Task · Coding
Best AI agents to scan code for vulnerabilities
This task needs 2 capabilities. 19 tools cover all of them; 913 cover at least one.
| # | Tool | Coverage | Access | Trust | Seen |
|---|---|---|---|---|---|
| 1 | GitHub Actions Security AuditMCP Audit GitHub Actions workflows for script injection, unpinned actions and missing permissions. | 100% | REMOTELOCAL | DECLARED | 14h ago |
| 2 | Vulnerability Intel MCPMCP Defensive vulnerability intelligence search across public CVE/NVD and GitHub advisory APIs with CVSS | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 3 | SecurityScanMCP Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 4 | regulatory-signalsMCP Audit GitHub repos for security, compliance, and EU AI Act exposure from Claude or Cursor. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 5 | flagrixMCP Scan GitHub repos and profiles for malware before cloning — commit-pinned risk verdicts for agents | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 6 | Repo Security Scanner — Malicious Code & Supply ChainMCP Audit GitHub repos for malicious and supply-chain code before you depend on them. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 7 | taskbounty-checkMCP Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 8 | dingdawg-code-reviewMCP AI code review — security, quality, performance. Learns your patterns. Receipted. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 9 | diffpilotMCP MCP server for PR code review, commit messages, changelogs, and secret detection. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 10 | Grasp — Code Architecture & Dependency AnalysisMCP Codebase analysis: dependency graphs, security scanning, and refactor plans for GitHub and GitLab. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 11 | Kubernetes Manifest AuditMCP kube-linter audit for Kubernetes manifests — 63 checks: security, availability, RBAC, network. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 12 | GitHub Actions AuditMCP GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 13 | sphior-code-mcpMCP Deterministic SAST/SCA findings + fix guidance for your GitHub repos, handed to your AI agent. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 14 | Agentic SDLC MCPMCP Agentic SDLC governance and security controls for AI coding agents working with GitHub. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 15 | MCP Code Review ServerMCP Code review as an MCP server — structured reviews with OWASP security scanning. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 16 | mcpMCP FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 17 | megalinterMCP MCP server for running Ox Security MegaLinter via mega-linter-runner | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 18 | Compuute MCP Security ScannerMCP Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 19 | VulX WatchMCP Independent security review for AI-built apps. Watch a GitHub repo. Never a patch. | 100% | REMOTELOCAL | DECLARED | 4d ago |
| 20 | security-proxyMCP Security proxy between an MCP client and server: prompt injection and drift detection | 50% | REMOTELOCAL | DECLARED | 17m ago |
| 21 | WARDEN — MCP Security FirewallMCP MCP security firewall: vet tool definitions before they reach the model. | 50% | REMOTELOCAL | DECLARED | 17m ago |
| 22 | Presend MCP ServerMCP Free MCP server of security & dev API tools -- supply-chain, CVE, DNS, WHOIS, OFAC, Cosmos SDK. | 50% | REMOTELOCAL | DECLARED | 17m ago |
| 23 | AppWizzy ProjectsMCP Create and monitor AppWizzy app environments from GitHub or ZIP with AI agents. | 50% | REMOTELOCAL | DECLARED | 1h ago |
| 24 | ClairMCP Audits AI-built websites for France and Belgium: cookies, GDPR, legal pages, exposed keys, security. | 50% | REMOTELOCAL | DECLARED | 2h ago |
| 25 | supply-chain-guardMCP Supply-chain malware scanner and MCP server: vet packages in 15 ecosystems before install, offline. | 50% | REMOTELOCAL | DECLARED | 2h ago |
| 26 | Agentic Task System (ATS)MCP MCP server giving AI agents persistent task memory across TickTick, Notion, GitHub, Linear & Beads | 50% | REMOTELOCAL | DECLARED | 4h ago |
| 27 | gitlab-mcpMCP GitLab over MCP from your own account: issues, merge requests, reviews, the repository and CI. | 50% | REMOTELOCAL | DECLARED | 4h ago |
| 28 | dracoMCP Coding & security oracle grounded in 1855 real books. Cited answers via MCP. | 50% | REMOTELOCAL | DECLARED | 5h ago |
| 29 | vdbMCP Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them. | 50% | REMOTELOCAL | DECLARED | 6h ago |
| 30 | guardvibeMCP Deterministic security layer your AI can't be. 503 rules, 39 tools, CLI + doctor + host audit. | 50% | REMOTELOCAL | DECLARED | 6h ago |
| 31 | gitlab-mcpMCP GitLab MCP server for projects, merge requests, issues, pipelines, wiki, releases, and more. | 50% | REMOTELOCAL | DECLARED | 7h ago |
| 32 | KubeStellar MCPMCP AI-powered Kubernetes diagnostics, RBAC analysis, security checks, and app deployment via MCP | 50% | REMOTELOCAL | DECLARED | 7h ago |
| 33 | VersionlyMCP Monitor third-party API changes in GitHub repos, map breaks to files, open reviewable auto-fix PRs. | 50% | REMOTELOCAL | DECLARED | 7h ago |
| 34 | DraugrMCP Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk. | 50% | REMOTELOCAL | DECLARED | 8h ago |
| 35 | vaastMCP Read-only access to VAAST vulnerability scan findings, workspaces, and targets for AI agents | 50% | REMOTELOCAL | DECLARED | 11h ago |
| 36 | cliMCP Search your developer network and trace connection paths via GitHub & LinkedIn. | 50% | REMOTELOCAL | DECLARED | 13h ago |
| 37 | TrentMCP Security reviews, threat models over a repo or website, and remediation tracking, in your editor. | 50% | REMOTELOCAL | DECLARED | 13h ago |
| 38 | agent-bomMCP Security scanner and graph for agentic infrastructure — agents, MCP, runtime, and blast radius. | 50% | REMOTELOCAL | DECLARED | 13h ago |
| 39 | Dockerfile Security AuditMCP Audit Dockerfiles for root users, baked-in secrets, curl-pipe-shell and unpinned base images. | 50% | REMOTELOCAL | DECLARED | 14h ago |
| 40 | Pine Script Strategy AuditMCP Static analysis for Pine Script v6 strategies — catches backtest-vs-live divergence traps. | 50% | REMOTELOCAL | DECLARED | 14h ago |
| 41 | Agent Skill & Config Security AuditMCP Scan AI agent skills and configs for hidden Unicode, prompt injection and exfiltration. | 50% | REMOTELOCAL | DECLARED | 14h ago |
| 42 | uploads.shMCP Host files from coding agents; stage on a branch and attach to GitHub PRs. | 50% | REMOTELOCAL | DECLARED | 15h ago |
| 43 | hacktricks-mcpMCP Offline full-text search over the HackTricks security wiki, synced every 3 days. | 50% | REMOTELOCAL | DECLARED | 17h ago |
| 44 | GitHubMCP Connect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language. | 50% | REMOTELOCAL | DECLARED | 18h ago |
| 45 | cubicMCP Triage cubic AI code review findings, start PR reviews, and read wikis, scans, and team learnings. | 50% | REMOTELOCAL | DECLARED | 18h ago |
| 46 | GitHub Repo Change IntelligenceMCP Track public GitHub repos: free snapshot, paid release, star & issue intel via x402 USDC. | 50% | REMOTELOCAL | DECLARED | 19h ago |
| 47 | OpenOSINTMCP AI-powered OSINT agent & MCP server. 16 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more. | 50% | REMOTELOCAL | DECLARED | 20h ago |
| 48 | rrubocopMCP Fast RuboCop-compatible Ruby linter with MCP inspect and autocorrect tools. | 50% | REMOTELOCAL | DECLARED | 20h ago |
| 49 | OctoCounts MCP ServerMCP Analyze and compare public GitHub repo line counts (SLOC) via OctoCounts, from any MCP client. | 50% | REMOTELOCAL | DECLARED | 20h ago |
| 50 | MCP Server for OSCALMCP AI agent tools for Open Security Controls Assessment Language (OSCAL) | 50% | REMOTELOCAL | DECLARED | 23h ago |
Page 1 / 19Next →
Coverage = share of this task's required capabilities that an agent or tool documents. For AI agents, capabilities are those stated on the vendor's website; for tools, they are matched automatically from the publisher's description (keyword method, low confidence).