Sandboxed security scanning for AI skills and MCP servers — precise findings, heatmap posture, fail-closed agent guard. Multi-scanner security platform for AI skills and MCP servers, scan what the age
Discover and scan AI skills and MCP servers, then review the findings in one dashboard.
Tripwire helps technical teams assess AI skills and MCP servers before they rely on them. It discovers targets, runs the enabled scanner adapters in an isolated scan environment, stores the findings, and brings them together in one dashboard.
Tripwire is currently an early-adopter tool with a hands-on setup and management component. It is a good fit if you are comfortable using a terminal and shell, managing local tooling and environment variables, editing .env and other configuration files carefully, creating cloud/vendor accounts, and using command output to resolve a setup issue.
You are... You want to... ------ An AI-tooling developer or team Assess skills and MCP servers before using or sharing them A platform, operations, or security practitioner Run and maintain scans for a team A contributor Extend scanner support, the CLI, or the dashboard
You do not need to be a security specialist, but you should be ready to interpret findings and decide when to escalate them. The optional Mock preview is available for evaluating the dashboard without accounts; real scans require the setup below.
Follow this order before running a scan or opening the Live dashboard. The Quickstart supplies the commands; the linked guides explain each decision before you make it.
1. Check the required tools and install the CLI. 2. Create the accounts you need: Supabase, Modal, then add Snyk, Tessl, and Cisco credentials with the environment-variable procurement guide. 3. Create .env only after you have th
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/neomatrix369--tripwire.html)
Universal MCP server: connect any OpenAPI/Swagger, GraphQL, gRPC or SOAP API to AI agents. Security-first, local, token-efficient. Any API. One server.
eltociear/mcp-auditScan MCP servers & AI-agent skills for malicious patterns (prompt injection in tool descriptions, credential exfil, download-and-execute). 17 patterns / 60 signatures, zero-dep. Measured over 196 publ
12122J/mcpvetMCP security scanner — vet a Model Context Protocol server before you add it to Claude Code, Cursor, or Windsurf. Grades it A–F, catching credential theft, tool-poisoning, and install-script payloads
sgateway/s-gwLocal credential control for AI coding agents.
100yenadmin/boardstateYour dashboard is data. Any AI can build it; any human can edit it. A protocol + runtime for agent-composable dashboards — layout-as-data, one guarded control plane, sandboxed agent-authored widgets,
fengyincheng/ShellBridgeGive ChatGPT fast, safe, and auditable visibility into your VPS through MCP.
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.