A knowledge graph of your codebase, exposed as an MCP server — so AI coding agents stop re-deriving structure from grep and Read on every request.
Find vulnerabilities and insecure patterns in code.
A knowledge graph of your codebase, exposed as an MCP server — so AI coding agents stop re-deriving structure from grep and Read on every request.
Reverse engineer anything from your terminal or agent with one CLI and MCP server.
Bounded conventions map and local-pattern discovery for AI coding agents. Local-first MCP server with AST-backed hybrid search.
bouncer — static compliance-controls checker. Verifies the controls a regulation requires actually exist in your code (UK Online Safety Act, ICO Children's Code), as deterministic rule packs. No LLM required.
Package Intelligence MCP server for AI agents. Stops hallucinated/malicious package installs across 19 ecosystems (npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia). 22 to
Your agents break less code and burn fewer tokens. codeweb maps your repo into a deterministic call/import graph; 28 MCP tools answer impact, callers, and duplication before agents write. Claude Code plugin & MCP server; zero deps, runs 100% locally.
Lightweight pre-commit safety gate for AI agents. Answers 'is this change safe?' with PASS/WARN/BLOCK verdict in seconds. Zero setup, no database.
Supply chain security risk scorer for npm, PyPI, Cargo, and Go packages — behavioral signals that can't be faked
Scans your code changes for leaked secrets and insecure configuration, and returns actionable fixes to your AI coding agent. MCP server plus CLI for Claude Code, Cursor, Codex and Windsurf.
MCP server that gives Cursor, Claude Code, VS Code and Windsurf a pre-deploy ship gate. Five tools: scan a path or files, explain a rule, read a hosted verdict, and audit the agent stack itself (MCP config and instruction files).
Scan AI agent skills for 25 attack classes + runtime monitoring. 1,316+ findings.
Security co-pilot for AI agents. Scan for vulnerabilities, verify governance, audit MCP servers, and generate compliance reports — all from Claude, Cursor, or any MCP client.
Turn failing JSON requests into replay-verified reductions, and catch TypeScript or OpenAPI contract drift before merge.
MCP server for FinishKit. Production readiness scanner for AI-built apps. Enables AI agents in Claude, Cursor, Windsurf, and VS Code to check if code is ready to ship.
Safety-first context & orchestration engine for AI coding agents. MCP server with mandatory research pipeline, knowledge graph, impact analysis, decision memory, and safety guard — works with any MCP client.
MCP server that returns a cross-validated dependency FITNESS verdict for npm packages: deprecated / yanked / superseded status plus an inferred safe migration target — what to move to and how confident we are — cross-checked across the npm registry, deps.
MCP server for CallLint — a static preflight safety gate for MCP servers and agent tools. Use before installing or approving other MCP servers. Never executes the server it judges.
aiglare: audit AI/LLM features in any JS/TS codebase for governance guardrails. Finds where model output reaches users or side-effects without confidence handling, fallbacks, validation, or human-in-the-loop.
MCP server for npm — search packages, check bundle sizes, scan vulnerabilities, compare downloads, and inspect dependencies
Evidence-first reverse-engineering workbench for humans and AI agents