Enables agents to prove and verify that a real, unique human performed an action, issuing machine-readable signed credentials with public verification.
Assists in Advanced Persistent Threat malware analysis by providing tools to securely download samples via jump servers using SSH and SCP. It enables automated retrieval of remote files through a multi-hop configuration for analysis workflows.
Enables AI assistants to access real-time threat intelligence, malware sample metadata, and security analysis tools via integration with MalwareBazaar, VirusTotal, and Telegram.
Provides real-time threat intelligence and malware metadata by integrating with MalwareBazaar and VirusTotal APIs. Users can search for IOCs, analyze local file hashes, and access data transformation tools for defensive security research.
Analyzes raw email headers and emails for phishing, spoofing, and BEC using AI forensics, SPF/DKIM/DMARC/ARC validation, and IP reputation checks. Exposes analyze_email, get_analysis, and list_analyses as MCP tools.
Enables comprehensive ransomware threat analysis through 25+ tools that interact with ransomware.live API. Provides real-time data on ransomware groups, victims, negotiations, IOCs, and attack trends for cybersecurity investigation and monitoring.
An MCP server that provides authorization middleware for AI agents using private data, enabling consent management on Aleo and local private inference with persistent policy storage.
Enables interaction with the Huntress SAT API to manage security awareness training, including learners, phishing campaigns, and training assignments. It supports OAuth2 authentication and optional role-based access control for secure organizational management.
Enables AI-powered analysis of Rapid7 vulnerability and asset data by exporting via the Bulk Export API and making it queryable through natural language or SQL in MCP-compatible tools.
Mandatory human approval gate for autonomous AI agents. Before any critical, irreversible, or
financially significant action executes — file deletion, production deployment, financial transaction
— the agent calls oracle_validate. A human receives a real-time Telegram notification with full
context and taps Approve or Reject. The agent waits for the decision before proceeding.
Before an AI agent pays an x402 endpoint, checks whether it's safe to pay: liveness, scam/anomaly scan (payTo hijack, bait-and-switch, honeypot), and on-chain receiver verification. ~70% of x402 endpoints are dead or scams.
security tools for AI agents: URL safety scanning, prompt injection detection (200+ patterns), email/password breach checks via HIBP, domain & IP reputation analysis, and AI skill supply chain scanning. Free tier (3 calls/day) or pay-per-request with USDC micropayments via x402.
Enables AI assistants to execute malware analysis tools on a REMnux system via Docker, SSH, or local connections. It provides automated file-type analysis, structured tool discovery, and security guardrails for streamlined malware investigation.
Enables security analysis of URLs, files, IPs, and domains using the VirusTotal API, with automatic fetching of relationship data to provide comprehensive reports.
Interactive visualization of Microsoft Entra ID identity relationships, enabling exploration of org charts, groups, attributes, and access assignments through a D3 force-directed graph within MCP clients.
A security gate MCP server that audits agent extensions (skills, MCP servers, tools) by scanning for risks, adversarial analysis, and sandbox execution, returning a trust verdict of allow, quarantine, or block.