Agent Sec is answering right now. Last checked 10 min ago. It exposes 2 tools. Last commit 1 Aug 2026.
Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
We read the source, 20 h ago · tools taken from the live server · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
out = subprocess.run(
export const FAVICON_PNG_B64 = "iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAABmJLR0QA/wD/AP+gvaeTAAADO0lEQVRYhcXXX4hUZRjH8e/7njPOljtTEIWJ5EZT2kUY3UiCWxS5pWJQ5o1asF1tttNVC93EgpBB7oUt1M1u2B9ZhG0N3MpiiZaCFLuQjUjWjIUsbFlsnXVt/p3z62Kc4/E005wR3Xlh4Jnn/Pk87/u8Z/4YQuOjd3SXLRezMmaLfO5H…
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 10 min ago.
claude mcp add agent-sec --transport http https://agentsec.kernora.ai/mcp
{
"mcpServers": {
"agent-sec": {
"url": "https://agentsec.kernora.ai/mcp"
}
}
}
[mcp_servers.agent-sec]
url = "https://agentsec.kernora.ai/mcp"
{
"mcpServers": {
"agent-sec": {
"url": "https://agentsec.kernora.ai/mcp"
}
}
}
{
"mcpServers": {
"agent-sec": {
"url": "https://agentsec.kernora.ai/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
check_action
get_security_baseline
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://agentsec.kernora.ai/mcp | streamable-http | answering | 326 ms | 10 min ago |
Evidence-traced codebase understanding and security scanning for AI agents over MCP.
OS keychain secrets for AI coding agents, over MCP.
MCP security trust-check for agents before installing MCPs, Skills or tools.
Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.
Inspect an MCP server for common security risks before you install it. Offline, zero telemetry.
Real-time semantic security for AI coding agents and MCP tools
BridgeGuard MCP Server - Cross-chain bridge security audit tools for AI coding agents. Scan bri...
Pre-install security scanner for AI agent skills (local stdio MCP). Offline static scan; no upload.
Answers built from our own checks of this server.