1. Conduid
  2. Security
  3. Find Evil
MCP server · Security

Find Evil

Autonomous, audit-traced incident-response agent for the SANS SIFT Workstation. The agent has no shell — evidence tampering and hallucinated findings are architecturally impossible. Every finding verifies in <10s via its call_id. SANS Find Evil! Hackathon 2026.

34Low

Scored 6 hours ago · breakdown

About Find Evil

Find Evil is an MCP server in the Security category: autonomous, audit-traced incident-response agent for the SANS SIFT Workstation. The agent has no shell — evidence tampering and hallucinated findings are architecturally impossible. Every finding verifies in <10s via its call_id. SANS Find Evil! Hackathon 2026. It has been installed 0 times through Conduid.

Install

Clone
git clone https://github.com/manojmallick/find-evil

This server has no ConduID identity, so agent calls to it are not receipted. Pin the version you install and review the source before granting it credentials.

Ask AI

Ask AI about Find Evil

Powered by Claude · Grounded in docs

I know everything about Find Evil. Ask me about installation, configuration, usage, or troubleshooting.

Security checks

  • ·README presentNot checked yet.
  • ·License declaredNot checked yet.
  • ·Tests presentNot checked yet.
  • ·Dependencies pinnedNot checked yet.
  • ·No dynamic code executionNot checked yet.
  • ·Scoped permissionsNot checked yet.
Questions

About Find Evil

How do I install Find Evil?

Run git clone https://github.com/manojmallick/find-evil, then add the server to your MCP client's configuration. Conduid has recorded 0 installs, so the command is known to work with current clients.

Is Find Evil safe to use with an AI agent?

Its trust score is 34 out of 100 (low). Conduid hasn't run static security checks on this repository yet, so review the source yourself before granting it credentials. It has no ConduID identity yet, so agent calls to it are not receipted.

Is Find Evil still maintained?

Conduid hasn't recorded a commit date for this repository yet. Check the repository directly for recent activity.