Application Security, Threat Modeling, OWASP Hardening, Secrets & Incident Response
Threat-model products with asset/attacker/surface analysis, harden OWASP Top 10 with vulnerable-vs-fixed code pairs (IDOR, injection, SSRF, auth failures) plus AI-codegen warning patterns, lock down secrets and supply chain with OIDC CI and leaked-secret runbooks, configure strict nonce-based CSP and security headers with zero-breakage rollouts, and prepare SOC 2 audits, pentests, incident response and bug bounty launches.
Paste this into your Cursor / Claude Code / Windsurf MCP config (streamable HTTP):
{
"mcpServers": {
"secforge": {
"url": "https://secforge-api.agentweb-hub.workers.dev/mcp"
}
}
}
Free tier: 10 requests/day per agent. Pro lifetime unlock: $7.99 on Gumroad (or the all-access suite pass). Solana USDC supported on-chain.