security MCP Server
MCP server for automated macOS malware analysis via SSH. 43 tools, 5 prompts, 5 resources, composite playbooks (triage, behavioral, app-bundle audit, IR scan).
Discovered via github-topic:model-context-protocol and last synced 3mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
Hashes + Mach-O + security strings + signing + entitlements + quarantine + Gatekeeper
Run any bash command (optional sudo)
Entitlements plist
lsof + vmmap + ps for a process
SW version, hardware, SIP, boot-args
`otool -tV` disassembly
Info.plist, signing, entitlements, helpers, dylibs, hashes of every bundled binary
Copy file from macOS → Kali
key
Persistence baseline → tcpdump + fs_usage → execute → diff persistence → IOCs
com.apple.quarantine xattr
Verify SSH + show OS version. **Always call first.**
Certificate, team ID, notarization
Read remote file contents
Copy file from Kali → macOS
`ps aux` with optional filter
`execute_with_monitoring`
Stop capture + summarize + optional download
Parse any plist in human-readable form
TCC DB: app permission grants
`frida_run_script`
`execute_bash`
`check_persistence` (before/after)
`inspect_process`
Persistence + kexts + TCC + SIP + live network + suspicious procs + filters
Mach-O headers, load commands, symbols
`spctl` assessment
File system activity via `fs_usage`
Strings with optional regex filter
Description
Login items via osascript
kexts + System Extensions
Spawn + instrument from launch
Full .app bundle analysis
`get_file_hash`
`list_launch_agents` + `check_persistence`
Linked dylibs (`otool -L`)
DTrace one-liner or script
Start packet capture (background)
LaunchAgents + LaunchDaemons
SIP + authenticated root status
List Frida-injectable processes
LLDB commands on binary/process
`extract_strings`
`lldb_run_commands`
Live connections via `lsof -i`
**Comprehensive**: all persistence locations
Network Extension providers
.pkg contents + scripts + signature
`analyze_macho` + `extract_strings`
`gcore` memory dump
`take_screenshot`
`analyze_code_signing` + `analyze_macho`
真实性验证技能。分析用户提供的信息、消息、图片或内容,判断其真实性和可信度,识别虚假信息、AI生成内容或伪造内容。
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
Learn how to use the absolute-audit Claude skill. Complete guide with installation instructions and examples.
Learn how to use the token-scam-analysis Claude skill. Complete guide with installation instructions and examples.
Learn how to use the absolute-upgrade Claude skill. Complete guide with installation instructions and examples.