Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP. Connect the official Agent Sec MCP server to Claude, ChatGPT, or Cursor through gate — one gateway URL, no config files, security-checked.
Free to start · No credit card · No hosting needed
Pick your client. Copy, paste, done — or let gate handle sign-ins and policies for you.
claude mcp add --transport http agent-sec https://agentsec.kernora.ai/mcpRun in your terminal, then restart Claude Code.
Agent Sec · https://agentsec.kernora.ai/mcp
Real prompts you can type the moment it's connected — no setup, no docs to read.
“Use “get_security_baseline”: Return Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, suppl.”
“Use “check_action”: Advisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply,.”
Every server in the gate directory has to pass the same four checks before your AI can touch it. Here's how Agent Sec holds up.
Operated by Agent Sec (kernora.ai) at its documented MCP endpoint — not a third-party mirror or community re-host.
This server only exposes public data — no account and no credentials are involved when you connect.
gate checks every tool for prompt injection, hidden instructions, data-exfiltration hints, and over-broad permissions before the server is available through your gateway.
If Agent Sec adds or changes tools later, gate re-scans and alerts you — before your AI acts on the change.
Add one gateway URL to Claude, ChatGPT, or any MCP client. One-time setup, about two minutes.
Choose Agent Sec in the gate directory. No sign-in needed.
Agent Sec's tools are live in every AI client you've connected — with rules and logging built in.
Free to start · No credit card · No hosting needed
Fetched live from the official endpoint and re-checked daily by gate — not marketing copy.
get_security_baseline — Return Kernora Agent Security's curated security baseline — the known-good rules an AI coding agent should follow (secrets, injection, suppl
check_action — Advisory check: given a described action or command the agent is about to take, return the baseline security factlets that plausibly apply,
https://agentsec.kernora.ai/mcpYes — Agent Sec operates its own remote MCP server at agentsec.kernora.ai. gate connects you to that official endpoint and adds security scanning, per-tool access rules, and an activity log on top.
Add gate's gateway URL to your AI client once, then pick Agent Sec in the directory. No account or sign-in is needed. From then on, Agent Sec's tools are available in every client you've connected to gate.
No. Agent Sec runs the server, and gate is fully managed. You just connect one URL — there's nothing to install, deploy, or maintain.
It's the vendor's official endpoint, and gate scans its tools for prompt injection and hidden instructions before it goes live, re-checks it whenever it changes, and lets you allow, block, or require approval for every single tool.
Yes — you can get started with gate for free and connect Agent Sec in minutes. No credit card required.
Every server below works through the same gateway URL — connect once, add tools anytime.
Set up Agent Sec in: Claude · Claude Code · ChatGPT · Cursor · VS Code