Honeybadger

devops-infra MCP Server

Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.

Verified
devops-infradevops-infra
6 views2 stars0 forksMIT

Why This Matters

Discovered via github-topic:mcp and last synced 2mo ago.

Verified
Source
github-topic:mcp
Stars
2
Last synced
2mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
33
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (33)

Secrets

gitleaks v8

meta

Required fields and format validation

minimal

family

FamClaw

Built-in pipeline

No

CRITICAL

supplychain

Webhook/requestbin exfiltration endpoints

Type

Guide

Homoglyphs

skillsafety

Yara

yes (skills mode)

Hook

[docs/integrations/codex-cli.md](docs/integrations/codex-cli.md)

MCP

JSON-RPC stdio

bash

supplychain

attestation

Cosign signatures and checksum files present (strict+)

CVEs

osv.dev

capability

Declared `requires.*` vs actual code: network/filesystem/bins/env reads (family+)

Check

Scanner

Typosquat

supplychain

HoneyBadger

Cisco MCP Scanner

OpenClaw

Skill

family

secrets, cve, supplychain, meta, capability, skillsafety

skillsafety

Unexpected script blocks in primary-language skills (family+)

Go

Python

yes

no

PicoClaw

Skill

mcptool

Tool definitions changed since the approved baseline (family+)

no

## Integrations

JSONL

no

NanoBot

Skill

paranoid

family + attestation + allowlist

CLI

[docs/EXAMPLES.md](docs/EXAMPLES.md)

Level

Scanners

off

None

strict

family + attestation