Search for a command to run...
120 MCPs · 0 installs total
MCP server for AI content generation, enabling agents to learn a voice, generate content ideas, write scripts, and produce multi-platform content deterministica
RAG corpus poisoning detector that scans for embedding anomalies and backdoor triggers, with an MCP server for AI agent integration.
Local LLM cost & token forensics proxy with anomaly detection, enabling security teams to scan for cost anomalies and abuse patterns, and expose results via MCP
MCP-native auditor for LLM hallucination and grounding issues in RAG systems. Provides prioritized findings in table, JSON, or SARIF format for CI gating and AI
Runtime agent firewall for PII redaction, rate limits, and policy enforcement, enabling autonomous agent security via MCP integration.
MCP server for scanning AI systems and code for demographic, occupational, and geographic biases. Enables CI integration and AI agent-driven bias detection.
Enables AI agents to auto-generate NIST AI RMF and EU AI Act Annex IV compliant model and system cards via MCP.
LLM red-team harness that scans for OWASP LLM Top 10 and MITRE ATLAS vulnerabilities, providing prioritized findings in table, JSON, SARIF, or via an MCP server
Runtime allowlist and policy for agent tool-calls, enabling security scanning (e.g., TODO/FIXME/XXX findings) via MCP for AI agents.
Enables AI agents to scan codebases for TODO/FIXME/XXX patterns and get prioritized results over MCP, supporting CI gates and multiple output formats.
A self-hostable, MCP-native RAG pipeline that ingests, indexes, and serves data, enabling AI agents to scan codebases for prioritized findings and integrate wit
Enables AI agents to scan codebases for prioritized findings (TODO, FIXME, XXX) and retrieve results in table, JSON, or SARIF format via MCP.
Enables AI agents to scan code for TODO, FIXME, XXX issues via MCP, providing prioritized findings in table, JSON, or SARIF format.
A local GeoGuessr-for-real-life: reads EXIF GPS and reasons over visual clues using a local uncensored vision-language model + a reasoning model — no cloud, no
Cryptographically verifiable, scope-narrowing delegation chains for AI agents, enabling human-anchored authorization across multiple hops.
Enables lightweight CRM pipeline management with email sequences, project scanning, and MCP-based interaction for AI agents.
Portable long-term memory store for agents, exposed over MCP.
Scans MCP servers for security hardening issues including capability declarations, transport, and tool descriptions.
Enables LLM agents to acquire token-budgeted, deterministic context packs from repositories, with hash-chained provenance for auditability.
Re-identification risk assessment that computes k-anonymity, l-diversity, and HIPAA Safe Harbor compliance on a dataset.
Generate a CycloneDX SBOM directly from an unpacked firmware root filesystem and flag components with known CVEs and EOL kernels.
Test, explain & benchmark regexes + a library of security patterns
Self-hosted SaaS metrics — MRR, churn, LTV from Stripe or CSV
Third-party / vendor risk questionnaires with SBOM cross-ref
Org charts and headcount plans generated from CSV / HRIS export
Static malicious payload analyzer — PE/ELF/LNK/macro/OneNote
Area-of-interest geospatial helper: bounding boxes, geofence checks, and change-event diffs from coordinate logs.
Map ASN/CIDR ownership & neighbors from whois/RIR exports
Generates a CycloneDX SBOM for mobile apps by unpacking native libs and bundled SDKs, then matches components against known-vuln and tracker/privacy databases.
Dependency risk visualizer — Scorecard + OSV + typosquat + maintainer signals
Generate and audit a Content-Security-Policy from a page's resources
Lightweight semantic-aware SAST that runs curated taint rules over diffs only, so PRs get fast incremental SAST instead of whole-repo scan fatigue.
Analyze GraphQL introspection for risky fields, depth, and authz gaps
DNS posture & misconfiguration scanner — SPF/DKIM/DMARC/DNSSEC/CAA
A headless, config-as-code DAST runner that crawls an authenticated web/mobile-API surface and fires a curated active-scan ruleset, emitting deduplicated SARIF.
Audit a GitHub org's security posture (branch rules, 2FA, secrets) from an export
GSA Schedule opportunity surveyor — SAM.gov + eBuy + FedConnect
Server-side outbound connection auditor — eBPF/Falco wrapper
Correlate electronic-warfare event logs by time/frequency/bearing to cluster emitters.
Replays a stream of transactions against pluggable fraud rules and ML scorers, emitting precision/recall and alert volume from the terminal.
Open-source phishing simulation — campaigns, templates, training
Diff two firmware images and surface exactly what changed: new binaries, flipped config flags, added certs, and shifted entropy regions.
Sniff and decode BLE GATT traffic, fingerprint device profiles, and assert on insecure pairing/characteristics in CI against a capture.
Builds a transaction graph from ledger/account data and surfaces structuring, layering, and mule-network patterns for AML triage.
Generate branded sales proposals and SOWs from a YAML scope file + pricing table into PDF/HTML, with a deterministic line-item math check.
Multi-cloud cost report, anomaly detection, and FOCUS export
Fast CLI for profiling and cleaning huge CSV / Parquet files
Validates that a mobile app's TLS pinning, certificate transparency, and network-security-config are actually enforced by replaying a MITM handshake against the
Validate classification banner markings (CUI/CONFIDENTIAL/SECRET) in documents per portion-marking rules.
Runtime agent firewall — PII redaction, rate limits, policy enforcement
CLI invoicing + payment-link generator with PDF and a local ledger
Personal breach aggregator — HIBP + DeHashed + stealer-log triage
Mainnet-fork invariant fuzzer that replays your contract against live state and stateful sequences to break protocol invariants before deploy.
Offline LLM / agent eval harness with regression gates
Agentic workflow replay & audit with OTel GenAI semantic conventions
Hunt MITRE ATT&CK techniques across logs with a rule pack
Detect & crack classical ciphers (caesar/vigenere/xor) by scoring
NIST AI RMF / EU AI Act / ISO 42001 self-assessment & SSP generator
Self-hosted status page with incident timeline and subscribers
Surface program-execution evidence from Windows Prefetch exports
Analyze an ADS-B feed/CSV for anomalies: callsign spoofing, squawk 7500/7600/7700, and unusual loiter patterns.
Find SSRF-prone sinks and unvalidated URL fetches in code
Synthetic uptime and Playwright checks exported to Prometheus
Fuzzes Android/iOS deep links, intents, and custom URL schemes against an emulator/device to surface unvalidated-redirect, injection, and component-hijack bugs.
Lint email sequences and drip campaigns for deliverability: SPF/DKIM/DMARC, link health, unsubscribe presence, and CAN-SPAM/GDPR compliance.
Generate canary URLs/tokens + a matcher for trip events
Screens counterparties and transactions against OFAC/EU/UN sanctions lists with fuzzy name matching and explainable hit scoring.
Recurring-charge and subscription detector from bank/Plaid CSV
One-command static triage of Android APK/AAB binaries: surfaces hardcoded secrets, exported components, dangerous permissions, and insecure manifest flags as a
Verifies and replays signed payment webhooks (Stripe/Adyen/PayPal/Plaid) locally, catching signature, idempotency, and replay-attack bugs.
Triage memory-dump artifacts: strings, IOCs, suspicious processes from a dump export
Continuous SBOM diff & vulnerability watch with maintainer-change tracking
Breaking-change detector for OpenAPI / GraphQL across commits
Conformance and security linter for Open Banking / FAPI APIs: validates OAuth flows, consent scopes, and PSD2 endpoints against the spec.
Replays a tx or address history to attribute sandwich, frontrun, and backrun MEV extraction with per-trade loss accounting.
Validate FHIR R4/R5 resources and bundles against profiles (US Core, etc.) with precise, line-level error reporting.
Defense logistics route/sustainment planner computing fuel, resupply windows, and chokepoint risk from a YAML plan.
Bidirectional, idempotent sync of contacts/deals between a local SQLite source-of-truth and CRM APIs (HubSpot/Pipedrive/Salesforce) via one config.
Summarize and diff nmap XML into prioritized, attackable findings
Grade TLS config (protocols/ciphers/expiry) from openssl/sslyze output
Lint documents against MIL-STD / DoD formatting and classification-marking rules.
Validate OTA update packages end-to-end: signature chains, rollback protection, anti-downgrade counters, and delta-patch integrity.
Offline RF signal reconnaissance & triage from capture files — detect, fingerprint & classify emitters (drone/Wi-Fi/BLE/GNSS) without demod. Defensive, zero-dep
Parse, pretty-print, diff, and replay HL7 v2 messages over MLLP from the terminal.
Track partnership/channel agreements as YAML records and compute account overlap, co-sell coverage gaps, and renewal/expiry alerts.
Dependency license + SBOM gate, developer-CLI first
Changelog and release notes from conventional commits
Config-first scaffolding and orchestration for multi-agent workflows
Lightweight synthetic-media detector with C2PA validation
Influence-operations pattern monitor for election periods
Aggregate & dedupe subdomain enumeration from multiple sources
Score and rank inbound/outbound leads from a YAML rulebook, emitting a ranked queue as JSON/CSV for your SDRs and CI gates.
Test an access-control matrix (role x endpoint) for IDOR/authz gaps
Detect permissive/misconfigured CORS from headers or a config
Scan documents and file metadata for OPSEC leaks: geotags, author, GPS EXIF, unit identifiers.
Local PII discovery in your own files — SSN/CC/passport/DL/email/phone/DOB
Statically map task structures, stack usage, and ISR call graphs in FreeRTOS/Zephyr firmware to flag stack overflows and priority-inversion risks.
Per-opcode and per-function gas profiler that flags unbounded loops, DoS-prone patterns, and regressions against a committed baseline.
Embedding / vector-store drift and poisoning audit
News bias & framing diff across 50+ outlets per event
Multi-provider LLM usage, cost & rate-limit meter with budget guards — Anthropic/OpenAI/OpenRouter/local, TUI + MCP + CI exit codes. Zero-dependency.
Self-hosted password cracking queue — multi-user hashcat with audit log
Summarize flows/talkers/protocols from a pcap text export
Self-hosted canary token network — AWS keys, DNS, docs, web URLs
CI/CD supply-chain auditor — GH Actions / GitLab CI / OWASP CI/CD Top 10
Surface-web mirror of public Tor leak-site index for brand monitoring
Find leaked cloud keys (AWS/GCP/Azure) + classify blast radius
Build a forensic super-timeline by merging & normalizing log/artifact CSVs
Cloud security posture from a config export (public buckets, open SGs, weak IAM)
Hardened browser profile generator — Firefox / LibreWolf / Brave
Auto-generate security policies from a short questionnaire
Alert dedup, correlation, and routing in front of Grafana / PagerDuty
Kubernetes cost and rightsizing advisor with no Prometheus dependency
Parse and classify signal metadata (freq, modulation, bandwidth) into a normalized catalog.
Scan MCP servers for RCE/SSRF/no-auth/tool-poisoning vulnerabilities
AIS vessel tracking & sanctions-evasion anomaly detection
Proposal / quote / SOW generator — YAML to branded PDF
TLS cert lifecycle & rogue-issuance watch via Certificate Transparency
Misinformation provenance tracer — earliest-known appearance graph
One-shot repo security posture grade (secrets/CI/branch rules/deps)