{"name":"io.github.inkog-io/inkog","slug":"inkog-io-inkog","title":null,"description":"Security co-pilot for AI agents. Scan for vulnerabilities, audit MCP servers, verify governance.","url":"https://mcp.market/server/inkog-io-inkog","rating":null,"grade":"B","score":74,"certified":false,"status":"active","category":"security","tags":["security"],"presence":{"score":31,"stars":3,"forks":0,"downloads_week":98,"last_push_at":"2026-09-16T09:53:51.000Z","license":"Apache-2.0"},"uptime":null,"claimed":false,"transport":"npm","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/inkog-io/inkog-mcp","website":null,"version":"1.0.20","remotes":[],"packages":[{"registryType":"npm","identifier":"@inkog-io/mcp","version":"1.0.20","transport":{"type":"stdio"},"environmentVariables":[{"description":"Your Inkog API key from https://app.inkog.io (free tier available)","isRequired":true,"format":"string","isSecret":true,"name":"INKOG_API_KEY"}]}],"tools":[{"name":"inkog_audit_a2a","description":"Audit Agent-to-Agent (A2A) communications in multi-agent systems. Detects infinite delegation loops, privilege escalation, data leakage between agents, and unauthorized handoffs. Supports Google A2A protocol, CrewAI, LangGraph, and AutoGen. Use this when building or reviewing multi-agent systems to detect delegation vulnerabilities.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inkog_audit_mcp_server","description":"Security audit any MCP server from the registry or GitHub. Analyzes tool permissions, data flow risks, input validation, and potential vulnerabilities. Use this before installing any new MCP server to verify it is safe.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inkog_compliance_report","description":"Generate a compliance report for EU AI Act, NIST AI RMF, ISO 42001, or OWASP LLM Top 10. Analyzes agent code and maps findings to regulatory requirements. Use this when preparing AI agents for regulatory compliance or audit.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inkog_explain_finding","description":"Get detailed explanation and remediation guidance for a security finding or pattern. Includes what the issue is, why it's dangerous, step-by-step fixes, and code examples. Use this after scanning to understand how to fix security findings.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inkog_generate_mlbom","description":"Generate a Machine Learning Bill of Materials (MLBOM) for AI agents. Lists all models, tools, data sources, frameworks, and dependencies. Supports CycloneDX and SPDX formats. Use this when documenting AI agent dependencies for supply chain compliance.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inkog_scan","description":"Security co-pilot for AI agent development. Scans for prompt injection, infinite loops, token bombing, SQL injection via LLM, and missing guardrails. Supports LangChain, CrewAI, LangGraph, AutoGen, n8n, and 20+ agent frameworks. Use this whenever building, reviewing, or deploying AI agents to catch security issues before they reach production.","write_action":false,"price_micros":0,"input_schema":null},{"name":"inkog_verify_governance","description":"Validate that AGENTS.md declarations match actual code behavior. Detects governance mismatches like 'read-only declared but code writes data' or 'human approval required but no approval gates in code'. Essential for EU AI Act Article 14 compliance. Use this whenever an AI agent project has an AGENTS.md file, or to verify governance compliance before deployment.","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":74,"grade":"B","scanned_at":"2026-09-28T06:09:01.007Z","report":{"scannerVersion":"0.1.10","scannedAt":"2026-09-28T06:09:00.972Z","components":{"code":{"score":20,"max":25,"notes":["33 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 12 days ago"]},"identity":{"score":7,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[{"id":"exec.eval","severity":"medium","component":"code","title":"eval / new Function used","evidence":"dist/utils/agent-detector.js: …ENSITIVE_PATTERNS = [ 'exec(', 'eval(', 'subprocess', 'os.system', …"}],"inputs":{"packages":[{"registryType":"npm","identifier":"@inkog-io/mcp","version":"1.0.20","found":true,"license":"Apache-2.0","hasInstallScripts":false,"dependencyCount":3,"publishedAt":"2026-02-28T09:27:03.011Z","repositoryUrl":"git+https://github.com/inkog-io/inkog-mcp.git","weeklyDownloads":98}],"repo":{"found":true,"owner":"inkog-io","repo":"inkog-mcp","archived":false,"pushedAt":"2026-09-16T09:53:51Z","stars":3,"forks":0,"openIssues":0,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/240290934?v=4","ownerCreatedAt":"2025-10-26T09:31:13Z","license":"Apache-2.0"},"icon":{"url":"https://avatars.githubusercontent.com/u/240290934?v=4&s=128","source":"github"},"presence":{"stars":3,"forks":0,"downloadsWeek":98,"license":"Apache-2.0","lastPushAt":"2026-09-16T09:53:51.000Z","score":31}}}},"grade_history":[],"reviews":[]}