agent-sec

Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.

我该使用它吗

质量与安全性

B
描述质量
85%
模式完整度
65%
命名质量
100%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

发现(1)

  • LOWTool 'get_security_baseline' description lacks action verb在 get_security_baseline 中

基于对工具定义和协议合规性的自动分析。

上下文开销

~168token 数(工具定义)
~243 B典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.13%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "agent-sec": {
      "url": "https://agentsec.kernora.ai/mcp"
    }
  }
}

远程端点

https://agentsec.kernora.ai/mcpstreamable-http

它能做什么

工具清单

工具(2)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢get_security_baseline

Return Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, supply-chain, destructive ops, data protection). Advisory grounding.

输入模式

{
  "type": "object",
  "properties": {}
}
🟢check_action(action)

Advisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply, so the agent can self-correct. Advisory only — does NOT block. Real-time blocking is Kernora Agent Security's paid Integrity Plane.

输入模式

{
  "type": "object",
  "properties": {
    "action": {
      "type": "string",
      "description": "the action/command about to run"
    }
  },
  "required": [
    "action"
  ]
}

推荐提示词

retrieve_data
Get details about [item] from agent-sec
预期工具: get_security_baseline
fetch_info
Fetch [information type] using agent-sec
预期工具: get_security_baseline

社区

评价此服务器

证据

最近观测

已验证未记录版本2 个工具
已验证未记录版本2 个工具