Connects AI assistants to IDA Pro for decompilation, disassembly, database changes, and reverse-engineering workflows.
Key Features: IDA Pro decompilation access Database comments, renaming, and type updates Automates security vulnerability remediation by analyzing SAST reports or scanning repos, providing fix recommendations via MCP.
Key Features: Supports SAST tools: Checkmarx, CodeQL, Fortify, Snyk Two modes: Scan (runs SAST scan) and Analyze (uses existing SAST report) Generates automated code fixes for detected vulnerabilities Screens projects for China-specific compliance risks and adds runtime checks for injections, sensitive data, paths, tools, and commands.
Key Features: Stdio MCP server with local execution Prompt injection detection for Chinese and English text PII, credential, and sensitive-data scanning Enforces YAML permissions on agent tool calls, inspects sensitive data and tool chains, and records audit trails.
Key Features: PII and PHI classification Dangerous tool-chain detection Local static analysis for dead code, security issues, secrets, dependencies, quality regressions, and AI-generated code defects.
Key Features: Dead-code and unused-file detection Security, secret, and dependency analysis AI-generated code verification Security scanner for MCP servers with vulnerability detection and prompt injection analysis.
Local MCP proxy that blocks risky agent actions, scans tool traffic, pins catalogs, and supports approvals and audit logs.
Key Features: Pre-execution MCP call guardrails TOFU tool-catalog pinning Tool description and result scanning Scans MCP server packages and directories for malicious code, prompt injection, and supply chain risks.
Key Features: Scans npm packages for malicious patterns Scans local JavaScript and TypeScript directories Detects exfiltration, code execution, obfuscation, and sensitive file access UI/UX design-audit MCP server: scores a project on 12 dimensions vs WCAG 2.2 + APCA.
Proxies MCP traffic to add signed audits, redaction, policies, rate limits, and a local read-only dashboard.
Key Features: Stdio and HTTP MCP proxying JSONL and SQLite audit storage HMAC-SHA256 audit signing Queries Shodan for IP, DNS, device, CPE, and vulnerability intelligence through MCP tools.
Key Features: IP reconnaissance with service and location details Forward and reverse DNS lookups Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.