SecurityClaw 技能安全审计
v1.0.0
io.clawhub.mallen-lbx/securityclaw
面向 OpenClaw 技能的“安全优先”审计与隔离。当安装新技能、审查来源不明的技能、扫描技能中的提示注入/数据外泄/供应链风险,或机器人怀疑某个技能有害时使用。指导静态检查加可选沙箱检查,隔离可疑技能,并生成需人工处置的清单(删除/举报/放行/全量扫描)。
“Security Scanning” 共 1,369 个结果
v1.0.0
io.clawhub.mallen-lbx/securityclaw
面向 OpenClaw 技能的“安全优先”审计与隔离。当安装新技能、审查来源不明的技能、扫描技能中的提示注入/数据外泄/供应链风险,或机器人怀疑某个技能有害时使用。指导静态检查加可选沙箱检查,隔离可疑技能,并生成需人工处置的清单(删除/举报/放行/全量扫描)。
io.smithery.daniel-abbay.compuute-scan-api
Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back. 37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning). This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly. POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review. Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.
io.smithery.eren-solutions.mcp-security-audit
AI 驱动的代码安全审计器。扫描 GitHub 仓库中的漏洞,给出 OWASP/CWE 依据与修复建议。
v2.0.0
io.github.CallMarcus/securityscorecard-mcp
社区构建的 SecurityScorecard API 全功能 MCP 服务器(非官方)。
v3.97.0
com.blackveilsecurity/dns
DNS 与邮件安全扫描器,80 个 MCP 工具覆盖 SPF、DMARC、DNSSEC、SSL 与品牌审计。
v1.4.0
dev.workers.fhi-llc-1118.polished-truth-c514/fhi-x402-security-tools
Free payment guide and Base-USDC x402 MCP security, package, domain, and SEC tools.
v0.8.20260928
io.github.rubrikinc/rubrik-mcp
Connect AI assistants to the Rubrik Security Cloud GraphQL API to discover, query, and automate.
v1.4.0
io.github.4hmetuyar/security-proxy
MCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log
v0.8.2
io.github.alexar76/warden
MCP security firewall: stdio wrap proxy or inspection tools; zero runtime dependencies.
v1.0.0
io.github.tylerscomic-lab/github-actions-audit-mcp
Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions.
v1.0.0
io.github.tylerscomic-lab/dockerfile-audit-mcp
Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images.
v1.0.0
io.github.tylerscomic-lab/agent-skill-audit-mcp
Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration.
v0.1.0
ai.skuit/catalog
AI helper for choosing and speccing network & security products from Cisco, Arista, Juniper and more
v1.5.0
io.github.Gadriel-ai/gadriel
AI Security Harness: SAST, secrets, deps, containers, config & OWASP LLM. Scans locally.
v0.1.1
io.github.pratham-jain33/security-mcp
Zero-key security toolkit: grade sites A+ to F, check CVE exploits, plain-English attack defenses
v0.1.124
io.sealsecurity/mcp
Vulnerability management: scan projects, search sealed packages, manage sealing rules and reports.
v0.18.0
io.github.shigechika/gwsadm-mcp
MCP server for Google Workspace security auditing — login audit, external sharing, daily brief
v0.6.4
co.ship-safe/scanner
Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access.
v0.2.3
io.github.4hmetuyar/security-suite
Bundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence
v2.0.1
io.github.renaat-s/pyresec-agent
AI code security audits via x402 USDC: $0.01 scans, $0.50 audits, $5 auto-fixes. SAST/SCA.
v0.1.2
io.github.pipeworx-io/securitytrails
SecurityTrails MCP——封装 SecurityTrails API(securitytrails.com)。
v0.1.3
io.github.pipeworx-io/security-feeds
提供网络安全类资讯订阅源的 MCP。
v0.3.0
io.github.nzdsf2-gif/relayshield-mcp
数据泄露、SIM 卡调换、信息窃取器、域名仿冒、MCP 注册表风险与提示注入检测。
v1.0.7
io.github.jmshinhwa/security-txt-cra-lint
13 rules that decide whether a vulnerability report ever reaches you