MCP App Store
by KeenEthics

Category Hub

Risk Screening apps and integrations

Risk Screening apps help teams and individuals assess cybersecurity, fraud, compliance, privacy, vendor, and identity risks using connected records, threat intelligence, or submitted messages, links, domains, and packages. Listings cover security-posture reviews, vulnerability and dependency scans, scam and breach checks, compliance evidence, KYB or AML screening, risk prioritization, and remediation guidance.

76 apps

Top risk screening apps

Open full directory →
Financial-Services
D&B Risk Analytics

D&B Risk Analytics

By Dun & Bradstreet

Dun & Bradstreet empowers teams to execute risk workflows such as KYC/KYB, entity resolution, screening, alert triage, and more using relationship-aware business context from the D&B Commercial Graph™. Verified risk data, anchored in the global standard D‑U‑N‑S® Number business identifier, and policy-driven logic provide the foundation for consistent decisioning across systems of record and scalable risk operations in regulated environments.

Tools: 33

View details →
Business & Operations
Sumsub

Sumsub

By Sumsub

Bring your compliance operations into ChatGPT. Connect to your Sumsub account to onboard applicants, generate verification links, and pull live data on identities, businesses, transactions, AML screening cases, and fraud networks—all in plain language. Triage your review queue by risk, assemble due-diligence dossiers, investigate suspicious activity, and draft regulatory reports without clicking through the Dashboard. Turn full-cycle verification into an AI-powered workflow that moves at the speed of conversation.

Tools: 18

View details →
Other
Mnemom

Mnemom

By Mnemom

Mnemom is trust infrastructure built for agents, not just the humans who run them. In one chat you can look up an agent's Continuous Trust Rating — the score, the grade, and the accountability evidence behind it — and confirm it's cryptographically signed, not merely asserted. Drop your own alignment card and get an instant trust read back; claim a verifiable identity with no human in the loop; and walk away with an embeddable Trust Rating badge for your README or agent card. Every read is honest about what it knows: a quiet record reads as quiet, never as a red flag. The system tells the truth — and view-source proves it.

Tools: 17

View details →
Defense.com Threat Analysis

Defense.com Threat Analysis

By Defense.com Threat Analysis

Connect Claude to your Defense.com portal to query open threats, security issues, and remediation status. Filter by risk level, source type, assignee, or keyword. View team workload and assignments. Includes interactive security training sessions. Supports 200+ source type aliases for natural language queries like 'show me pentest findings' or 'get m365 threats'.

Tools: 16

View details →
Business-Productivity
Norton

Norton

By Norton (part of Gen Digital Inc.)

Stay protected while you chat with Claude. Norton brings real-time, AI-powered scam detection directly into your conversations, backed by the Norton Genie AI assistant. Share suspicious emails, texts, messages, images, or links for instant analysis and clear cyber safety guidance to help you avoid phishing, scams, and malicious content before you click. You can also ask everyday questions about security, privacy, identity protection, and device performance, and get trusted answers right where you’re already chatting.

Tools: 7 · Prompts: 3

View details →
Security
Malwarebytes

Malwarebytes

By Malwarebytes Inc.

Verify links, emails, phone numbers, and domains against Malwarebytes threat intelligence directly from Claude. Get instant scam verdicts, domain ownership details, and risk levels for unknown callers, shortened URLs, and suspicious messages before you click, call, or reply. Report suspicious indicators back to Malwarebytes to help protect others.

Tools: 6 · Prompts: 3

View details →
Productivity
McAfee

McAfee

By McAfee

Steer clear of scams while you chat. McAfee brings real-time scam detection directly into Claude so you know what to trust before you click. Share suspicious emails, texts, social messages, or links for instant analysis, clear explanations of the risk, and guidance on what to do next.

Tools: 0 · Prompts: 3

View details →
Endor Labs

Endor Labs

By Endor Labs

Endor Labs AI Plugins brings application security scanning directly into your development workflow. It automates the installation, authentication, and configuration of endorctl, the Endor Labs CLI, so you can scan, prioritize, and fix security risks across your software supply chain without leaving your coding environment. The plugin supports macOS (Intel/ARM), Linux, and Windows, and handles authentication via browser-based OAuth or API key credentials.

Prompts: 4

View details →
Sonatype Guide

Sonatype Guide

By Sonatype

Sonatype Guide connects Claude Code to Sonatype's software supply chain intelligence platform via MCP. It lets you scan your project's dependencies for known vulnerabilities, get secure version recommendations, and evaluate open-source components based on security, licensing, and quality metrics — all without leaving your editor.

Prompts: 4

View details →
Security
PrivacyHawk

PrivacyHawk

By PrivacyHawk, Inc

Use PrivacyHawk with ChatGPT to Take Control of Your Personal Data -- Manage, control, and delete your data from thousands of businesses exploiting your personal information. PrivacyHawk helps you reduce your digital footprint, decrease spam, and protect yourself from identity theft, scams, and hacks. Key Features: - Delete your data from unwanted databases by automatically finding and removing your private information from companies that expose or sell it. - Stop companies from selling your data by easily sending "Do Not Sell" requests to thousands of businesses. - Unsubscribe from spam emails and clean up your inbox. Now supporting Gmail, Yahoo, and Microsoft accounts—including Hotmail, MSN, Live, and Outlook. - Use advanced data broker tools to opt out of data brokers and protect your personal information. - Protect multiple email addresses under the same account to maximize your privacy. Why Choose PrivacyHawk: Thousands of corporations share and sell your personal data. Although privacy laws now require them to stop when requested, opting out is difficult due to complex processes and the sheer number of companies. PrivacyHawk simplifies this process by handling it for you.

Prompts: 3

View details →
Security
Ansvar Gateway

Ansvar Gateway

By Ansvar AI

Ansvar Systems AB is a Swedish cybersecurity company that gives AI agents verifiable access to law, regulation and security standards. Customers connect the AI assistant they already use (Claude, Microsoft Copilot, ChatGPT or any MCP-compatible client) to the Ansvar Gateway and run compliance work directly in that assistant: regulatory gap analyses, threat models (STRIDE/LINDDUN, TARA), DPIAs and audit preparation, grounded in more than 300 curated corpora of EU and international legislation, case law, preparatory works, regulator guidance and security standards. Every answer carries paragraph-level citations to the official source. When a source is unavailable, the platform returns an error instead of guessing, accuracy over availability is an architectural rule, not a disclaimer. All content is ingested from the original publisher under verified licensing, so results can be relied on and redistributed. Ansvar serves legal insurers, compliance teams, security consultancies and software teams that need to know which rules apply; NIS2, GDPR, DORA, CRA, the EU AI Act, national and sector regulation — and to prove where every answer came from.

Prompts: 3

View details →
sonarqube

sonarqube

By SonarSource

SonarQube uses multi-layered analysis, built on deterministic verification and complemented by AI-powered capabilities. This allows Sonar to enforce organizational standards consistently, repeatedly, and automatically. The SonarQube plugin applies the same quality standards already governing developer-written code to every line of code Claude produces — 7,500+ rules, secrets scanning, agentic analysis, and quality gates across 40+ languages. With Agentic Analysis enabled, PostToolUse hooks run SonarQube analysis after every file edit, catching issues the moment they're introduced — not after a CI pipeline or pull request. Every file Claude reads and every prompt you enter is automatically scanned for 450+ secrets patterns before content reaches the LLM context window, preventing secrets from ever leaking to the model. Slash commands give you on-demand access to quality gate status, open issues, coverage, duplication metrics, and dependency risks without leaving the terminal.‍

Prompts: 1

View details →
Data & Analytics
PowerDMARC

PowerDMARC

By PowerDMARC

PowerDMARC brings your email-authentication data into ChatGPT. Ask about any domain's security posture and get an interpreted DMARC, SPF, DKIM, BIMI, and MTA-STS breakdown. Dig into DMARC aggregate reports to see who's sending email as your domain, which sources are failing authentication, and where your mail is coming from by country and organization. Look up live DNS and WHOIS records, generate correctly-formatted DMARC, SPF, and DKIM records, and review your hosted-service configuration. Authentication is handled securely via OAuth — the plugin accesses only what your PowerDMARC account already permits, and never stores your credentials or tokens.

Prompts: 3

View details →
Developer Tools
Canonical Memory Verifier

Canonical Memory Verifier

By Sizhe Cheng

A local, read-only verifier for source integrity, explicit supersession, deterministic current projection, declared source-reference tracing, and remembered-authority boundaries.

Prompts: 3

View details →
Security
Codex Security

Codex Security

By OpenAI

Codex Security packages reusable workflows for security scans, analysis, validation, and investigation across code, diffs, and related artifacts.

Prompts: 3

View details →
Security
Radar Lite

Radar Lite

By Red Sift

Analyze any domain’s email authentication, DNS, and web security configuration. Radar Lite scans your domain, visualizes security scores on a radar chart, and generates a summary with prioritized findings and remediation guidance. Try prompts like: - Radar Lite Evaluate the DNS security of example.com - Radar Lite Compare the DMARC configuration of domain1.com to domain2.com - Radar Lite Give me an assessment of the overall security posture of domain1.com, domain2.com and domain3.com You can ask follow-up questions to clarify any terms and dig deeper into the performed tests.

Prompts: 2

View details →
Aikido Security

Aikido Security

By Aikido Security

The plugin automatically identifies files generated or changed during your session, runs a full security scan (up to 50 files per request), and when vulnerabilities are found, applies remediation guidance and re-scans — repeating up to three times until the code is clean. Each finding includes its title, severity, location, and line numbers.

Prompts: 2

View details →
Security
PureVPN Privacy Assistant

PureVPN Privacy Assistant

By PureVPN

Get reliable guidance for safer and more private browsing. Receive smart VPN server recommendations based on performance and location, along with practical troubleshooting tips to improve connection stability and speed.

Prompts: 2

View details →
Security
Bitdefender

Bitdefender

By Bitdefender SRL

Bitdefender Link Checker is a free tool designed to verify URLs, helping users avoid malware, phishing attempts, and counterfeit websites.

Prompts: 2

View details →
Security
Sprinto

Sprinto

By Sprinto

This ChatGPT app connects to your organization’s Sprinto workspace so you can work with your own compliance information inside ChatGPT Use it to explore questions about your security and compliance posture using the Compliance Knowledge Hub: the policies, procedures, approved questionnaire content, and related documentation your organization maintains in Sprinto. Responses are intended to reflect your documented practices, and when Sprinto returns supporting material, you should see references to those sources so answers can be verified. For vendor security questionnaires and similar requests, you can bring structured questionnaires into the conversation and obtain consistent, context‑aware draft responses drawn from the same Knowledge Hub. Items that cannot be supported clearly from your content may be flagged for human review before you share answers with customers, partners, or auditors. Capabilities depend on your organization’s Sprinto configuration and the content available in your hub. A valid Sprinto sign‑in is required. Currently only supported for US region.

Prompts: 1

View details →
Developer Tools
SentinelX

SentinelX

By PensaInfra

SentinelX lets you manage your Linux servers from ChatGPT — no SSH required. Install a small open-source agent on any Linux box, and ChatGPT can run inspection commands, manage systemd services, read/search/edit files, run scripts, upload files, and call out to integrations like Cloudflare DNS, Resend, and Telegram. Every action is constrained by a per-host allowlist that you control. The agent only runs commands and services you've explicitly declared safe, rejects anything outside the policy at the agent boundary, and Linux file permissions still apply on top. You can connect multiple servers and label them however you want. Typical uses: check uptime and disk space, restart services, tail logs, edit nginx configs, run quick scripts, manage DNS records, send notifications. The agent is open source on GitHub (github.com/pensados/sentinelx-cloud-core). Authentication uses OAuth 2.0 with PKCE and Dynamic Client Registration, scoped per user.
View details →
Security
Bastion

Bastion

By Bastion Technologies

Connect Bastion to ChatGPT to manage your security and compliance posture through natural conversation. Review framework compliance status across SOC 2, ISO 27001, HIPAA, and GDPR. Drill into failing tests, upload evidence, and submit controls for review. Ask your knowledge base security and compliance questions grounded in your own policies and documentation. Monitor code security findings and GitHub configuration status. All data is scoped to your authenticated account - you only ever see your own tenant.
View details →
Security
AJAXX Data Scrubber

AJAXX Data Scrubber

By FORTRESS APPS LLC

AJAXX Data Scrubber in ChatGPT provides read-only information about digital privacy risks and data broker exposure. It explains how personal data appears online, how removal services work, and answers common questions about scans, monitoring, and protection options. This ChatGPT app does not run scans, show personal scan results, perform removals, or manage accounts. For secure account access, scans, removals, billing, or support, users are directed to the official AJAXX website.
View details →
Security
ToolCheck by M8ven

ToolCheck by M8ven

By M8ven Inc.

ToolCheck is M8ven's trust layer for the MCP ecosystem. Give it a GitHub URL or npm package name and it returns an independent trust score (0–100) and a clear verdict (Trusted / Caution / Concern), backed by static code analysis, runtime behavioral observation in a sandbox, CVE scanning, and a semantic check comparing the tool's declared behavior against what its code actually does — catching the gap between "read-only market data" and code that can move your funds.
View details →

Need a custom risk screening integration built?