Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.
Connects AI assistants to IDA Pro for decompilation, disassembly, database changes, and reverse-engineering workflows.
Key Features: IDA Pro decompilation access Database comments, renaming, and type updates Connects JADX-GUI to MCP so Claude can inspect decompiled Android classes, methods, fields, and smali.
Key Features: Exposes selected JADX-GUI classes over MCP Retrieves Java source and smali code Lists project classes, methods, and fields Automates Android APK decoding, inspection, modification, and rebuilding through Apktool and MCP.
Key Features: APK decoding through Apktool Manifest and apktool.yml inspection Smali and resource file access UI/UX design-audit MCP server: scores a project on 12 dimensions vs WCAG 2.2 + APCA.
Audits npm packages and projects for supply-chain risks, vulnerabilities, AI-generated code debris, and SBOM output through MCP.
Key Features: Pre-install package verification and typosquat detection Static install-script and code-pattern analysis Workspace, project, bulk, and transitive dependency audits MCP server exposing dnstwist for DNS fuzzing to detect typosquatting, phishing, and domain impersonation risks.
Key Features: Domain fuzzing with multiple algorithms Registration and DNS record checks (A, AAAA, MX, NS) Audit certificates and keystores to surface expiry risks, weak algorithms, and misconfigurations.…
Audits npm dependencies against the remote registry and reports severity, CVE, CVSS, and upgrade information.
Key Features: Remote npm registry security checks Critical-to-low severity reporting CVE, CVSS, CWE, and advisory references Automates security vulnerability remediation by analyzing SAST reports or scanning repos, providing fix recommendations via MCP.
Key Features: Supports SAST tools: Checkmarx, CodeQL, Fortify, Snyk Two modes: Scan (runs SAST scan) and Analyze (uses existing SAST report) Generates automated code fixes for detected vulnerabilities Searches public sites for usernames and analyzes URLs through Maigret, with Docker-backed reports in several output formats.
Key Features: Username searches across social networks and websites URL parsing with associated username searches Local MCP proxy that blocks risky agent actions, scans tool traffic, pins catalogs, and supports approvals and audit logs.
Key Features: Pre-execution MCP call guardrails TOFU tool-catalog pinning Tool description and result scanning