"Spring Security" matching MCP connectors:
Matching Connector Tools:
Proves AI-generated Python does what you asked: lint, types, security, sandbox run, exact fixes.
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Security + bug + perf + refactor audit for Python. Returns 0-10 score + MD report.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
MCP gateway with 10 tools for code analysis, architecture, package audit & security.
The OpenZeppelin Stylus Contracts MCP server generates secure smart contracts for the Arbitrum Stylus environment using OpenZeppelin templates, including ERC-20, ERC-721, and ERC-1155 standards. It automatically validates generated code against OpenZeppelin's security and style rules, enforcing best practices for imports, modifiers, naming conventions, and security checks to prevent common vulnerabilities. The server integrates with AI development tools like Cursor, Claude, Gemini, Windsurf, and VS Code to enable AI-assisted, production-ready smart contract development.
MCP server for static security analysis of Android source code
The OpenZeppelin Solidity Contracts MCP server integrates OpenZeppelin's security and style rules into AI-driven development workflows, enabling AI assistants to generate safe, correct, and production-ready smart contracts. It automatically validates generated code against OpenZeppelin standards (including imports, modifiers, naming conventions, and security checks) and supports various contract types including ERC-20, ERC-721, ERC-1155, Stablecoins, RWA, Governor, and Account contracts through prompt-driven workflows.
The OpenZeppelin Cairo Contracts MCP server generates secure smart contracts in the Cairo language for Starknet environments based on OpenZeppelin templates. It brings OpenZeppelin's proven security and style rules directly into AI-driven development workflows to create safe, production-ready contracts. Key capabilities include providing templates for ERC-20, ERC-721, ERC-1155, Multisig, Governor, and Vesting contracts.
Vulnerability management: scan projects, search sealed packages, manage sealing rules and reports.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Security audits for WordPress plugins and themes — 62 verification layers, fix plans and SBOMs.
Validates AI-generated Python: syntax, lint, security scan and deterministic repair.
Security reviews for coding agents: diffs checked against your org policy and live infrastructure.
Enterprise code intelligence for M&A, security audits, and tech debt. Hosted server with 200k free.
## Skill Catalog The library contains 42 public skills organized by Rails development concern. | Category | Examples | |----------|----------| | Planning | `create-prd`, `generate-tasks`, `plan-tickets` | | Testing | `plan-tests`, `write-tests`, `test-service`, `triage-bug` | | Code quality | `code-review`, `respond-to-review`, `security-check`, `refactor-code` | | Architecture and DDD | `define-domain-language`, `review-domain-boundaries`, `model-domain`, `review-architecture` | | Rails imple
Deep security scans of repos you own from your editor: dependency CVEs, SAST, git-history secrets.