From 9fb0de85e26ecc8ebe699106b8b228f26aa9dff2 Mon Sep 17 00:00:00 2001 From: "Shuang.W" Date: Tue, 18 Aug 2026 04:26:00 +0300 Subject: [PATCH 1/4] Add swnotmetal/Project-Koma to Security --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 72a96c8ff..b68d74479 100644 --- a/README.md +++ b/README.md @@ -3230,6 +3230,7 @@ Tools for conducting research, surveys, interviews, and data collection. - [Skyrxin/sast-mcp-server](https://github.com/Skyrxin/sast-mcp-server) [![Skyrxin/sast-mcp-server MCP server](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server/badges/score.svg)](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server) 🐍 🏠 🍎 πŸͺŸ 🐧 - SAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scanβ†’patchβ†’re-scanβ†’verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira). - [snyk/studio-mcp](https://github.com/snyk/studio-mcp) πŸŽ–οΈ πŸ“‡ ☁️ 🍎 πŸͺŸ 🐧 - Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs. - [StacklokLabs/osv-mcp](https://github.com/StacklokLabs/osv-mcp) 🏎️ ☁️ - Access the OSV (Open Source Vulnerabilities) database for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID. +- [swnotmetal/Project-Koma](https://github.com/swnotmetal/Project-Koma) [![swnotmetal/Project-Koma MCP server](https://glama.ai/mcp/servers/swnotmetal/Project-Koma/badges/score.svg)](https://glama.ai/mcp/servers/swnotmetal/Project-Koma) πŸŽ–οΈ 🟒 🏠 🍎 πŸͺŸ 🐧 - Lightweight AI security firewall and middleware for Node.js & TypeScript that protects agents from prompt injection (`koma-gate-mcp`), audio hallucinations, and RAG data scraping (`koma-core-mcp`). Includes a 1,769-attack benchmark verification and runs with zero dependencies. - [Synvoya/codeinspectus](https://github.com/Synvoya/codeinspectus) [![codeinspectus MCP server](https://glama.ai/mcp/servers/Synvoya/codeinspectus/badges/score.svg)](https://glama.ai/mcp/servers/Synvoya/codeinspectus) πŸ“‡ 🏠 🍎 - Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry. - [velvetway/minreestr-mcp](https://github.com/velvetway/minreestr-mcp) [![velvetway/minreestr-mcp MCP server](https://glama.ai/mcp/servers/velvetway/minreestr-mcp/badges/score.svg)](https://glama.ai/mcp/servers/velvetway/minreestr-mcp) 🐍 ☁️ 🍎 πŸͺŸ 🐧 - Search ΠΊΠ°Ρ‚Π°Π»ΠΎΠ³ΠΏΠΎ.Ρ€Ρ„ (Russian software registry, 26k+ products) for import-substitution and ЀБВЭК/Π€Π‘Π‘-certified software discovery. Three tools: full-text search, manufacturer listing, featured products. Ideal for Russian security/compliance teams (152-Π€Π—, 187-Π€Π—) using Claude. - [vespo92/OPNSenseMCP](https://github.com/vespo92/OPNSenseMCP) πŸ“‡ 🏠 - MCP Server for managing & interacting with Open Source NGFW OPNSense via Natural Language From ed1f59dab11698d21d61e07f95e2880cc37e62e5 Mon Sep 17 00:00:00 2001 From: Shuang Wu <66452432+swnotmetal@users.noreply.github.com> Date: Tue, 18 Aug 2026 10:57:45 +0300 Subject: [PATCH 2/4] Fix Project-Koma entry in README Updated Project-Koma entry with new badge and description. --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index b68d74479..b1c9e99f2 100644 --- a/README.md +++ b/README.md @@ -3230,7 +3230,7 @@ Tools for conducting research, surveys, interviews, and data collection. - [Skyrxin/sast-mcp-server](https://github.com/Skyrxin/sast-mcp-server) [![Skyrxin/sast-mcp-server MCP server](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server/badges/score.svg)](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server) 🐍 🏠 🍎 πŸͺŸ 🐧 - SAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scanβ†’patchβ†’re-scanβ†’verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira). - [snyk/studio-mcp](https://github.com/snyk/studio-mcp) πŸŽ–οΈ πŸ“‡ ☁️ 🍎 πŸͺŸ 🐧 - Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs. - [StacklokLabs/osv-mcp](https://github.com/StacklokLabs/osv-mcp) 🏎️ ☁️ - Access the OSV (Open Source Vulnerabilities) database for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID. -- [swnotmetal/Project-Koma](https://github.com/swnotmetal/Project-Koma) [![swnotmetal/Project-Koma MCP server](https://glama.ai/mcp/servers/swnotmetal/Project-Koma/badges/score.svg)](https://glama.ai/mcp/servers/swnotmetal/Project-Koma) πŸŽ–οΈ 🟒 🏠 🍎 πŸͺŸ 🐧 - Lightweight AI security firewall and middleware for Node.js & TypeScript that protects agents from prompt injection (`koma-gate-mcp`), audio hallucinations, and RAG data scraping (`koma-core-mcp`). Includes a 1,769-attack benchmark verification and runs with zero dependencies. +- [swnotmetal/Project-Koma](https://github.com/swnotmetal/Project-Koma) [![swnotmetal/Project-Koma MCP server](https://glama.ai/mcp/servers/swnotmetal/Project-Koma/badges/score.svg)](https://glama.ai/mcp/servers/swnotmetal/Project-Koma) πŸŽ–οΈ πŸ“‡ 🏠 🍎 πŸͺŸ 🐧 - Lightweight AI security firewall and middleware for Node.js & TypeScript that protects agents from prompt injection (`koma-gate-mcp`), audio hallucinations, and RAG data scraping (`koma-core-mcp`). Includes a 1,769-attack benchmark verification and runs with zero dependencies. - [Synvoya/codeinspectus](https://github.com/Synvoya/codeinspectus) [![codeinspectus MCP server](https://glama.ai/mcp/servers/Synvoya/codeinspectus/badges/score.svg)](https://glama.ai/mcp/servers/Synvoya/codeinspectus) πŸ“‡ 🏠 🍎 - Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry. - [velvetway/minreestr-mcp](https://github.com/velvetway/minreestr-mcp) [![velvetway/minreestr-mcp MCP server](https://glama.ai/mcp/servers/velvetway/minreestr-mcp/badges/score.svg)](https://glama.ai/mcp/servers/velvetway/minreestr-mcp) 🐍 ☁️ 🍎 πŸͺŸ 🐧 - Search ΠΊΠ°Ρ‚Π°Π»ΠΎΠ³ΠΏΠΎ.Ρ€Ρ„ (Russian software registry, 26k+ products) for import-substitution and ЀБВЭК/Π€Π‘Π‘-certified software discovery. Three tools: full-text search, manufacturer listing, featured products. Ideal for Russian security/compliance teams (152-Π€Π—, 187-Π€Π—) using Claude. - [vespo92/OPNSenseMCP](https://github.com/vespo92/OPNSenseMCP) πŸ“‡ 🏠 - MCP Server for managing & interacting with Open Source NGFW OPNSense via Natural Language From 744d70e82cdd6ea9e5e9e696c53047244fb64acd Mon Sep 17 00:00:00 2001 From: Shuang Wu <66452432+swnotmetal@users.noreply.github.com> Date: Wed, 19 Aug 2026 02:49:49 +0300 Subject: [PATCH 3/4] Revise Project-Koma entry in README Updated Project-Koma description to clarify its functionalities and removed duplicate entry. --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index b1c9e99f2..d150c5bd3 100644 --- a/README.md +++ b/README.md @@ -3230,7 +3230,7 @@ Tools for conducting research, surveys, interviews, and data collection. - [Skyrxin/sast-mcp-server](https://github.com/Skyrxin/sast-mcp-server) [![Skyrxin/sast-mcp-server MCP server](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server/badges/score.svg)](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server) 🐍 🏠 🍎 πŸͺŸ 🐧 - SAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scanβ†’patchβ†’re-scanβ†’verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira). - [snyk/studio-mcp](https://github.com/snyk/studio-mcp) πŸŽ–οΈ πŸ“‡ ☁️ 🍎 πŸͺŸ 🐧 - Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs. - [StacklokLabs/osv-mcp](https://github.com/StacklokLabs/osv-mcp) 🏎️ ☁️ - Access the OSV (Open Source Vulnerabilities) database for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID. -- [swnotmetal/Project-Koma](https://github.com/swnotmetal/Project-Koma) [![swnotmetal/Project-Koma MCP server](https://glama.ai/mcp/servers/swnotmetal/Project-Koma/badges/score.svg)](https://glama.ai/mcp/servers/swnotmetal/Project-Koma) πŸŽ–οΈ πŸ“‡ 🏠 🍎 πŸͺŸ 🐧 - Lightweight AI security firewall and middleware for Node.js & TypeScript that protects agents from prompt injection (`koma-gate-mcp`), audio hallucinations, and RAG data scraping (`koma-core-mcp`). Includes a 1,769-attack benchmark verification and runs with zero dependencies. +- [swnotmetal/Project-Koma](https://github.com/swnotmetal/Project-Koma) [![MCP server](https://glama.ai/mcp/servers/swnotmetal/Project-Koma/badges/score.svg)](https://glama.ai/mcp/servers/swnotmetal/Project-Koma) πŸŽ–οΈ πŸ“‡ 🏠 🍎 πŸͺŸ 🐧 - Lightweight AI security middleware for Node.js & TypeScript. `koma-gate-mcp` classifies prompt injection, jailbreaks, and out-of-scope input before agents act on it β€” 4 guard presets (general/code/support/reference), batch classification, zero dependencies, MIT. - [Synvoya/codeinspectus](https://github.com/Synvoya/codeinspectus) [![codeinspectus MCP server](https://glama.ai/mcp/servers/Synvoya/codeinspectus/badges/score.svg)](https://glama.ai/mcp/servers/Synvoya/codeinspectus) πŸ“‡ 🏠 🍎 - Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry. - [velvetway/minreestr-mcp](https://github.com/velvetway/minreestr-mcp) [![velvetway/minreestr-mcp MCP server](https://glama.ai/mcp/servers/velvetway/minreestr-mcp/badges/score.svg)](https://glama.ai/mcp/servers/velvetway/minreestr-mcp) 🐍 ☁️ 🍎 πŸͺŸ 🐧 - Search ΠΊΠ°Ρ‚Π°Π»ΠΎΠ³ΠΏΠΎ.Ρ€Ρ„ (Russian software registry, 26k+ products) for import-substitution and ЀБВЭК/Π€Π‘Π‘-certified software discovery. Three tools: full-text search, manufacturer listing, featured products. Ideal for Russian security/compliance teams (152-Π€Π—, 187-Π€Π—) using Claude. - [vespo92/OPNSenseMCP](https://github.com/vespo92/OPNSenseMCP) πŸ“‡ 🏠 - MCP Server for managing & interacting with Open Source NGFW OPNSense via Natural Language From 2a48712ca67bbe11e5fce5c896492cee344abcc7 Mon Sep 17 00:00:00 2001 From: Shuang Wu <66452432+swnotmetal@users.noreply.github.com> Date: Mon, 7 Sep 2026 12:22:30 +0300 Subject: [PATCH 4/4] Revise Project-Koma entry in README Updated the Project-Koma entry to reflect the new repository structure and added a description for the MCP server functionality. --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index d150c5bd3..65fadf7f6 100644 --- a/README.md +++ b/README.md @@ -3230,7 +3230,7 @@ Tools for conducting research, surveys, interviews, and data collection. - [Skyrxin/sast-mcp-server](https://github.com/Skyrxin/sast-mcp-server) [![Skyrxin/sast-mcp-server MCP server](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server/badges/score.svg)](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server) 🐍 🏠 🍎 πŸͺŸ 🐧 - SAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scanβ†’patchβ†’re-scanβ†’verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira). - [snyk/studio-mcp](https://github.com/snyk/studio-mcp) πŸŽ–οΈ πŸ“‡ ☁️ 🍎 πŸͺŸ 🐧 - Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs. - [StacklokLabs/osv-mcp](https://github.com/StacklokLabs/osv-mcp) 🏎️ ☁️ - Access the OSV (Open Source Vulnerabilities) database for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID. -- [swnotmetal/Project-Koma](https://github.com/swnotmetal/Project-Koma) [![MCP server](https://glama.ai/mcp/servers/swnotmetal/Project-Koma/badges/score.svg)](https://glama.ai/mcp/servers/swnotmetal/Project-Koma) πŸŽ–οΈ πŸ“‡ 🏠 🍎 πŸͺŸ 🐧 - Lightweight AI security middleware for Node.js & TypeScript. `koma-gate-mcp` classifies prompt injection, jailbreaks, and out-of-scope input before agents act on it β€” 4 guard presets (general/code/support/reference), batch classification, zero dependencies, MIT. +- [swnotmetal/Project-Koma](https://github.com/swnotmetal/Project-Koma/tree/main/packages/koma-gate-mcp) [![MCP server](https://glama.ai/mcp/servers/swnotmetal/Project-Koma/badges/score.svg)](https://glama.ai/mcp/servers/swnotmetal/Project-Koma) πŸŽ–οΈ πŸ“‡ 🏠 🍎 πŸͺŸ 🐧 - MCP server exposing Koma Gate's LLM-based classification of prompt injection and out-of-scope input through the `classify_input` tool. - [Synvoya/codeinspectus](https://github.com/Synvoya/codeinspectus) [![codeinspectus MCP server](https://glama.ai/mcp/servers/Synvoya/codeinspectus/badges/score.svg)](https://glama.ai/mcp/servers/Synvoya/codeinspectus) πŸ“‡ 🏠 🍎 - Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry. - [velvetway/minreestr-mcp](https://github.com/velvetway/minreestr-mcp) [![velvetway/minreestr-mcp MCP server](https://glama.ai/mcp/servers/velvetway/minreestr-mcp/badges/score.svg)](https://glama.ai/mcp/servers/velvetway/minreestr-mcp) 🐍 ☁️ 🍎 πŸͺŸ 🐧 - Search ΠΊΠ°Ρ‚Π°Π»ΠΎΠ³ΠΏΠΎ.Ρ€Ρ„ (Russian software registry, 26k+ products) for import-substitution and ЀБВЭК/Π€Π‘Π‘-certified software discovery. Three tools: full-text search, manufacturer listing, featured products. Ideal for Russian security/compliance teams (152-Π€Π—, 187-Π€Π—) using Claude. - [vespo92/OPNSenseMCP](https://github.com/vespo92/OPNSenseMCP) πŸ“‡ 🏠 - MCP Server for managing & interacting with Open Source NGFW OPNSense via Natural Language