Flagged: sudo usage, privileged Docker. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by calebevans · MCP Server · ★ 88
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mulder safe to install? View the security audit →
mulder 🏆 1st Place - SANS Institute Find Evil Hackathon 2026 Mulder takes a directory of forensic evidence (disk images, memory dumps, PCAPs, event logs) and runs a five-phase autonomous investigation with hard quality gates between each phase. It produces structured incident reports with MITRE ATT&CK mappings, IOC exports, and a full audit trail. An adversarial "Alternative Narrative" phase challenges every finding before the report is generated. All tool invocations go through typed MCP interfaces - never through a shell - and an append-only audit log validates every evidence citation at the API boundary, making findings with fabricated evidence citations structurally impossible to submit. Results Four autonomous investigations against real forensic datasets, unmodified from tool output. Each case has an interactive HTML report on GitHub Pages (sidebar navigation, dark/light theme, audit trail). See the examples index for all report links.
| Stars | 88 |
| Forks | 19 |
| Language | Python |
| Category | MCP Server |
| License | Apache-2.0 |
| Quality Score | 59.7089953969702/100 |
| Open Issues | 16 |
| Last Updated | 2026-10-04 |
| Created | 2026-04-08 |
| Platforms | claude-code, mcp, python |
| Est. Tokens | ~16k |
Looking for a mulder alternative? If you're comparing mulder with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Valhuntir CLI — AI-augmented incident response platform
Investigation toolkit for Claude Code: case management, OSINT, structured analytic techniques, chain-of-custod
Daymon puts your favorite AI to work 24/7. It schedules, remembers, and orchestrates your own virtual team. Fr
DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent
Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability
Build AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red tea
Explore other popular mcp server tools:
mulder is Agentic DFIR. It is categorized as a MCP Server with 88 GitHub stars.
mulder is primarily written in Python. It covers topics such as ai, ai-agents, claude-code.
You can find installation instructions and usage details in the mulder GitHub repository at github.com/calebevans/mulder. The project has 88 stars and 19 forks, indicating an active community.
mulder is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to mulder on Agent Skills Hub include Valhuntir, huntkit, daymon. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: