agent-sec
Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
Should I use this
Quality & Safety
Findings (1)
- LOWin get_security_baseline
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"agent-sec": {
"url": "https://agentsec.kernora.ai/mcp"
}
}
}Remote endpoints
https://agentsec.kernora.ai/mcpstreamable-httpWhat it can do
Tool inventory
Tools (2)
🟢get_security_baseline
Return Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, supply-chain, destructive ops, data protection). Advisory grounding.
Input Schema
{
"type": "object",
"properties": {}
}🟢check_action(action)
Advisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply, so the agent can self-correct. Advisory only — does NOT block. Real-time blocking is Kernora Agent Security's paid Integrity Plane.
Input Schema
{
"type": "object",
"properties": {
"action": {
"type": "string",
"description": "the action/command about to run"
}
},
"required": [
"action"
]
}Recommended Prompts
get_security_baselineget_security_baselineCommunity
Evidence