MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a clear, actionable baseline for securing MCP deployments , whether you're shipping an internal tool or a customer-facing AI agent.
☆22Mar 9, 2026Updated 6 months ago
Alternatives and similar repositories for mcp-security-checklist
Users that are interested in mcp-security-checklist are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Human Delegation Provenance Protocol - cryptographic chain-of-custody for agentic AI☆18Aug 3, 2026Updated last month
- TypeScript port of ACE framework, written entirely by Claude Code running in a loop☆22Dec 4, 2025Updated 9 months ago
- Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.☆49Updated this week
- LdapWordlistHarvester but then with neo4j☆17Jun 3, 2025Updated last year
- Jailbreak detection bypasses based on Frida.☆21Oct 6, 2025Updated 11 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Browser based Privacy Aware SBoM Exploration☆37Updated this week
- Visual Studio Code extension for TOON format support☆16Dec 2, 2025Updated 9 months ago
- DevSecOps for the AI-era CI/CD pipeline. Catches the bugs your AI coding assistant introduces — before they reach production.☆64Updated this week
- A Burp Suite extension that detects, catalogs, and exports developer comments, secrets, and keywords embedded in both HTTP response bodie…☆19Sep 18, 2025Updated 11 months ago
- Secure Rust Code☆16Dec 10, 2024Updated last year
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆60Feb 29, 2024Updated 2 years ago
- A local reverse proxy that records every LLM request/response to SQLite. No cloud, no data leaving your machine.☆15Mar 1, 2026Updated 6 months ago
- A web frontend for tesseract-ocr☆11Aug 4, 2023Updated 3 years ago
- AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and …☆21Mar 9, 2026Updated 6 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆10Aug 9, 2024Updated 2 years ago
- TheDarkMark is a C2 framework designed to be fast and parallel.☆24Jul 21, 2026Updated last month
- Reverse engineering the TI AM3358 boot ROM☆67Aug 25, 2024Updated 2 years ago
- Autogrep automates Semgrep rule generation and filtering by using LLMs to analyze vulnerability patches, enabling automatic creation of h…☆88Feb 27, 2025Updated last year
- visually see issues with supported cipher suites☆19May 28, 2026Updated 3 months ago
- N8N Langfuse integration via Open Telemetry☆15Sep 17, 2025Updated 11 months ago
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 3 months ago
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆34Feb 10, 2026Updated 7 months ago
- a dead simple monitoring service with real time alerts☆20Jan 29, 2026Updated 7 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆18Oct 24, 2025Updated 10 months ago
- Search an entire directory of .eml email files for a word or phrase... in over 100 languages.☆12Feb 28, 2023Updated 3 years ago
- ☆19Dec 25, 2025Updated 8 months ago
- The DNS Security Analysis Tool is a Python-based utility designed to conduct an in-depth security analysis of DNS configurations for mult…☆20Oct 18, 2024Updated last year
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆91Jun 15, 2026Updated 2 months ago
- AD CS exploitation related stuff goes here☆38Mar 23, 2026Updated 5 months ago
- A Fast, Modular, and Scalable TLS/SSL Security Scanner Written in Rust☆38Aug 27, 2026Updated 2 weeks ago
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆176Jun 19, 2026Updated 2 months ago
- Tricard - Malware Sandbox Fingerprinting☆24Dec 11, 2023Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- CloudConqueror is a 4 parter tool, which provides simulation of utilizing AWS CloudControl API as an attack tool.☆15Oct 2, 2025Updated 11 months ago
- ☆17Aug 5, 2026Updated last month
- A Windows tool that converts LDIF files to BloodHound CE☆31Dec 20, 2025Updated 8 months ago
- a small python container that lets you proxy requests from claude's cloud container through your home network☆17Dec 31, 2025Updated 8 months ago
- A Collection of Proof of Concepts for non-published Web Exploits and Common CVEs☆10Nov 29, 2020Updated 5 years ago
- Windows named pipe hooking toolkit