Skip to main content
Glama
Baneado98

ci-sentinel

by Baneado98

Related Servers

Alternatives to ci-sentinel

No user-submitted related servers found.

    Related Servers

    • F
      license
      Not graded
      quality
      D
      maintenance
      Audits GitHub Actions workflow files for supply-chain risks like script injection, leaked tokens, unpinned actions, and broad permissions.
      -
    • A
      license
      Not graded
      quality
      B
      maintenance
      A keyless, defensive code-security auditor that scans codebases for hardcoded secrets, audits dependencies for known CVEs, and checks passwords against breach data using k-anonymity.
      1
      MIT
    • F
      license
      B
      quality
      D
      maintenance
      Enables security auditing, penetration testing, and compliance validation with tools like Semgrep, Trivy, Gitleaks, and OWASP ZAP. Features strict project boundary enforcement and supports OWASP, CIS, and NIST compliance frameworks.
      7
      -
    • A
      license
      Not graded
      quality
      B
      maintenance
      Audits infrastructure configurations (Dockerfiles, GitHub Actions, Kubernetes, Terraform/Compose) against 14 deterministic security rules, returning BLOCK/REVIEW/PASS verdicts and signing attestations. Helps agents verify deployment configs before applying them.
      1
      MIT
    • A
      license
      B
      quality
      D
      maintenance
      Universal AI security layer for code scanning, PII detection, prompt injection defense, secret detection, dependency auditing, and audit logging.
      27
      3
      Apache 2.0
    • F
      license
      Not graded
      quality
      C
      maintenance
      Enables local security scanning and compliance gap analysis for code and text, detecting secrets, PII, and OWASP vulnerabilities, and assessing readiness across major frameworks like NCA, ISO 27001, NIST CSF, and SOC 2.
      -

    TDQS

    A4.5/5.0

    Scored across 2 tools

    Disambiguation5/5

    The two tools have clearly distinct purposes: one performs a full security audit of CI configs, the other computes a differential between before and after states. No overlap or confusion possible.

    Naming Consistency5/5

    Both tools follow a consistent verb_ci_security pattern: audit_ci_security and diff_ci_security. The naming is uniform and predictable.

    Tool Count3/5

    Only 2 tools for a domain that spans 7 CI ecosystems and OIDC IaC analysis. While each tool is comprehensive, the server lacks granularity (e.g., per-ecosystem tools) which might limit agent flexibility.

    Completeness4/5

    The tools cover full auditing and differential analysis for all major CI/CD systems and OIDC misconfigurations. Missing are tools for fixing or managing findings, but core scanning needs are well addressed.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues