Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’» Developer Tools
  3. SecHelix
S
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

SecHelix

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View RepositoryVisit Website

Evidence-first security review of authorized repositories. Read-only, root-confined, no shell.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for SecHelix, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ’» More in Developer Tools

Documentation Overview

SecHelix β€” evidence-first application security for coding agents

Most AI security tools try to find more. SecHelix tries to prove itself wrong.

validation Apache-2.0

SecHelix

Every candidate finding goes to an independent verifier whose only job is to disprove it. The report shows you what it refuted and why β€” and returns INCOMPLETE rather than a clean PASS when it could not actually check.

Open source, Apache-2.0, for code you own or are authorized to test. Runs in Claude Code, Codex, Copilot and other Agent Skills-compatible agents; the Python runtime is optional.

It helps a coding agent:

  • map the attack surface and trust boundaries;
  • review only security checks that apply to the project;
  • investigate authentication, authorization, business logic, injection, SSRF, files, supply chain, AI/MCP and other security surfaces;
  • verify important candidates instead of reporting guesses;
  • fix the root cause;
  • add regression proof and retest;
  • return a clear release decision.

See it work in 90 seconds

bash
git clone https://github.com/omarmohelal/SecHelix && cd SecHelix
python examples/expense-api/prove.py

A small multi-tenant API with two candidate issues. One is a real cross-tenant read that a scanner walks past, because the endpoint does have an authorization check β€” it just checks the wrong thing. The other is f-string SQL that every pattern matcher flags and that is not exploitable at all.

Walkthrough, root cause, the two-line fix and the regression proof: examples/expense-api.

Or take the same test in your browser β€” ten cases, three of them decoys, no signup: Can you tell the real bug from the decoy?

Install

Recommended for Agent Skills-compatible coding agents:

Terminal
npx skills@latest add omarmohelal/SecHelix --skill sechelix

Then open the repository you want to review in your coding agent. The skill installs instructions and data only β€” no executable code. The optional runtime below is a separate, explicit install.

A compact edition, sechelix-lite, is a single runtime-free review skill (about 200 lines plus five references) for skill directories and hosts where a small context footprint matters. See docs/distribution/awesome-copilot.md.

Use it

Full security audit

Copy this into your agent:

text
Use SecHelix for a complete authorized security audit of this repository.
Start STATIC and use LOCAL only if it is safe and useful.
Map the attack surface and trust boundaries first.
Verify important candidates before reporting them.
Fix root causes, add regression tests, retest, and give me the final release gate.

Fast security review

text
Use SecHelix to triage this repository for security issues.
Prioritize authentication, authorization, business logic, secrets, injection, SSRF, file handling, supply chain, dangerous configuration, and AI/MCP surfaces.
Return evidence-backed findings and clearly mark anything unproven.

AI-built app launch audit

Use this before launching an AI-generated, agent-generated, rapidly prototyped, or vibe-coded application:

text
Use SecHelix's AI-Built App Launch Audit on this authorized application.
Evaluate launch checks 01-36 from references/ai-built-app-launch.md.
Do not mark PASS without exact code, configuration, policy, test, log, or safe runtime evidence.
For every FAIL or security-relevant UNKNOWN, give the realistic failure mode, smallest root-cause fix, and exact safe verification step.
After fixes, re-run the failed/unknown checks and produce the normal SecHelix release gate.

The launch profile covers practical pre-release failures around secrets, auth/authz, cross-user data, database/storage permissions, debug exposure, input validation, SQL/NoSQL injection, XSS/CSRF, uploads, traversal, SSRF, password reset, sessions/JWT, CORS, rate limiting, staging, default credentials, webhooks, payments/entitlements, IDOR/BOLA, sensitive logs, and production artifacts.

Review a pull request

text
Review this PR with SecHelix.
Focus on security changes introduced by the diff, verify important candidates, and tell me whether the PR introduces a verified blocker or known risk.

Fix findings

text
Use SecHelix Fix Mode on the verified findings.
Fix the root cause, look for variants of the same bug, add security regression tests, and retest the original finding.

More copy-paste workflows: Command Cookbook.

What should I ask SecHelix to do?

GoalAsk for
Full repository reviewcomplete security audit
Quick first passsecurity triage
AI-built/vibe-coded app before launchAI-Built App Launch Audit
Broken access controlauthorization / IDOR / BOLA audit
Login and sessionsauthentication / session / OAuth audit
Input handlinginjection / XSS / SSRF / files audit
Payments and workflowsbusiness logic / race / idempotency audit
Dependencies and CIsupply chain / CI/CD audit
LLMs, agents and toolsAI / Agent / MCP security audit
A code changePR security review
Existing verified issuesFix Mode
Release decisionrelease gate
Shareable outputsecurity report

You do not need to memorize special slash commands. SecHelix is primarily a skill: tell the coding agent what security job you want done.

How the review works

text
scope
  β†’ map attack surface
  β†’ select applicable checks
  β†’ investigate
  β†’ independently verify important candidates
  β†’ fix root cause
  β†’ add regression proof
  β†’ retest
  β†’ report + release gate

A scanner match or model suspicion is treated as a candidate, not automatically as a vulnerability.

A strong finding should show the affected surface, attacker control or security boundary involved, reachability, impact, root cause, safe evidence, the fix, and regression/retest status.

What SecHelix does not claim

  • It is not a certification. PASS means the release-gate rules found no unresolved blocking condition in what was reviewed, not that the software has no vulnerabilities.
  • On real code it found 2 of 12 known CVEs. A blinded run against the vulnerable and patched trees of 12 recent CVEs found 2 cleanly under the pre-registered rule, 3 with hand adjudication, and no finding it marked VERIFIED was one of the known defects (report). Precision is NOT_MEASURED.
  • The model still does the reasoning. SecHelix structures the review and labels unproven claims as unproven rather than dropping them: in that run 92 of 106 findings were marked LIKELY_BUT_UNPROVEN or HYPOTHESIS. It does not make a model see a bug it cannot reason about.
  • Host support varies. Installation is verified for the Claude Code plugin, the Agent Skills CLI, the portable bundle and the curated Copilot CLI plugin; other hosts are documented paths (compatibility).
  • Authorized targets only. It is not an internet scanner and ships no exploit payloads.

Optional CLI runtime

The Agent Skill works without the Python runtime. The runtime is optional and adds stored runs, coverage tracking, replayable evidence, reports, CI-friendly exit codes, and an MCP adapter.

Install it with:

bash
pipx install sechelix
sechelix doctor

uv tool install sechelix and python -m pip install sechelix are also supported.

Useful CLI commands

CommandWhat it does
sechelix doctorShows available components and reasoning executors
sechelix audit . --executor claude-codeRuns an audit using Claude Code as the reasoning executor
sechelix audit . --executor gemini-cliRuns an audit using Gemini CLI as the reasoning executor
sechelix runsLists saved runs and checks their integrity
sechelix coverageShows what previous runs did not examine
sechelix reportRenders the latest saved run
sechelix replay <run_id>Replays a recorded run offline and checks consistency
sechelix mcp .Serves the local MCP adapter over stdio

Example:

bash
sechelix doctor
sechelix audit . --executor claude-code
sechelix coverage
sechelix report --format markdown

sechelix audit . with the default --executor none intentionally does not pretend to analyze code. Reasoning nodes are blocked and the run remains incomplete until a real executor is configured.

For all CLI flags:

bash
sechelix --help
sechelix audit --help

Advanced runtime guide: V4 Runtime Quickstart.

GitHub Action

yaml
- uses: omarmohelal/SecHelix@v4.0.0-alpha.7
  with:
    executor: none

Outputs PASS, PASS_WITH_KNOWN_RISK, BLOCKED or INCOMPLETE, writes SARIF for code scanning, and uploads the run as an artifact. The default executor: none deliberately reports INCOMPLETE rather than a green check it did not earn β€” configure a reasoning executor to get an actual review.

Full reference: GitHub Action.

MCP adapter

bash
uvx sechelix mcp /path/to/the/repository

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Developer Tools View all alternatives
  • O
    Openapi MCP Server

    Connect any HTTP/REST API server using an Open API spec (v3)

    πŸ’» Developer Tools3 views
    Compare vs Openapi MCP Server β†’
  • C
    Claude Task Master

    AI-powered task management system for AI-driven development. Features PRD parsing, task expansion, multi-provider support (Claude, OpenAI, Gemini, Perplexity, xAI), and selective tool loading for optimized context usage.

    πŸ’» Developer Tools8 views
    Compare vs Claude Task Master β†’
  • M
    MCP Server Docker

    Integrate with Docker to manage containers, images, volumes, and networks.

    πŸ’» Developer Tools3 views
    Compare vs MCP Server Docker β†’
  • N
    Next Devtools MCP
    Verified

    Official Next.js MCP server for coding agents. Provides runtime diagnostics, route inspection, dev server logs, docs search, and upgrade guides. Requires Next.js 16+ dev server for full runtime features.

    πŸ’» Developer Tools6 views
    Compare vs Next Devtools MCP β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about SecHelix

We don't have a confirmed install command for SecHelix yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/omarmohelal/SecHelix) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSecHelix AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/sechelix?style=directory)](https://allmcps.com/mcp/sechelix)
HTML Embed
<a href="https://allmcps.com/mcp/sechelix"><img src="https://allmcps.com/api/badge/sechelix?style=directory" alt="SecHelix on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’»Developer Tools
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging Β· 27/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Featured
M

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’» Developer Tools β†’Best MCP servers for Developers β†’Alternatives to SecHelix β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients