mcpbeat Sign in

Agent Sec MCP Server

answering

Agent Sec is answering right now. Last checked 10 min ago. It exposes 2 tools. Last commit 1 Aug 2026.

Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.

Uptime history 47 days of history · worst day 96%
47 days agonow
100.0%
Uptime 24h
91 of 91 checks
2
Tools
read from the server
190 ms
Response time
average over 24h
1
Stars
last commit 1 Aug 2026

What the code does

We read the source, 20 h ago · tools taken from the live server · rules 3dff92dd89df

Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

    out = subprocess.run(
Long encoded blob in source assets.js:8
export const FAVICON_PNG_B64 = "iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAABmJLR0QA/wD/AP+gvaeTAAADO0lEQVRYhcXXX4hUZRjH8e/7njPOljtTEIWJ5EZT2kUY3UiCWxS5pWJQ5o1asF1tttNVC93EgpBB7oUt1M1u2B9ZhG0N3MpiiZaCFLuQjUjWjIUsbFlsnXVt/p3z62Kc4/E005wR3Xlh4Jnn/Pk87/u8Z/4YQuOjd3SXLRezMmaLfO5H…

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

This code can reach further than it looks

We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.

run in your terminal
claude mcp add agent-sec --transport http https://agentsec.kernora.ai/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "agent-sec": {
      "url": "https://agentsec.kernora.ai/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.agent-sec]
url = "https://agentsec.kernora.ai/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "agent-sec": {
      "url": "https://agentsec.kernora.ai/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "agent-sec": {
      "url": "https://agentsec.kernora.ai/mcp"
    }
  }
}

Available tools 2

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

action
check_action
Advisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply, so the agent can self-correct. Advisory only — does NOT block. Real-time blocking is Kernora Agent Security's paid Integrity Plane.
security
get_security_baseline
Return Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, supply-chain, destructive ops, data protection). Advisory grounding.

Endpoints

URLTransportStateLatencyChecked
https://agentsec.kernora.ai/mcp streamable-http answering 326 ms 10 min ago

Alternatives to Agent Sec

same job, measured the same way
Rune
by thecolourfoundation

Evidence-traced codebase understanding and security scanning for AI agents over MCP.

24 installs/wk local only
q-ring
by i4ctime

OS keychain secrets for AI coding agents, over MCP.

712 installs/wk local only
AgentSecurityLens MCP Security Trust Check
by professor2k8

MCP security trust-check for agents before installing MCPs, Skills or tools.

74 installs/wk local only
pkgxray
by adamsjack711-ux

Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.

92 installs/wk local only
MCP Customs
by mcpcustoms

Inspect an MCP server for common security risks before you install it. Offline, zero telemetry.

30 installs/wk local only
Defenter Proxy
by defenter-ai

Real-time semantic security for AI coding agents and MCP tools

122 installs/wk local only
Bridgeguard MCP
by kota1026

BridgeGuard MCP Server - Cross-chain bridge security audit tools for AI coding agents. Scan bri...

54 installs/wk local only
Yotta Verify MCP
by yottameta

Pre-install security scanner for AI agent skills (local stdio MCP). Offline static scan; no upload.

567 installs/wk local only

Agent Sec — questions

Answers built from our own checks of this server.

What can Agent Sec do?
It exposes 2 tools, read directly from the server on our last check. Among them: check_action, get_security_baseline. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Agent Sec working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 190 ms. The bar chart above shows every period we have measured.
How do I connect Agent Sec?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Agent Sec need an API key?
No. Agent Sec completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 2 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Agent Sec?
It answers our handshake in 190 ms on average, which is faster than 68% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.
Is Agent Sec open source?
Yes — it is published under the Apache-2.0 licence, written in JavaScript and 1 stars on GitHub. The source link is on this page, so you can read exactly what it does with your data before you connect it.