Permission control proxy enforcing least-privilege policies and auditing AI agent tool calls at runtime.
Key Features: Runtime enforcement of YAML-defined least-privilege policies Sensitive data classification with compliance framework hints Detection of supply chain threats including deserialization attacks MCP server for Maigret, an OSINT tool to search usernames and analyze URLs across public social networks.
Key Features: Username search with site filtering and format options URL parsing and analysis for associated usernames Supports multiple output formats: txt, html, pdf, json, csv, xmind Local MCP proxy that enforces adaptive guardrails to block destructive AI agent tool calls and protect supply chain.
Key Features: Intercepts and blocks destructive tool calls with 65+ adaptive rules Supports local stdio and remote Streamable HTTP MCP servers TOFU pinning of tool catalogs to prevent supply-chain attacks Adds named-human approval, trust receipts, verification, disputes, and delegation for consequential AI-agent actions.
Key Features: Named-human approval for irreversible actions Offline-verifiable Ed25519 Trust Receipts MCP server exposing dnstwist for DNS fuzzing to detect typosquatting, phishing, and domain impersonation risks.
Key Features: Domain fuzzing with multiple algorithms Registration and DNS record checks (A, AAAA, MX, NS) Scans MCP server packages and directories for malicious code, prompt injection, and supply chain risks.
Key Features: Scans npm packages for malicious patterns Scans local JavaScript and TypeScript directories Detects exfiltration, code execution, obfuscation, and sensitive file access AI agent security middleware with 8 defense layers for prompt injection, data exfiltration, PII detection, and compliance scanning.
Key Features: 8-layer defense including prompt guard, input auditor, tool blocker, output scanner Data loss prevention with full data return and outbound send blocking PII detection for Chinese and international identifiers with low false positives Local MCP server providing real-time cybersecurity reconnaissance including WHOIS, DNS, port scanning, SSL inspection, and CVE lookup.
Key Features: WHOIS domain registration data retrieval DNS record enumeration with subdomain brute-forcing Nmap-based port scanning with service and version detection Privacy-preserving AI gateway that redacts PII before sending prompts to LLMs and issues signed cryptographic certificates.
Key Features: Three-layer PII detection including custom and Presidio recognizers Redacts PII with placeholders before upstream model access Signed Ed25519 certificates with RFC 3161 timestamp and Sigstore anchoring MCP server providing AI agent trust, identity verification, escrow, and reputation management tools.
Key Features: Agent identity verification and certification Prompt injection detection and output redaction Escrow creation and audit ticket issuance Create and read AES-256-GCM encrypted notes that self-destruct after one read.
Key Features: Create encrypted notes up to 2 KB Read and permanently destroy notes Use AES-256-GCM end-to-end encryption MCP server for VirusTotal API providing URL, file hash, IP, and domain security analysis with relationship data.
Key Features: Automatic relationship data fetching with batched API calls Cached-report-first URL lookups with fallback scanning Detailed file hash analysis including sandbox behavior summaries