Offline security scanner for Node web apps and AI coding agents. OWASP rules with framework-specific fixes for 12 stacks, plus .claude/.cursor/.vscode config scanning. No telemetry.
Security analysis, scanning and identity.
Offline security scanner for Node web apps and AI coding agents. OWASP rules with framework-specific fixes for 12 stacks, plus .claude/.cursor/.vscode config scanning. No telemetry.
Stores for MCP ABAP ADT auth-broker - BTP, ABAP, and XSUAA implementations
Local RAG MCP server with hybrid search, PDF/DOCX support, and zero-config setup
Shared MCP utility for gating write operations with environment variable controls
Experimental MCP extension for proactive third-party OAuth readiness discovery on local stdio servers.
Audit, optimize, and secure Claude Code, OpenClaw, and Hermes AI agent deployments. Token waste detection, security scanning, config drift, fleet SSH audit. Free to install.
Trident plugin for Codex and Claude Code: web-application penetration testing, security finding triage, and verified remediation over Trident's remote MCP server.
Encrypted environment variable vault with AI access policies, keeping secrets safe from AI agents.
Author, edit and run Bruno collections as files: HTTP, WebSocket, gRPC, per-request pass/fail.
Model Context Protocol server for OAuthLint. Lets AI coding tools scan their own generated OAuth/OIDC/JWT/session/CORS code for the anti-patterns OAuthLint catches, in-loop.
Local encrypted credential vault for coding agents — secrets never touch agent context, only the process boundary
Header validator for MCP ABAP ADT - validates and prioritizes authentication headers
Obsidian MCP server: semantic search, knowledge graph, and vault editing. No plugin required.
Scan a project for leaked secrets, risky MCP configs, and unsafe automation before handing it to an AI coding agent (Claude Code, Cursor, Codex). Zero dependencies, runs locally.
Scans Greenhouse, Lever, Ashby, Workday, Rippling for roles in any category. Clay-ready.
An MCP server for Clerk generated by @buildwithalyer
Gmail MCP server — scope-gated tools + attachment/download path jails + supply-chain hardening. Fork of GongRzhe/Gmail-MCP-Server via ArtyMcLabin's intermediate fork.
Delegation-aware authorization middleware around the official MCP TypeScript SDK. The decision layer, not the SDK.
Post-quantum identity for AI agents and autonomous systems: a KYC-verified institution sponsors an ML-DSA-65 keypair and locked capability scope for any agent that cannot pass KYC itself.
Stock and crypto market data — 49 tools for quotes, technicals, options, SEC filings, and more.