Aguara

data-ai MCP Server

The open source security engine for AI agent and supply-chain trust.

VerifiedReviewed
data-aidata-ai
4 views83 stars15 forksApache-2.0

Why This Matters

Discovered via github-seeds:mcp-hot and last synced 3mo ago.

VerifiedReviewed
Source
github-seeds:mcp-hot
Stars
83
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
50
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (50)

Format

Flag

Category

Rules

upload-sarif

`true`

13

Unpinned npx/uvx servers, hardcoded secrets, Docker cap-add, host networking, pip without hashes

Input

Default

22

API keys (OpenAI, AWS, GCP, Stripe, ...), private keys, DB strings, HMAC secrets

format

`sarif`

Partial

No

Layer

Engine

path

`./`

21

Download-and-execute, reverse shells, sandbox escape, symlink attacks, privilege escalation

severity

`info`

16

shell=True, eval, subprocess, child_process, PowerShell

Feature

Aguara

fail-on

_(none)_

version

_(latest)_

10

RTL override, bidi, homoglyphs, zero-width sequences, normalization bypass

Directive

Effect

11

Credential file reads, .pth executable code, bulk env collection, K8s secrets access, systemd persistence, archive+POST exfil, Session-Network endpoints

NuGet

`packages.lock.json`, `*.csproj`/`*.fsproj`/`*.vbproj`

RubyGems

`Gemfile.lock`

PyPI

`site-packages`, `.pth`, pip/uv/npx caches

Analyzer

Engine

No

Partial

Ecosystem

Evidence read

Maven

`pom.xml`, Gradle lockfiles

Surface

Examples

Go

`go.sum`, `go.mod`

Yes

Yes

Dependencies

npm, pnpm, PyPI, Go, Rust, PHP, Ruby, Java, .NET

Packagist

`composer.lock`

24

Download-and-execute, reverse shells, sandbox escape, symlink attacks, privilege escalation, OIDC token vars, runner-pivot memory, Claude Code persistence path

npm

`node_modules`, pnpm `.pnpm` store, `pnpm-lock.yaml`, `package-lock.json`, `yarn.lock` (classic v1 + Berry v2+), `bun.lock`

Behavior

Detector

Finding

Severity

HIGH

`defaultMode: "bypassPermissions"` shipped in the repo

MEDIUM

`apiKeyHelper` / `awsAuthRefresh` pointing at a repo-relative script

Terminal

`--format terminal` (default): color, severity dashboard, top-files chart

LOW

`defaultMode: "acceptEdits"` / `"auto"` shipped in the repo

INFO

`onlyBuiltDependencies` and friends

CRITICAL

a hook command piping a network fetch into a shell (`curl \

JSON

`--format json`: machine processing, API integration

SARIF

`--format sarif`: GitHub Code Scanning, IDE / SAST dashboards

Markdown

`--format markdown`: GitHub Actions job summaries, PR comments

PkgMeta

`package.json` JSON

JSRisk

JavaScript single-pass

PyRisk

Python install-hook scanner

RSBuild

Cargo build-script scanner

NLP

Goldmark AST + JSON/YAML

Rug-Pull

SHA256 change tracking