@loxeai/mcp-server
Related Servers
Alternatives to @loxeai/mcp-server
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityCmaintenanceEnables local security scanning and compliance gap analysis for code and text, detecting secrets, PII, and OWASP vulnerabilities, and assessing readiness across major frameworks like NCA, ISO 27001, NIST CSF, and SOC 2.-
- AlicenseAqualityCmaintenanceEnables local-first scanning of Terraform for security misconfigurations while an AI assistant writes the code, providing fixes and compliance mappings without uploading infrastructure code.87Apache 2.0
- FlicenseNot gradedqualityAmaintenanceEnables auditors to scan cloud IAM policies for privilege-escalation paths, wildcards, and risky grants directly within Cursor or Claude Code, using a deterministic rule engine that runs entirely on local infrastructure.1-
- AlicenseAqualityBmaintenanceEnables analyzing Salesforce deployment logs, validating metadata manifests, assessing permission risks, and generating remediation plans through deterministic, local-only rules.4MIT
- AlicenseNot gradedqualityCmaintenanceEnables LLMs to perform automated compliance scanning of AWS infrastructure against PCI-DSS, CIS, and Well-Architected frameworks. It provides tools for scanning, remediation, and audit report generation.MIT
- FlicenseNot gradedqualityDmaintenanceAn MCP-powered compliance copilot for SaaS stacks, enabling structured audit workflows including stack detection, module wiremapping, implementation directives, code verification, and security/infrastructure/legal readiness gates.-
TDQS
Scored across 16 tools
Every tool targets a distinct step in the scan-to-evidence pipeline: scan vs paginate vs detail vs explain vs classify vs map are clearly separated, and even the adjacent preview/render and status/capability pairs are differentiated by their names and descriptions. There is no pair an agent would plausibly confuse when selecting a tool.
Most tools follow a lower_snake_case verb_noun pattern (scan_iac, list_findings, render_trust_page); a few are noun-phrase names (controls, scanner_status, applicability_brief). The style is still internally consistent and readable, so this is a minor deviation rather than a real problem.
16 tools is one above the typical well-scoped range, but each tool maps to a distinct stage in the SOC 2 IaC workflow: environment checks, scanning, finding navigation, mapping, applicability, policy drafting, and reporting. No tool is redundant, so the count feels deliberate rather than bloated.
The tool surface covers the full lifecycle this server promises: environmental preflight, scanning, finding investigation, control mapping, blast-radius triage, tailored applicability, policy draft, trust-page rendering, and OSCAL export. The read-only/no-file-write constraint is consistently honored and does not leave obvious dead ends; list_findings/get_finding and applicability_questions/applicability_brief are properly chained.