agent-sec by kernora.ai

MCP server · indexed, not reviewed

Hostedvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.

What the official MCP registry says

Facts

MCP registry
ai.kernora/agent-sec · 0.1.0
Endpoint
https://agentsec.kernora.ai/mcp
GitHub stars
1
Registry entry
updated 31 Jul 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under kernora.ai, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 2 · about 252 tokens of context · checked 1 hour ago

ToolWhat it doesHint
get_security_baselineReturn Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, supply-chain, destructive ops, data protection). Advisory grounding.
check_actionAdvisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply, so the agent can self-correct. Advisory only — does NOT block. Real-time…

What https://agentsec.kernora.ai/mcp answered to tools/list, asked without credentials. answered without the initialize handshake. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 2 warnings · 1 note

  • warnTC16check_actionno readOnlyHint or destructiveHint
  • warnTC16get_security_baselineno readOnlyHint or destructiveHint
  • noteTC24server2 of 2 tools have no outputSchema

The checks from /check and anchor check, run each day on the list above: about 252 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.