ci-sentinel
Related Servers
Alternatives to ci-sentinel
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityDmaintenanceAudits GitHub Actions workflow files for supply-chain risks like script injection, leaked tokens, unpinned actions, and broad permissions.-
- AlicenseNot gradedqualityBmaintenanceA keyless, defensive code-security auditor that scans codebases for hardcoded secrets, audits dependencies for known CVEs, and checks passwords against breach data using k-anonymity.1MIT
- FlicenseBqualityDmaintenanceEnables security auditing, penetration testing, and compliance validation with tools like Semgrep, Trivy, Gitleaks, and OWASP ZAP. Features strict project boundary enforcement and supports OWASP, CIS, and NIST compliance frameworks.7-

EVIDIQ Bastionofficial
AlicenseNot gradedqualityBmaintenanceAudits infrastructure configurations (Dockerfiles, GitHub Actions, Kubernetes, Terraform/Compose) against 14 deterministic security rules, returning BLOCK/REVIEW/PASS verdicts and signing attestations. Helps agents verify deployment configs before applying them.1MIT- AlicenseBqualityDmaintenanceUniversal AI security layer for code scanning, PII detection, prompt injection defense, secret detection, dependency auditing, and audit logging.273Apache 2.0
- FlicenseNot gradedqualityCmaintenanceEnables local security scanning and compliance gap analysis for code and text, detecting secrets, PII, and OWASP vulnerabilities, and assessing readiness across major frameworks like NCA, ISO 27001, NIST CSF, and SOC 2.-
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: one performs a full security audit of CI configs, the other computes a differential between before and after states. No overlap or confusion possible.
Both tools follow a consistent verb_ci_security pattern: audit_ci_security and diff_ci_security. The naming is uniform and predictable.
Only 2 tools for a domain that spans 7 CI ecosystems and OIDC IaC analysis. While each tool is comprehensive, the server lacks granularity (e.g., per-ecosystem tools) which might limit agent flexibility.
The tools cover full auditing and differential analysis for all major CI/CD systems and OIDC misconfigurations. Missing are tools for fixing or managing findings, but core scanning needs are well addressed.