From 71831cb94b725b574e3b2ed11737924fbcaafb14 Mon Sep 17 00:00:00 2001 From: Aurelio Nakamura Date: Sat, 19 Sep 2026 00:12:38 -0700 Subject: [PATCH] Add cmdxray (shell-command safety gate + explainer for AI agents) to Security --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 45f85250f..82e1eee9f 100644 --- a/README.md +++ b/README.md @@ -3948,6 +3948,7 @@ Tools for conducting research, surveys, interviews, and data collection. - [CTRLRun/ctrlrun](https://github.com/CTRLRun/ctrlrun) [![CTRLRun/ctrlrun MCP server](https://glama.ai/mcp/servers/CTRLRun/ctrlrun/badges/score.svg)](https://glama.ai/mcp/servers/CTRLRun/ctrlrun) 🐍 🏠 - Execution safety for AI agent actions. `ctrlrun mcp-operator` exposes the approval queue as tools (`list_pending_approvals`, `approve`, `deny`, `resolve`, plus `receipts`, `effects`, `stats` and `inspect_action`), so the human who has to answer a held action answers it from the assistant they are already in; read tools answer without a credential and write tools refuse without one that names a person. Separately, the gateway proxies any MCP server so every tool call is checked against a YAML policy before it runs: allow, hold for a human, or deny. Approvals are single-use and bound to the hash of the exact action, one logical effect runs at most once across processes and hosts, and an unknown outcome is recorded AMBIGUOUS rather than FAILED so a blind retry is refused. Every attempt leaves a hash-chained JSON receipt. Apache-2.0. `pip install ctrlrun` - [Drumworks/ssid-mcp](https://github.com/Drumworks/ssid-mcp) [![Drumworks/ssid-mcp MCP server](https://glama.ai/mcp/servers/Drumworks/ssid-mcp/badges/score.svg)](https://glama.ai/mcp/servers/Drumworks/ssid-mcp) 📇 ☁️ - MAC-address (OUI) vendor lookup and router default-login directory for AI agents. Identify a device manufacturer from its MAC address, detect randomized/private (locally-administered) addresses instead of reporting "unknown", or fetch a router's default login IP and admin credentials — every router field cited to the manufacturer's own documentation. Free tier, no signup. `npx -y ssid-mcp` +- [aurelio-nakamura/cmdxray](https://github.com/aurelio-nakamura/cmdxray) [![aurelio-nakamura/cmdxray MCP server](https://glama.ai/mcp/servers/aurelio-nakamura/cmdxray/badges/score.svg)](https://glama.ai/mcp/servers/aurelio-nakamura/cmdxray) 📇 🏠 🍎 🪟 🐧 - A safety gate and explainer for AI coding agents that run shell commands. `check_command_safety` returns a danger/caution/none verdict for a proposed command — catching `rm -rf /`, `curl | sudo bash`, `dd`/`mkfs`/`shred` to a device, `chmod -R 777 /`, fork bombs, `git push --force` and CI `${{ }}` script-injection — so an agent can guard a command before executing it. `explain_command` gives a token-by-token breakdown of every flag, pipe, redirect and subshell. Fully offline, zero dependencies, nothing leaves the machine. `npx -y cmdxray-mcp`. ### 🌐 Social Media