidecar for AI agents - MIT, single Go binary, <5ms p99 overhead, protects Claude Code/Cursor/Codex/Gemini CLI/Windsurf
Deterministic MCP Security Architecture. FrozenNamespace as Root of Trust for Model Context Protocol tool verification
Prompt-injection defenses for Claude Code. A PreToolUse Bash hook blocks compositional credential-exfiltration shapes (secret read plus network, env dump to network, remote script to shell, reverse shells). A sanitizing MCP server wraps untrusted URLs and files in sentinels, strips invisible unicode, flags jailbreaks.
Autonomous AI agents inside a Qubes-isolated sandbox - tag-scoped Admin API access with dom0-mediated trust boundary.
Security scanner and developer toolkit for MCP servers used by AI agents.
Security & governance guardrails for MCP agents in Java — audit trail, agent-to-tool authorization, prompt-injection detection and rate limiting as a zero-config Spring Boot starter.
Security proxy for MCP servers. Catches indirect prompt injection attempts before they reach your AI agent.
A Roslyn analyzer that catches prompt-injection and tool-poisoning in C# Model Context Protocol (MCP) server tool descriptions at build time. MCPGxxx diagnostics, code fixes, and a CI gate.
MCP server for AI security intelligence. Check any MCP server for supply-chain threats before installing -- from Claude, Cursor, or Windsurf.