agent-sec
Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
我該用這個嗎
品質與安全性
B
發現項目(1)
- LOW在 get_security_baseline 中
根據工具定義與協定合規性的自動化分析。
上下文成本
~168Token(工具定義)
~243 B典型回應大小
極小的注意力影響(128k 上下文的 0.13%)
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"agent-sec": {
"url": "https://agentsec.kernora.ai/mcp"
}
}
}遠端端點
https://agentsec.kernora.ai/mcpstreamable-http它能做什麼
工具清單
工具(2)
🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
🟢get_security_baseline
Return Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, supply-chain, destructive ops, data protection). Advisory grounding.
輸入結構描述
{
"type": "object",
"properties": {}
}🟢check_action(action)
Advisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply, so the agent can self-correct. Advisory only — does NOT block. Real-time blocking is Kernora Agent Security's paid Integrity Plane.
輸入結構描述
{
"type": "object",
"properties": {
"action": {
"type": "string",
"description": "the action/command about to run"
}
},
"required": [
"action"
]
}建議的提示詞
retrieve_data
Get details about [item] from agent-sec
預期的工具:
get_security_baselinefetch_info
Fetch [information type] using agent-sec
預期的工具:
get_security_baseline社群
證據
近期觀測
已驗證未記錄版本2 個工具
已驗證未記錄版本2 個工具
已驗證未記錄版本2 個工具