- Conduid
- Marketplace
- #sarif
MCP servers tagged sarif
19 live MCP servers tagged "sarif", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with sarif.
safedep/vet
Scan MCP server source code for patterns that break under the final 2026-07-28 Model Context Protocol specification.
PhpCodeArcheology/PhpCodeArcheology
PHP static analysis MCP server for architecture and maintainability. 11 tools exposing 60+ code quality metrics, problem detection, refactoring priorities, dependency graphs, git…
Agents Shipgate
The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI +…
Fence
Local-first security scanner, MCP protocol inspector, dynamic fuzzer, Docker sandbox, and report generator for Model Context Protocol servers.
Docguard
The enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
Ctxlint
Lint your AI agent context files, MCP server configs, and session data against your actual codebase
Decoy Scan
Security scanner for MCP server configurations. Finds risky tools, vulnerable packages, and suspicious servers across Claude Desktop, Cursor, VS Code, and more.
Meritmcp
The CI quality gate for MCP servers — functional tests + official conformance + OWASP-MCP-Top-10 security in one command, with SARIF, a 0-100 safety score, and a README badge.
Agent MCP Guard
Open-source CLI scanner for risky MCP server and AI agent tool configuration.
Mcpeek
Source-code-level security scanner for MCP (Model Context Protocol) server implementations
Security Lab
MCP Security Lab — MCP Verifier: evidence-first, deterministic security checks for local and remote Model Context Protocol servers, with optional Claude-powered remediation.
Sealpin
A supply-chain and prompt-injection scanner for MCP (Model Context Protocol) servers.
Mcpie
Security scanner for MCP servers. Think `npm audit` for the Model Context Protocol.
Mcpward
Black-box security & contract testing for MCP servers — rug-pull, tool-poisoning, schema-drift & protocol checks for CI (JUnit + SARIF).
VibeGuard
Free security & privacy scanner for AI-coded apps. 766 rules, 84 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your A…
Nsauditor AI
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration.…
Patient Zero
Supply-chain attack scanner for the agent era. Triage in 30s with `npx patient-zero`, block malicious installs before postinstall runs, or drop into CI as a GitHub Action. Covers…
Rust Doctor
Scan, score, and fix your Rust code — clippy + cargo-audit + cargo-deny + 19 custom rules unified into one 0–100 health score. CLI · MCP server · GitHub Action.
gavelcode/gavel
quality gate for Bazel monorepos: runs lint, coverage and architecture checks off the build graph and returns a pass/fail verdict an agent can request before finishing a change.