{
  "data": {
    "tool": {
      "category": "",
      "endpoint": "https://agentsec.kernora.ai/mcp",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kernora-agent-sec.json",
      "kind": "mcp",
      "listed": "indexed",
      "liveUrl": "https://www.anchorterminal.com/api/v1/live/kernora-agent-sec.json",
      "markdownUrl": "https://www.anchorterminal.com/tools/kernora-agent-sec.md",
      "mcpTools": {
        "check": {
          "checker": "anchor-check/1.0",
          "totalTokens": 252,
          "counts": {
            "error": 0,
            "note": 1,
            "warn": 2
          },
          "findings": [
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "check_action",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"check\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC16",
              "severity": "warn",
              "tool": "get_security_baseline",
              "message": "no readOnlyHint or destructiveHint",
              "fix": "Its name starts with \"get\"; if it only reads, set readOnlyHint: true so harnesses can run it without asking."
            },
            {
              "rule": "TC24",
              "severity": "note",
              "message": "2 of 2 tools have no outputSchema",
              "fix": "Declare outputSchema for tools that return structured data, and return structuredContent that matches it."
            }
          ]
        },
        "checkedAt": "2026-10-04T22:20:17Z",
        "count": 2,
        "note": "answered without the initialize handshake",
        "schemaTokens": 252,
        "status": "ok",
        "tools": [
          {
            "name": "get_security_baseline",
            "description": "Return Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, supply-chain, destructive ops, data protection). Advisory grounding.",
            "inputSchema": {
              "properties": {},
              "type": "object"
            }
          },
          {
            "name": "check_action",
            "description": "Advisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply, so the agent can self-correct. Advisory only — does NOT block. Real-time blocking is Kernora Agent Security's paid Integrity Plane.",
            "inputSchema": {
              "properties": {
                "action": {
                  "description": "the action/command about to run",
                  "type": "string"
                }
              },
              "required": [
                "action"
              ],
              "type": "object"
            }
          }
        ]
      },
      "name": "agent-sec",
      "note": "Indexed from the official MCP registry: facts and our own checks, not reviewed, so no score, grade or rank.",
      "packages": null,
      "pageJsonUrl": "https://www.anchorterminal.com/tools/kernora-agent-sec.json",
      "popularity": {
        "githubStars": 1
      },
      "registryName": "ai.kernora/agent-sec",
      "remotes": [
        {
          "type": "streamable-http",
          "url": "https://agentsec.kernora.ai/mcp"
        }
      ],
      "repository": "https://github.com/kernora-ai/agent-sec",
      "reviewed": false,
      "slug": "kernora-agent-sec",
      "source": "the official MCP registry",
      "sourceUrl": "https://registry.modelcontextprotocol.io/v0.1/servers?search=ai.kernora/agent-sec",
      "summary": "Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.",
      "updatedAt": "2026-07-31T21:35:17Z",
      "url": "https://www.anchorterminal.com/tools/kernora-agent-sec",
      "vendor": "kernora.ai",
      "vendorUrl": "https://agentsec.kernora.ai",
      "version": "0.1.0",
      "websiteUrl": "https://agentsec.kernora.ai",
      "where": "hosted",
      "why": [
        "vendor"
      ]
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/kernora-agent-sec",
    "json": "https://www.anchorterminal.com/tools/kernora-agent-sec.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/kernora-agent-sec.md",
    "slim": "https://www.anchorterminal.com/tools/kernora-agent-sec.min.md"
  },
  "markdown": "# agent-sec\n\n\u003e Indexed, not reviewed: facts from the official MCP registry and our own checks. No score, grade or rank, and not in the rankings until the panel reviews it. How the index works: https://www.anchorterminal.com/indexed/\n\n- Kind: MCP server, by kernora.ai (https://agentsec.kernora.ai)\n- Listed because: It's published in the registry under kernora.ai, a namespace the registry only gives to whoever proves they control that domain.\n- What the official MCP registry says: Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.\n\n## Facts\n\n- MCP registry: `ai.kernora/agent-sec` 0.1.0\n- Endpoint: https://agentsec.kernora.ai/mcp (streamable HTTP)\n- Source: https://github.com/kernora-ai/agent-sec\n- Website: https://agentsec.kernora.ai\n- GitHub stars: 1\n- Registry entry updated: 2026-07-31\n\n## Tools\n\n- Tools it lists (2, about 252 tokens of context, `tools/list` without credentials, checked 2026-10-04 22:20 UTC):\n  - `get_security_baseline`: Return Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, supply-chain,…\n  - `check_action`: Advisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply, so the agent can…\n- How its tools read to an agent (0 errors, 2 warnings, 1 note, about 252 tokens; rules at https://www.anchorterminal.com/check.md; not part of the score):\n  - warn TC16 check_action: no readOnlyHint or destructiveHint\n  - warn TC16 get_security_baseline: no readOnlyHint or destructiveHint\n  - note TC24 server: 2 of 2 tools have no outputSchema\n\n- JSON: https://www.anchorterminal.com/api/v1/tools/kernora-agent-sec.json\n- Being indexed says nothing about quality, and nobody can pay for it. Ask for a review: https://www.anchorterminal.com/builders/#claiming\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-05",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Indexed",
        "url": "https://www.anchorterminal.com/indexed/"
      },
      {
        "name": "agent-sec",
        "url": ""
      }
    ],
    "description": "agent-sec, an MCP server by kernora.ai, listed from the official MCP registry. Indexed, not reviewed: facts and our own checks, no score or ranking. Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.",
    "facts": [
      "not reviewed",
      "not ranked",
      "facts only"
    ],
    "h1": "agent-sec",
    "image": "https://www.anchorterminal.com/assets/og/indexed.png",
    "path": "/tools/kernora-agent-sec",
    "published": "",
    "section": "indexed",
    "title": "agent-sec: MCP server, indexed from the official MCP registry",
    "toc": null,
    "updated": "2026-10-05",
    "url": "https://www.anchorterminal.com/tools/kernora-agent-sec"
  },
  "tokens": {
    "markdown": 650,
    "slim": 580
  },
  "version": 1
}
