diff --git a/README.md b/README.md index 2c4bba62e..569c99b32 100644 --- a/README.md +++ b/README.md @@ -3484,7 +3484,7 @@ Tools for conducting research, surveys, interviews, and data collection. - [sint-ai/sint-protocol](https://github.com/sint-ai/sint-protocol) [![sint-ai/sint-protocol MCP server](https://glama.ai/mcp/servers/sint-ai/sint-protocol/badges/score.svg)](https://glama.ai/mcp/servers/sint-ai/sint-protocol) πŸ“‡ 🏠 🍎 πŸͺŸ 🐧 - Security-first MCP governance proxy (`sint-mcp`) with capability tokens, T0-T3 approval tiers, fail-closed execution, and tamper-evident audit receipts. Includes a separate `sint-scan` CLI for preflight MCP tool-risk audits. - [Skyrxin/sast-mcp-server](https://github.com/Skyrxin/sast-mcp-server) [![Skyrxin/sast-mcp-server MCP server](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server/badges/score.svg)](https://glama.ai/mcp/servers/Skyrxin/sast-mcp-server) 🐍 🏠 🍎 πŸͺŸ 🐧 - SAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scanβ†’patchβ†’re-scanβ†’verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira). - [snyk/studio-mcp](https://github.com/snyk/studio-mcp) πŸŽ–οΈ πŸ“‡ ☁️ 🍎 πŸͺŸ 🐧 - Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs. -- [sp3ak/safenode-mcp-gateway](https://github.com/sp3ak/safenode-mcp-gateway) πŸ“‡ 🏠 ☁️ 🍎 πŸͺŸ 🐧 - Policy proxy for MCP tool calls. Evaluates every call before forwarding; deny means it never reaches the downstream server. Warn forwards with a visible banner, review holds for human approval. Client-side redaction reports what it stripped so server-side rules still fire on data they never receive. Fail-closed by default. `npx safenode-mcp-gateway` +- [sp3ak/safenode-mcp-gateway](https://github.com/sp3ak/safenode-mcp-gateway) [![sp3ak/safenode-mcp-gateway MCP server](https://glama.ai/mcp/servers/sp3ak/safenode-mcp-gateway/badges/score.svg)](https://glama.ai/mcp/servers/sp3ak/safenode-mcp-gateway) πŸ“‡ 🏠 ☁️ 🍎 πŸͺŸ 🐧 - Policy proxy for MCP tool calls. Evaluates every call before forwarding; deny means it never reaches the downstream server. Warn forwards with a visible banner, review holds for human approval. Client-side redaction reports what it stripped so server-side rules still fire on data they never receive. Fail-closed by default. `npx safenode-mcp-gateway` - [StacklokLabs/osv-mcp](https://github.com/StacklokLabs/osv-mcp) 🏎️ ☁️ - Access the OSV (Open Source Vulnerabilities) database for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID. - [Synvoya/codeinspectus](https://github.com/Synvoya/codeinspectus) [![codeinspectus MCP server](https://glama.ai/mcp/servers/Synvoya/codeinspectus/badges/score.svg)](https://glama.ai/mcp/servers/Synvoya/codeinspectus) πŸ“‡ 🏠 🍎 - Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry. - [velvetway/minreestr-mcp](https://github.com/velvetway/minreestr-mcp) [![velvetway/minreestr-mcp MCP server](https://glama.ai/mcp/servers/velvetway/minreestr-mcp/badges/score.svg)](https://glama.ai/mcp/servers/velvetway/minreestr-mcp) 🐍 ☁️ 🍎 πŸͺŸ 🐧 - Search ΠΊΠ°Ρ‚Π°Π»ΠΎΠ³ΠΏΠΎ.Ρ€Ρ„ (Russian software registry, 26k+ products) for import-substitution and ЀБВЭК/Π€Π‘Π‘-certified software discovery. Three tools: full-text search, manufacturer listing, featured products. Ideal for Russian security/compliance teams (152-Π€Π—, 187-Π€Π—) using Claude.