Skip to main content

Browse the directory

Showing 21 resources for "scanning"
Saved
Active

1 trusted · 20 review in this set — compare to see which signals differ.

Trust snapshot

21 results in this view

Claimed
0%(0/21)

4 trust signals differ in this sample: Review status, Package trust, Source provenance, Submitter

Signals differ on Review status, Package trust, Source provenance — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

12 scanned

Install payload

Install payload is broadly covered in current results.

good

75% (9/12)

Adoption queue

Browse adoption queue · balanced

4/21 visible results are in hold tier and need mitigation before adoption.

ready 0caution 17hold 4

Socket MCP Server for Claude

1 blockers: Metadata review

caution

70/100

Request metadata review from maintainers or internal owners.

mcp/socket-mcp-server · trust trusted · confidence 83%

ContrastAPI Security Tools

No required blockers for this preset.

caution

64/100

Collect package checksum or signed artifact information.

mcp/contrastapi-mcp-server · trust review · confidence 83%

BoolsAI Scan MCP Server for Claude

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

mcp/boolsai-scan-mcp-server · trust review · confidence 67%

Docker Image Security Scanner - Hooks

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/docker-image-security-scanner · trust review · confidence 67%

git-secrets Environment Risk Statusline

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

statuslines/git-secrets-env-risk-statusline · trust review · confidence 67%

Hardcoded Secret Pre-Write Guard Hook

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/environment-variable-leak-warning-hook · trust review · confidence 67%

Kubernetes DevSecOps Engineer for Claude

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

rules/kubernetes-devsecops-engineer · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

4/21 results are low-confidence and need review before adoption.

high 1medium 16low 4

Socket MCP Server for Claude

Confident candidate for staged adoption.

high

74/100

Missing: Metadata review

mcp/socket-mcp-server · trust trusted

ContrastAPI Security Tools

Address Package integrity before broader rollout.

medium

68/100

Missing: Package integrity

mcp/contrastapi-mcp-server · trust review

BoolsAI Scan MCP Server for Claude

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

mcp/boolsai-scan-mcp-server · trust review

Docker Image Security Scanner - Hooks

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

hooks/docker-image-security-scanner · trust review

git-secrets Environment Risk Statusline

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

statuslines/git-secrets-env-risk-statusline · trust review

Hardcoded Secret Pre-Write Guard Hook

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

hooks/environment-variable-leak-warning-hook · trust review

Kubernetes DevSecOps Engineer for Claude

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

rules/kubernetes-devsecops-engineer · trust review

Freshness distribution

50% of this view is aging or stale

Median age 77 days; 6 fresh of 12 scanned. Re-verify the oldest entries.

median 77d

Aging

91–180 days

8%

1 entry

Stale

> 180 days

42%

5 entries

Theme distribution

Results center on security

81% of this view shares the top theme. Leading themes: security, code-review, privacy.

Focused

74 distinct themes across 21 scanned

ContrastAPI logo

49 remote MCP security tools for CVE/KEV/CWE/EPSS lookup, composite CVSS+EPSS+KEV+PoC risk scoring, CVSS v3.x vector parsing, domain/IP/IOC enrichment, dependency and web intelligence checks, MITRE ATLAS AI/ML attacks, and MITRE D3FEND defenses. Anonymous tier available; Pro tier uses an API key.

Claude Code statusline that surfaces sensitive environment-file risk and can optionally run git-secrets as a local pre-commit-style scanner.

Docker logo

Comprehensive Docker image vulnerability scanning with layer analysis, base image recommendations, and security best practices enforcement. This PostToolUse hook automatically scans Docker images for vulnerabilities when Dockerfiles are modified, providing real-time security validation during development.

Trigger:PostToolUse
Safety ✓ Privacy ✓
Kubernetes logo

Expert in Kubernetes DevSecOps with GitOps workflows, pod security standards, RBAC, secret management, and automated security scanning for production clusters

Automated security vulnerability scanning that integrates with development workflow to detect and prevent security issues before deployment.

Trigger:PostToolUse
Safety ✓ Privacy ✓

Scans for potential sensitive data exposure and alerts immediately.

Trigger:Notification
Safety ✓ Privacy ✓
Grype logo
Grypeby Anchore · submitted by oktofeesh1

Apache-2.0 vulnerability scanner from Anchore for container images, filesystems, archives, SBOMs, PURLs, and CPEs, with risk scoring, VEX filtering, and CI-friendly output.

Kubernetes logo
Kubescapeby Kubescape · submitted by oktofeesh1

Apache-2.0 CNCF-incubating Kubernetes security platform and CLI for scanning clusters, manifests, Helm charts, Kustomize projects, Git repositories, and container images for misconfigurations, compliance gaps, and vulnerabilities.

Gitleaks logo
Gitleaksby Gitleaks · submitted by oktofeesh1

Open-source secret scanner for finding passwords, API keys, tokens, and other credentials in git history, files, directories, and stdin.

PreToolUse Write and Edit guardrail combining the hooks guide protected-file pattern with a local scan for common hardcoded credential shapes called out by GitHub secret scanning guidance before content is written.

Trigger:PreToolUse
Safety ✓ Privacy ✓

BoolsAI hosted MCP server with no authentication required for tech stack scanning via boolsai_scan and boolsai_scan_paths tools on boolsai.ai/mcp.

Odoo MCP Server logo

MCP server for Odoo ERP systems, with tools for reading records, discovering models and fields, aggregating data, diagnosing access, scanning addons, planning migrations, and running gated safe-write workflows.

Slash command runbook for scanning HeyClaude catalog collisions by slug, title, repo URL, and docs URL before opening a content-only PR—using audit-content patterns and GitHub code search.

Invocation:/catalog-collision-scan <category> <proposed-slug>
Safety ✓ Privacy ✓

Secure Claude Code hooks in shared repositories: version-control hook configs, code review for PreToolUse and PostToolUse scripts, least-privilege matchers, secret scanning, and rollback when hook behavior changes.

Source-backed agent for security review of open-source pull requests, including untrusted fork boundaries, GitHub Actions permissions, secret and code scanning, dependency review, provenance signals, and maintainer-owned merge recommendations.

A source-backed collection for private research workflows: local-first planning, reproducible notebooks, local analytical processing, redaction, human review datasets, trace review, and secret scanning before outputs are shared.

Giskard logo

AI testing platform for evaluating, scanning, and monitoring machine learning and LLM application quality.

Safety · Privacy ·

Connect Claude to Semgrep — scan code for security vulnerabilities, run custom rules, inspect the AST, and pull AppSec Platform findings — with the official Semgrep Model Context Protocol server.

Pentest AI logo

Offensive-security MCP server from pentest-ai that lets Claude list and run wrapped security tools, plan and install missing tools, launch authorized engagements, run web, recon, API, cloud, AD, credential, vulnerability, mobile, wireless, and LLM-red-team assessments, and retrieve findings, attack chains, reports.

A source-backed review workflow for pull requests that include AI-generated code. Treat generated diffs as untrusted implementation work, verify behavior in CI, inspect security-sensitive paths first, and merge only after a reviewer-owned checklist passes.