by dalisecurity · MCP Server · ★ 53
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
AI-native security toolkit — fray go target.com scans everything. 7,800+ payloads, 98 WAF vendors, 42+ recon checks. Zero config
| Stars | 53 |
| Forks | 4 |
| Language | Python |
| Category | MCP Server |
| Quality Score | 50.1931115953007/100 |
| Open Issues | 2 |
| Last Updated | 2026-03-18 |
| Created | 2026-03-01 |
| Platforms | mcp, python |
| Est. Tokens | ~505k |
Looking for a Fray alternative? If you're comparing Fray with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
AI-powered penetration testing MCP server
Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 51 rules mappe
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.
MCP-native security automation workbench (SDK + CLI + MCP) — authorized testing + static AI/MCP attack-surface
Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability
Explore other popular mcp server tools:
Fray is AI-native security toolkit — fray go target.com scans everything. 7,800+ payloads, 98 WAF vendors, 42+ recon checks. Zero config. It is categorized as a MCP Server with 53 GitHub stars.
Fray is primarily written in Python. It covers topics such as attack-surface, bugbounty, cloudflare.
You can find installation instructions and usage details in the Fray GitHub repository at github.com/dalisecurity/Fray. The project has 53 stars and 4 forks, indicating an active community.
The top alternatives to Fray on Agent Skills Hub include tengu, agent-audit, agent-security-scanner-mcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: