45 specialized judges that evaluate AI-generated code for security, cost, and quality.
Find vulnerabilities and insecure patterns in code.
45 specialized judges that evaluate AI-generated code for security, cost, and quality.
The anti-hallucination gate for AI coding agents: 9 MCP tools (undefined-symbol verification in 17 languages with real toolchain adapters, hallucination-word scan, sandboxed run, evidence receipts), a cross-client hook and a CI gate — so 'done' means obse
A screen ↔ endpoint ↔ field dependency map: answers which screens break if you change an endpoint or a response field. Local-first, git-friendly, open source.
Search and audit CVEs by keyword, severity, CWE, CISA KEV status, and CPE via the NIST National Vulnerability Database. STDIO or Streamable HTTP.
Local-first repo-memory MCP for coding agents. Best for relationship-heavy edits: symbols, callers, dependencies, diff review, and git-pinned decisions before code changes. Start with a no-write proof receipt; use grep/ripgrep for exact strings. MIT; bund
Agentic CVE remediation platform for Node.js. Correlates threat intelligence, applies policy-governed fixes, and delivers auditable remediation outcomes across CI/CD pipelines, agent workflows, and service portfolios.
Security infrastructure your AI can't be — deterministic, current past your model's training cutoff, whole-repo-aware, author-independent. Security MCP for vibe coding. 462 rules, 39 tools, CLI + doctor. Prompt-level shift-left security (secure_prompt — e
CodeInspectus, by Synvoya — a local-first security MCP server and CLI with CI policy, versioned exports, evidence bundles, history, baselines, and approval-gated agent workflows. Zero network egress at scan time.
AI writes. SPARDA proves. A deterministic, offline gate that catches when an AI edit removes a guard, exposes a route, or breaks an invariant — no API key, right in the agent edit loop.
Query OSV.dev for package vulnerabilities, batch-audit dependency lists, and fetch full advisory records via MCP. STDIO or Streamable HTTP.
Evidence-first code analysis for agents in TypeScript, JavaScript, and Svelte codebases.
Deploy Claude Code, Codex & Antigravity (agy) CLI agents to demolish your work before users do. Real file analysis. Brutal honesty. Per-call model pinning, conversation continuation & intelligent pagination.
ESLint plugin for Model Context Protocol (MCP) SDK security — catches tools registered without an input schema, handlers reading arguments the schema never declared, model-visible descriptions built from dynamic text, and tool arguments reaching a shell.
Euthynos — deterministic repository intelligence for AI coding agents (MCP server): exact source spans, call graphs, clone detection, honest evidence boundaries.
Roslyn-based MCP server that gives AI agents deep semantic understanding of .NET codebases — navigation, call graphs, diagnostics, refactoring, code-quality auditing, test intelligence, and IL inspection.
MCP server & CLI: codebase index + cache for Claude Code, Cursor, OpenAI Codex, Google Antigravity/Gemini. Model Context Protocol tools (codetree_read, codetree_search, …), hooks on Claude, rules on other IDEs. Token savings, SQLite index, symbol search,
Offline security scanner for Node web apps and AI coding agents. OWASP rules with framework-specific fixes for 12 stacks, plus .claude/.cursor/.vscode config scanning. No telemetry.
Codebase health as MCP tools — dead code, circular dependencies, coupling, and architectural drift for Claude Desktop, Cursor, Windsurf and Slack.
Deterministic, non-executing evidence reports for public npm MCP servers.
Multi-model AI code review server using OpenRouter - get diverse perspectives from multiple LLMs in parallel