Provides security audit primitives for MCP servers, agent tool schemas, and system prompts, along with pentest utilities like JWT inspection and HTTP diffing.
Static analysis scanner for multi-tenant SaaS and MCP server code that catches cross-tenant data leakage with 57 deterministic rules, including an MCP server for Claude Desktop and Cursor integration.
Enables agents to vet MCP servers and agent configurations before trusting them, using local static analysis to detect injection, dangerous capabilities, exfiltration paths, and CVEs, with policy-based gating for CI.
Enables static security scanning of MCP servers, AI agent skills, and plugins by detecting attack patterns across severity levels and producing SARIF output for GitHub Code Scanning.