An MCP server that enables AI agents to perform comprehensive GitHub security audits across org settings, repositories, Actions workflows, secrets, supply chain, and access control using 39 tools and 45 checks.
A lightweight stdio-to-http relay that enables the GitHub MCP server to authenticate using a GitHub App instead of a Personal Access Token. It automatically manages fine-grained permissions and short-lived tokens for secure, organizational AI agent workflows.
Enables AI clients to audit GitHub repositories for Dependabot, code scanning, and secret scanning alerts, generate conservative remediation plans, and execute verified fixes through MCP tools with fail-closed mutation controls.
This MCP server enables users to sign in with GitHub and use AI agents to scan entire repositories for leaked secrets such as API keys, passwords, and tokens, delivering a report with the exact file and line plus remediation guidance.
Scans diffs, files, and snippets for leaked secrets like AWS keys, GitHub tokens, and private keys, returning redacted findings while running fully locally without network calls.
Enables AI assistants to monitor GitHub repository health by calculating health scores, fetching repository metadata, analyzing Dependabot alerts, checking CI/CD status, and retrieving code scanning alerts.
Secure credential management for AI agents — encrypted storage, auto-refresh, and rate limiting via a single MCP call. Supports OpenAI, Anthropic, Stripe, GitHub, Brave Search, Kalshi, Coinbase, plus generic API key and OAuth2 for any service.
Exposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.
MCP server that integrates the Phylax verification API, enabling AI assistants to verify packages, repositories, and other MCP servers before use. It exposes tools for verifying artifacts, checking policies, and fetching attestations.
Enables AI to read and analyze repository incident scan results, including file diffs and summaries, to help investigate suspicious changes. It is read-only and does not execute code or send data externally.
Enables AI assistants to scan websites, public repositories, and OpenClaw/CLAW skills for security vulnerabilities, including local skill-package analysis before installation, cloud scans, and remediation guidance.
Enables agents to audit and safeguard repositories by detecting dependency pinning issues, license compliance problems, hardcoded secrets, and dead code through MCP tools.