AI security scanner - secrets, PII, prompt injection, and exfiltration detection.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Infrastructure security for AI agents. We attack what we defend.
Make agent behavior verifiable, auditable, and cryptographically provable across any harness, any platform. Built as a TypeScript monorepo with MCP integration, blockchain anchoring, and β as of Q4 β a published red-team engine that tests our own defenses.
The thesis: every security platform claims its defenses work. We're the first to publish the attacks that prove it. Same suite. Same scorecard. Same locked benchmark β applied to our own packages, every release.
The CLI detects your framework (LangChain, LlamaIndex, MCP, OpenAI, Anthropic, Microsoft, Google) and scaffolds the right security middleware for your stack. Or install everything at once:
The first agent security platform to publish its own offensive engine. Two new packages flipped the suite from purely defensive to defense + offense in the same monorepo, validated against each other:
| Package | Role | Version |
|---|---|---|
@weave_protocol/adversary | Offensive engine β 68 documented + novel attacks across 5 categories (IPI, tool-coercion, jailbreak, extraction, goal-corruption). Real Playwright browser target with 4 breach signal channels. Real-LLM demo mode via Anthropic API. | β v0.2.1 |
@weave_protocol/agentsecbench | Standardized benchmark β locked attack suites, tier grades AβF, paste-ready reports, side-by-side comparison | β v0.1.0 |
Trophy attacks β documented in-the-wild incidents reproduced in the corpus:
Why this matters: every model release, every WARD policy change, every adapter update can be re-benchmarked against the same locked suite. Did your score regress? agentsecbench compare will show you. Does your WARD policy actually defend anything? --measure-ward-delta will tell you. This is how a category gets defined.
See Adversary README β Β· See AgentSecBench README β Β· See METHODOLOGY.md β
Every enterprise agent question today is "what's my ceiling on this thing?" β measured in dollars, not just tool calls. @weave_protocol/witan@1.1.0 answers it. Per-window budgets (run / hour / day / week / month) that gate LLM calls and tool calls, with three actions: block, require approval/consensus, or notify.
Multi-provider LLM pricing built in β Anthropic, OpenAI, Google, and local (free). Per-tool amount caps (send_payment max $500/day). Interactive TTY approval prompt for human-in-loop terminals. Async callback for Slack/PagerDuty/custom UIs. Safe defaults β never silent approval in non-interactive contexts.
Backward compatible with the existing behavioral_limits.maxCostUSD. In-memory storage in v1.1 with a pluggable interface for the v1.2 Redis/SQLite backends. Programmatic API via import { SpendingTracker } from '@weave_protocol/witan/spending'.
See Witan spending caps README β
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mund)<a href="https://allmcps.com/mcp/mund"><img src="https://allmcps.com/api/badge/mund?style=directory" alt="Mund on AllMCPs" /></a>