security MCP Server
Cross-repo code knowledge graph for Java/Kotlin/JS/TS — MCP server, taint analysis, call graph, OWASP reports. 95% fewer tokens than source-reading.
Discovered via github-topic:mcp and last synced 3mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
Start the write-serialization server for team/server deployments
id, name, root_path
Description
Class → Class
Match RestCall URL patterns against Endpoints across all indexed repos
Key fields
endpoint_fqn, saturation_rps, ceiling_concurrency, risk_level
Class → Class
Commercial
Parse a repository and write its graph into KuzuDB
Default
http_method, path, path_regex
File → Class
<5ms
Start the MCP server with SSE transport (for CI runners and remote clients)
Description
endpoint_fqn, p50_ms, p99_ms, rps, source
Repo → Repo (cross-service dependency)
Orihime
path, language, blob_hash, branch_name
Method → Method; carries callee_name, caller_arg_pos, callee_param_pos
Class → EntityRelation
fqn, annotations, is_interface
Method → Endpoint (resolved cross-service call)
Method → PerfSample
MIT
Description
Description
fqn, line_start, annotations, is_entry_point, complexity_hint
Method → RestCall (not yet resolved)
Time
Description
Start the local web UI on port 7700
`~/.orihime/orihime.db`
http_method, url_pattern
Start the MCP server on stdio (for Claude Code, Claude Desktop, any MCP client)
_(unset)_
source_class, target_class, fetch_type, relation_type
Repo → Endpoint
Class → Method
Cold index
partial
Write the Orihime MCP server entry to `~/.claude/settings.json`
Copy bundled skills to the target AI assistant's config dir (`--agent claude\
真实性验证技能。分析用户提供的信息、消息、图片或内容,判断其真实性和可信度,识别虚假信息、AI生成内容或伪造内容。
Container escape is a critical attack technique where an adversary breaks out of container isolation to access the host system or other containers. Detection involves monitoring for escape indicators
Pod Security Standards (PSS) define three levels of security policies -- Privileged, Baseline, and Restricted -- enforced by the Pod Security Admission (PSA) controller built into Kubernetes 1.25+. PS
Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement. Covers TracingPolicy CRD authoring with kprobe/tracepoint hooks, in-kernel filtering via matchArgs/matchBinaries selectors, JSON event export, and integration with SIEM pipelines. Use when building kernel-level runtime security observability for Linux hosts or Kubernetes clusters.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
Learn how to use the absolute-audit Claude skill. Complete guide with installation instructions and examples.
Learn how to use the token-scam-analysis Claude skill. Complete guide with installation instructions and examples.
Learn how to use the absolute-upgrade Claude skill. Complete guide with installation instructions and examples.