Task · Coding
Best AI agents to scan code for vulnerabilities
This task needs 2 capabilities. 19 tools cover all of them; 919 cover at least one.
| # | Tool | Coverage | Access | Trust | Seen |
|---|---|---|---|---|---|
| 301 | GitlabMCP GitLab MCP — wraps the GitLab REST API v4 (BYO API key) | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 302 | GitignoreMCP gitignore MCP — github/gitignore templates. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 303 | GithubMCP GitHub MCP — wraps the GitHub public REST API (no auth required for public endpoints) | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 304 | Github_privateMCP GitHub Private MCP Pack — access private repos, org data via OAuth. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 305 | Circl Vulnerability LookupMCP CIRCL Vulnerability-Lookup — aggregated vulnerability records | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 306 | Guarded WhatsAppMCP Security gate for agent-driven WhatsApp: allowlist, secret scan, rate limit, audit log. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 307 | Perceptdot GitHubMCP AI agent vision for GitHub repository monitoring — with ROI measurement. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 308 | OWASP ZAP MCP ServerMCP MCP server for OWASP ZAP vulnerability scanning with Docker management | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 309 | Jeevesus — DugganUSA Threat Intelligence MCPMCP check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 310 | DugganUSA CLI — Local STDIO MCPMCP Local STDIO MCP for DugganUSA threat intel. 1.13M IOCs. Read-only. npm: dugganusa-cli. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 311 | SkimlessMCP Reading order for big pull requests: what to read first, what can wait. Offline, no model. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 312 | Dredd MCPMCP Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 313 | odoo-mcp-gatewayMCP Security-first MCP gateway for Odoo 17/18/19 — YAML-driven security, 27 tools | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 314 | Pine Script v6 DocumentationMCP Pine Script v6 documentation lookup, function validation, and linting for AI code generation | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 315 | sqlike-mcpMCP SQL static analysis & query-equivalence for Postgres, MySQL, SQLite, and SQL Server | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 316 | compliance-trestle-mcpMCP An MCP server that provides tools to author OSCAL security compliance documentation | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 317 | VulnHunt Security IntelligenceMCP Read-only smart-contract security intelligence for autonomous agents. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 318 | GitHub PR ContextMCP Retrieves GitHub PR history as context material; the connected IDE agent does the reasoning. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 319 | BenchBossMCP Play Chess, RPS-N and Safehouse Protocol via MCP. Public replays; GitHub verification required. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 320 | Agentic Security ShieldMCP 12-layer security configs for AI coding agents. Autonomous purchase via x402 (USDC on Base). | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 321 | operant-mcpMCP Security testing MCP server for penetration testing, forensics, and vulnerability assessment | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 322 | osf-data-marketplaceMCP 8.1M+ US gov and science data via x402 USDC. 21 tools, $0.001 sample tier, sanctions, SEC, CVEs. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 323 | council-aiMCP Multi-LLM council: 25+ frontier models in parallel, consensus scoring, verdict-first code review. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 324 | SecHelixMCP Evidence-first security review of authorized repositories. Read-only, root-confined, no shell. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 325 | github-gistMCP MCP server to create, read, update, list, and search GitHub Gists from your IDE | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 326 | npm-plusMCP npm MCP — search packages, bundle sizes, vulnerabilities, compare downloads. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 327 | mcpvessel-docsMCP mcpvessel agent io.github.okedeji/mcpvessel-docs | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 328 | GitLab Documentation MCP ServerMCP Searchable access to GitLab documentation from multiple repositories with full-text search. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 329 | RelayShield Security IntelligenceMCP Breach, SIM swap, infostealer, domain lookalikes, MCP registry risk, prompt-injection detection. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 330 | github-actionsMCP GitHub Actions MCP — view runs, read logs, re-run jobs, and manage CI/CD. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 331 | ruchy-mcpMCP MCP server for Ruchy: code analysis, scoring, linting, formatting, and transpilation tools | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 332 | PQC-Khepra MCP — CMMC Autopilot & AI Security RecorderMCP Post-quantum CMMC compliance scanner & AI agent attestation. FIPS 140-3, ML-DSA-65, 36K+ mappings. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 333 | VulnFeedMCP Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 334 | mcp-code-sanitizerMCP Strict AI code reviewer powered by Groq. Finds bugs and vulnerabilities. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 335 | AI Tool Discovery AgentMCP AI agent discovers MCP servers from GitHub npm - analyzes APIs configs | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 336 | GitHub to MCP ConverterMCP Convert any GitHub repo to MCP server - automatic tool generation API wrap | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 337 | Repository IntelligenceMCP Analyze repos of any size - security scanning code analysis monorepo support | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 338 | universalbenchMCP Run code, query databases, call any LLM, and commit to GitHub from your AI, safely. Free tier. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 339 | okffsMCP MCP server connecting Claude Code to GitHub for an issue to branch to PR to close workflow. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 340 | nexus-mcpMCP Japanese LLM security — prompt injection detection (jpi-guard) + PII masking (PII Guard). Free. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 341 | goliveMCP Check a site before you share it: link previews, SPA refresh 404s, noindex, security headers. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 342 | mythos-agentMCP Open-source AI security agent: SAST, DAST, and policy-as-code over MCP. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 343 | AuditraMCP Read-only MCP server for WordPress plugin audits: vulnerabilities, bloat, cron, orphaned tables. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 344 | recon-kit-mcpMCP Read-only network & security recon tools (DNS, TLS, headers, CORS) for AI agents, each graded. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 345 | gitlab-ci-mcpMCP GitLab CI/CD MCP — pipelines, jobs, schedules, MRs, files. Any GitLab (SaaS or self-hosted). | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 346 | unicode-security-mcpMCP Local first MCP checks for Unicode confusables, mixed scripts, invisible controls, and... | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 347 | ssl-labs-mcpMCP TLS security grades from SSL Labs. No key required. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 348 | nvd-cve-mcpMCP Search CVE vulnerability records from the NIST NVD database. No key required. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 349 | osv-mcpMCP Use this MCP server to OSV open source vulnerability data and package security checks. Tools... | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 350 | maltiverse-mcpMCP Threat intelligence for IPs and domains from Maltiverse. No key required. | 50% | REMOTELOCAL | DECLARED | 5d ago |
Coverage = share of this task's required capabilities that an agent or tool documents. For AI agents, capabilities are those stated on the vendor's website; for tools, they are matched automatically from the publisher's description (keyword method, low confidence).