MCP server for AI-driven VAPT orchestration, enabling agents to plan and execute authorized security scans through a control plane that enforces scope, sanitization, budget, rate limits, human approval, and audit logging.
An authorization-first MCP-governed control plane for executing security-tool workflows in explicitly approved, sandboxed environments with auditable campaigns and AI collaboration boundaries.
Enables security analysts to carry structured investigation state across sessions by storing typed observations, hypotheses, tasks, evidence and versioned decisions in a local SQLite graph with full-text search. It also enforces authorized scope and request controls, redacted and content-hashed evidence, duplicate-test signatures and validation gates that leave findings in draft until reproducibly confirmed, then produces technical and executive reports for Antigravity, Codex and other stdio MCP clients.
Enables natural-language-driven security testing by orchestrating multiple pen-testing tools through MCP, with automated scan execution and AI-assisted vulnerability summarization.
Offers a control surface for AI agent security with four independent checks: source-code scanning, tenant isolation, LLM content verification, and deploy gating. Currently in pre-release, with no functional scanning engines yet.
Enables red-team and blue-team security workflows on BlackArch Linux by wrapping local tools like nmap, gobuster, nikto, and hydra as MCP tools, with scope-gating that prevents unauthorized scanning against any target not explicitly listed in a local scope.yaml file.
Turns any MCP-capable AI agent into a professional penetration testing platform with 150+ security tools, adaptive async tasks, and crash-proof concurrency.
Provides AI agents with 25 security analysis tools including vulnerability scanning, package hallucination detection, prompt injection firewall, and CI/CD integration.
Enables AI agents to run bounded security reconnaissance tools against a local OWASP Juice Shop target via MCP, including HTTP checks, header inspection, Nmap scanning, and web enumeration, without granting arbitrary shell access.
Enables remote execution of 150+ offensive-security tools through a streamable-HTTP MCP server, allowing MCP clients like Claude Code to drive the HexStrike toolset over the network.
Enables MCP-compatible agents to query security checklists, protocols, and framework mappings to safely build and operate AI agents, with tools for checklist runs, protocol lookup, mapping lookup, and threat search.
A production-ready MCP server that wraps Nmap to enable AI agents to perform automated network security assessments, including port scanning, host discovery, service detection, OS fingerprinting, and vulnerability scanning.
Enables AI assistants to scan websites, public repositories, and OpenClaw/CLAW skills for security vulnerabilities, including local skill-package analysis before installation, cloud scans, and remediation guidance.
Enables AI agents to perform passive reconnaissance, vulnerability intelligence, DNS analysis, and device search using Shodan's database of internet-connected devices, all from within your IDE.