Connects AI assistants to IDA Pro for decompilation, disassembly, database changes, and reverse-engineering workflows.
Key Features: IDA Pro decompilation access Database comments, renaming, and type updates Audits npm dependencies against the remote registry and reports severity, CVE, CVSS, and upgrade information.
Key Features: Remote npm registry security checks Critical-to-low severity reporting CVE, CVSS, CWE, and advisory references SSE-based MCP server to query the OSV database for open source vulnerability info by package or commit.
Key Features: SSE transport mode with optional streamable-http Query by package name, ecosystem, version, or commit hash Batch querying multiple vulnerability queries in one request Audits npm packages and projects for supply-chain risks, vulnerabilities, AI-generated code debris, and SBOM output through MCP.
Key Features: Pre-install package verification and typosquat detection Static install-script and code-pattern analysis Workspace, project, bulk, and transitive dependency audits Permission control proxy enforcing least-privilege policies and auditing AI agent tool calls at runtime.
Key Features: Runtime enforcement of YAML-defined least-privilege policies Sensitive data classification with compliance framework hints Detection of supply chain threats including deserialization attacks Automates security vulnerability remediation by analyzing SAST reports or scanning repos, providing fix recommendations via MCP.
Key Features: Supports SAST tools: Checkmarx, CodeQL, Fortify, Snyk Two modes: Scan (runs SAST scan) and Analyze (uses existing SAST report) Generates automated code fixes for detected vulnerabilities Audit websites for SEO, performance, security, accessibility and agent experience issues.
A fail-closed policy-as-code proxy for MCP that enforces, records, and produces offline-verifiable evidence of privileged tool calls on Linux.
Key Features: Deterministic, fail-closed policy enforcement for MCP tool calls Offline-verifiable, tamper-evident evidence bundles of decisions and observations Kernel-level IPv4/TCP egress enforcement via eBPF/LSM and Landlock on Linux Local MCP server for domain and IP reconnaissance, including DNS, ports, TLS, CVEs, headers, cloud exposure, and breach checks.
Key Features: WHOIS, DNS, ASN, and certificate-transparency lookups Nmap port scanning with service and version detection SSL/TLS certificate and HTTP security-header inspection Queries Shodan for IP, DNS, device, CPE, and vulnerability intelligence through MCP tools.
Key Features: IP reconnaissance with service and location details Forward and reverse DNS lookups Immutable audit trail for agent-to-agent interactions
An MCP server enabling AI assistants to manage keys, users, and connections on CipherTrust Manager via JSON-RPC.
Key Features: Key management operations User and connection management CTE client management support