The MCP Security Problem Is Solved
Every AI agent using MCP today is running unsigned code with unchecked capabilities and zero audit trail. ddot-mcp-bridge is a drop-in fix: Ed25519 verification, tool whitelisting, capability gating, and hash-chained audit — all transparent to your existing tools.
The Problem No One Is Talking About
The Model Context Protocol (MCP) is becoming the standard for tool use in AI agents. Claude, Cursor, Windsurf, and dozens of other tools use it. But MCP was designed for functionality, not security. There is:
No Signature Verification
MCP servers are executables on disk. Nothing verifies they haven't been tampered with since installation. A supply chain attack modifies the binary and every agent call now runs compromised code.
No Tool Boundaries
An MCP server declares its tools at runtime via self-reporting. A malicious server can expose hidden tools that the user never approved. The AI agent has no way to distinguish legitimate tools from injected ones.
Full Environment Access
Every MCP server inherits the full environment of its parent process. API keys, database credentials, cloud tokens — all accessible to every server, regardless of whether it needs them.
Zero Audit Trail
There is no standard mechanism to log which tools were called, with what arguments, and what they returned. When something goes wrong, you have no forensic trail to investigate.
The Five-Gate Security Pipeline
ddot-mcp-bridge is a transparent stdio proxy that sits between your AI agent and its MCP servers. Every JSON-RPC message passes through five security gates before reaching the server. The server doesn't even know it's there.
Gate by Gate
Ed25519 Manifest Verification
Before the MCP server process is even spawned, the bridge verifies the server's manifest signature against the publisher's Ed25519 public key. If the manifest has been modified since signing — wrong tool list, changed command, altered capabilities — the bridge refuses to start the server. Period.
Tool Whitelist Enforcement
The signed manifest declares exactly which tools the server is allowed to expose. When the AI agent calls a tool, the bridge checks the tool name against the whitelist before forwarding the request. Undeclared tools are blocked — even if the server reports them as available. The whitelist lives in the signed manifest, not in the server.
Capability Gating
Each server declares its capabilities: network access (local or external), filesystem read/write (with path scoping), environment variable access, and process spawning. The bridge enforces these boundaries at the proxy layer. A server declared with net:local cannot make external HTTP calls. A server with fs:read(runtime) cannot write to disk.
Environment Isolation
The bridge strips the process environment before spawning the server. Only environment variables explicitly declared in the signed manifest are passed through. Your API keys, cloud credentials, and database passwords are invisible to servers that don't need them.
SHA-256 Hash-Chained Audit Trail
Every JSON-RPC request and response is logged to an append-only audit chain. Each entry contains a SHA-256 hash of the previous entry, creating a tamper-evident chain. If someone deletes or modifies a log entry, the chain breaks and the tampering is detectable. Full forensic visibility into every tool call, argument, and return value.
Attack Vectors Eliminated
These are real attack vectors against MCP-based AI agents. ddot mitigates all of them today.
Supply Chain Compromise
A malicious actor modifies an MCP server binary after installation. ddot detects the mismatch between the binary's behavior and its signed manifest and refuses to start it.
Tool Injection
A compromised server exposes hidden tools (e.g., a file-upload tool disguised as a read-only server). ddot's whitelist blocks any tool not in the signed manifest.
Credential Exfiltration
An MCP server reads AWS_SECRET_ACCESS_KEY from the environment and sends it to an external endpoint. ddot strips all undeclared env vars and blocks unauthorized network access.
Prompt-Driven Exploitation
A prompt injection tricks the AI agent into calling a dangerous tool with malicious arguments. ddot's 5-layer firewall catches injection patterns before they reach the MCP layer.
Lateral Movement
A compromised server attempts to access filesystem paths or network endpoints outside its declared scope. Capability gating blocks the request at the proxy layer.
Audit Tampering
An attacker attempts to cover tracks by modifying audit logs. The SHA-256 hash chain makes any modification detectable — every entry is cryptographically linked to the previous one.
Secured MCP Servers on This Gateway
| Server | Version | Publisher | Tools | Caps | Signature |
|---|---|---|---|---|---|
| Agentops | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Lmstudio | v1.0.0 | ai | 0 | 2 | Valid |
| Make | v1.0.0 | productivity | 0 | 2 | Valid |
| Newrelic | v1.0.0 | analytics | 0 | 3 | Valid |
| Sagemaker | v1.0.0 | ai | 0 | 3 | Valid |
| Google Tag Manager | v1.0.0 | analytics | 0 | 3 | Valid |
| Url Shortener | v1.0.0 | utility | 0 | 2 | Valid |
| Launchdarkly | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Vercel | v1.0.0 | cloud | 0 | 3 | Valid |
| Svgmaker | v1.0.0 | media | 0 | 2 | Valid |
| Apache Iotdb | v1.0.0 | database | 0 | 3 | Valid |
| Sentry | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Obsidian | v1.0.0 | productivity | 0 | 2 | Valid |
| Coinbase | v1.0.0 | finance | 0 | 3 | Valid |
| Resend | v1.0.0 | communication | 0 | 3 | Valid |
| Stability Ai | v1.0.0 | ai | 0 | 3 | Valid |
| Whisper | v1.0.0 | ai | 0 | 2 | Valid |
| Google Gemini | v1.0.0 | ai | 0 | 3 | Valid |
| Shodan | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Lemon Squeezy | v1.0.0 | finance | 0 | 2 | Valid |
| Serpapi | v1.0.0 | search | 0 | 3 | Valid |
| Webscraping Ai | v1.0.0 | search | 0 | 3 | Valid |
| Notion Calendar | v1.0.0 | productivity | 0 | 2 | Valid |
| R2 Storage | v1.0.0 | cloud | 0 | 3 | Valid |
| Slack | v1.0.0 | communication | 0 | 3 | Valid |
| 1password | v1.0.0 | utility | 0 | 2 | Valid |
| Cloudinary | v1.0.0 | media | 0 | 3 | Valid |
| Aws Ec2 | v1.0.0 | cloud | 0 | 3 | Valid |
| v1.0.0 | productivity | 0 | 3 | Valid | |
| Kubernetes | v1.0.0 | cloud | 0 | 2 | Valid |
| Json Placeholder | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Microsoft Devbox | v1.0.0 | cloud | 0 | 3 | Valid |
| Executeautomation Playwright | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Aws Cost Analysis | v1.0.0 | cloud | 0 | 3 | Valid |
| Mailchimp | v1.0.0 | communication | 0 | 3 | Valid |
| Antv Chart | v1.0.0 | analytics | 0 | 2 | Valid |
| Actionkit Paragon | v1.0.0 | api | 0 | 3 | Valid |
| Mistral | v1.0.0 | ai | 0 | 3 | Valid |
| Ifttt | v1.0.0 | productivity | 0 | 3 | Valid |
| Miro | v1.0.0 | productivity | 0 | 2 | Valid |
| Datadog | v1.0.0 | analytics | 0 | 3 | Valid |
| Zip | v1.0.0 | utility | 0 | 2 | Valid |
| Docker | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Nasa | v1.0.0 | api | 0 | 2 | Valid |
| Jira Confluence | v1.0.0 | productivity | 0 | 3 | Valid |
| Google Sheets | v1.0.0 | productivity | 0 | 2 | Valid |
| Redis Official | v1.0.0 | database | 0 | 3 | Valid |
| Llamaindex | v1.0.0 | ai | 0 | 2 | Valid |
| Together Ai | v1.0.0 | ai | 0 | 3 | Valid |
| Heroku | v1.0.0 | cloud | 0 | 2 | Valid |
| Raindrop | v1.0.0 | productivity | 0 | 3 | Valid |
| Network Ai | v1.0.0 | ai | 0 | 2 | Valid |
| Mermaid | v1.0.0 | utility | 0 | 2 | Valid |
| Vertex Ai | v1.0.0 | ai | 0 | 2 | Valid |
| Jetbrains | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Craft | v1.0.0 | productivity | 0 | 2 | Valid |
| Vimeo | v1.0.0 | media | 0 | 2 | Valid |
| N8n | v1.0.0 | productivity | 0 | 2 | Valid |
| Hologres | v1.0.0 | database | 0 | 3 | Valid |
| Chromadb | v1.0.0 | ai | 0 | 3 | Valid |
| Binance | v1.0.0 | finance | 0 | 3 | Valid |
| Exa Search | v1.0.0 | search | 0 | 3 | Valid |
| Linode | v1.0.0 | cloud | 0 | 2 | Valid |
| Cisco Webex | v1.0.0 | communication | 0 | 3 | Valid |
| Graphql | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Xero | v1.0.0 | finance | 0 | 3 | Valid |
| Aws Documentation | v1.0.0 | cloud | 0 | 3 | Valid |
| Knex | v1.0.0 | database | 0 | 2 | Valid |
| Exa | v1.0.0 | search | 0 | 3 | Valid |
| Quickbooks | v1.0.0 | finance | 0 | 3 | Valid |
| Pypi | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Google Search | v1.0.0 | search | 0 | 3 | Valid |
| Diagram Maker | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Embeddings | v1.0.0 | ai | 0 | 2 | Valid |
| Render | v1.0.0 | cloud | 0 | 2 | Valid |
| Databricks | v1.0.0 | database | 0 | 2 | Valid |
| Elevenlabs | v1.0.0 | ai | 0 | 3 | Valid |
| Gumroad | v1.0.0 | finance | 0 | 2 | Valid |
| Agentql | v1.0.0 | search | 0 | 3 | Valid |
| Mapbox | v1.0.0 | api | 0 | 3 | Valid |
| Puppet | v1.0.0 | cloud | 0 | 2 | Valid |
| Aiven | v1.0.0 | cloud | 0 | 3 | Valid |
| D3 | v1.0.0 | analytics | 0 | 2 | Valid |
| Twilio | v1.0.0 | communication | 0 | 3 | Valid |
| Ansible | v1.0.0 | cloud | 0 | 2 | Valid |
| Gitlab | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Circleci | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Home Assistant | v1.0.0 | iot | 0 | 2 | Valid |
| Codesandbox | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Clickhouse | v1.0.0 | database | 0 | 2 | Valid |
| Xcode | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Loki | v1.0.0 | analytics | 0 | 3 | Valid |
| Everart | v1.0.0 | media | 0 | 3 | Valid |
| Bigquery | v1.0.0 | database | 0 | 2 | Valid |
| Logstash | v1.0.0 | analytics | 0 | 2 | Valid |
| Pulumi | v1.0.0 | cloud | 0 | 2 | Valid |
| Flux | v1.0.0 | ai | 0 | 2 | Valid |
| Crossref | v1.0.0 | search | 0 | 2 | Valid |
| Typescript | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Convertkit | v1.0.0 | communication | 0 | 2 | Valid |
| D1 Cloudflare | v1.0.0 | database | 0 | 3 | Valid |
| Gitlab Dubuqingfeng | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Unsplash | v1.0.0 | media | 0 | 3 | Valid |
| Robots Txt | v1.0.0 | utility | 0 | 2 | Valid |
| Appium | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Midjourney | v1.0.0 | ai | 0 | 2 | Valid |
| Pdf Reader | v1.0.0 | productivity | 0 | 2 | Valid |
| Sentiment | v1.0.0 | ai | 0 | 2 | Valid |
| Raygun | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Gmail | v1.0.0 | communication | 0 | 2 | Valid |
| Monday | v1.0.0 | productivity | 0 | 2 | Valid |
| Pastebin | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Sqlite | v1.0.0 | database | 0 | 2 | Valid |
| Roam | v1.0.0 | productivity | 0 | 2 | Valid |
| Upstash | v1.0.0 | database | 0 | 2 | Valid |
| Plausible | v1.0.0 | analytics | 0 | 3 | Valid |
| Bear | v1.0.0 | productivity | 0 | 2 | Valid |
| Fetch | v1.0.0 | search | 0 | 2 | Valid |
| Matplotlib | v1.0.0 | analytics | 0 | 2 | Valid |
| Statuspage | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Grafana | v1.0.0 | analytics | 0 | 2 | Valid |
| Digitalocean | v1.0.0 | cloud | 0 | 3 | Valid |
| Statistics | v1.0.0 | analytics | 0 | 2 | Valid |
| Configcat | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Aws Terraform | v1.0.0 | cloud | 0 | 2 | Valid |
| Summarizer | v1.0.0 | ai | 0 | 2 | Valid |
| Smithery Cli | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Ssh | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Translation | v1.0.0 | utility | 0 | 2 | Valid |
| Swagger | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Memory | v1.0.0 | productivity | 0 | 2 | Valid |
| Opentelemetry | v1.0.0 | analytics | 0 | 3 | Valid |
| Calendar Ical | v1.0.0 | productivity | 0 | 2 | Valid |
| Sitemap | v1.0.0 | utility | 0 | 2 | Valid |
| Pinecone | v1.0.0 | database | 0 | 3 | Valid |
| Chroma | v1.0.0 | database | 0 | 2 | Valid |
| Deepseek | v1.0.0 | ai | 0 | 3 | Valid |
| v1.0.0 | communication | 0 | 2 | Valid | |
| Squarespace | v1.0.0 | productivity | 0 | 2 | Valid |
| Aws Ses | v1.0.0 | cloud | 0 | 3 | Valid |
| Semantic Scholar | v1.0.0 | search | 0 | 2 | Valid |
| Brave Search Extended | v1.0.0 | search | 0 | 3 | Valid |
| Google Analytics | v1.0.0 | analytics | 0 | 2 | Valid |
| Regex | v1.0.0 | utility | 0 | 2 | Valid |
| Canva | v1.0.0 | media | 0 | 2 | Valid |
| Github | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Rss | v1.0.0 | utility | 0 | 2 | Valid |
| Jira | v1.0.0 | productivity | 0 | 3 | Valid |
| v1.0.0 | utility | 0 | 2 | Valid | |
| Google Search Console | v1.0.0 | analytics | 0 | 3 | Valid |
| Weaviate | v1.0.0 | database | 0 | 2 | Valid |
| Prometheus | v1.0.0 | analytics | 0 | 2 | Valid |
| Sequential Thinking | v1.0.0 | ai | 0 | 2 | Valid |
| Etcd | v1.0.0 | cloud | 0 | 2 | Valid |
| Aws Cloudwatch | v1.0.0 | cloud | 0 | 3 | Valid |
| Roam Research | v1.0.0 | productivity | 0 | 3 | Valid |
| Google Ads | v1.0.0 | analytics | 0 | 2 | Valid |
| Ssl Checker | v1.0.0 | utility | 0 | 2 | Valid |
| Ocr | v1.0.0 | utility | 0 | 2 | Valid |
| Henkey Postgres | v1.0.0 | database | 0 | 3 | Valid |
| v1.0.0 | communication | 0 | 2 | Valid | |
| Playwright Automatalabs | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Dice Roller | v1.0.0 | productivity | 0 | 2 | Valid |
| Ical | v1.0.0 | utility | 0 | 2 | Valid |
| Notion Hosted | v1.0.0 | productivity | 0 | 2 | Valid |
| Rest Api | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Email Validator | v1.0.0 | utility | 0 | 2 | Valid |
| Vault | v1.0.0 | cloud | 0 | 2 | Valid |
| Outlook | v1.0.0 | communication | 0 | 2 | Valid |
| Excalidraw | v1.0.0 | productivity | 0 | 2 | Valid |
| Aws Cdk | v1.0.0 | cloud | 0 | 2 | Valid |
| Google Calendar | v1.0.0 | productivity | 0 | 2 | Valid |
| Perplexity | v1.0.0 | ai | 0 | 3 | Valid |
| Azure Devops | v1.0.0 | cloud | 0 | 3 | Valid |
| Ngrok | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Jina Ai | v1.0.0 | search | 0 | 3 | Valid |
| Twitch | v1.0.0 | media | 0 | 2 | Valid |
| Anyquery | v1.0.0 | database | 0 | 2 | Valid |
| Groq | v1.0.0 | ai | 0 | 3 | Valid |
| Dall E | v1.0.0 | ai | 0 | 3 | Valid |
| Alibaba Cloud Ecs | v1.0.0 | cloud | 0 | 3 | Valid |
| Upstash Redis | v1.0.0 | database | 0 | 3 | Valid |
| Height | v1.0.0 | productivity | 0 | 2 | Valid |
| Mixpanel | v1.0.0 | analytics | 0 | 3 | Valid |
| Typeorm | v1.0.0 | database | 0 | 2 | Valid |
| Tiktok | v1.0.0 | communication | 0 | 2 | Valid |
| Zapier | v1.0.0 | productivity | 0 | 3 | Valid |
| Trello | v1.0.0 | productivity | 0 | 3 | Valid |
| Pagerduty | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Postgres Henkey Advanced | v1.0.0 | database | 0 | 3 | Valid |
| Pulsar | v1.0.0 | api | 0 | 3 | Valid |
| Ftp | v1.0.0 | utility | 0 | 2 | Valid |
| Llm Txt | v1.0.0 | ai | 0 | 2 | Valid |
| Google Maps | v1.0.0 | api | 0 | 3 | Valid |
| Replit | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Strapi | v1.0.0 | productivity | 0 | 2 | Valid |
| Bigcommerce | v1.0.0 | finance | 0 | 2 | Valid |
| Loom | v1.0.0 | communication | 0 | 2 | Valid |
| Aws Sqs | v1.0.0 | cloud | 0 | 3 | Valid |
| Airtable | v1.0.0 | productivity | 0 | 3 | Valid |
| Yepcode Sandbox | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Azure Mcp | v1.0.0 | cloud | 0 | 3 | Valid |
| Cypress | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Base64 | v1.0.0 | utility | 0 | 2 | Valid |
| Doppler | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Puppeteer Screenshot | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Dependabot | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Segment | v1.0.0 | analytics | 0 | 3 | Valid |
| Docfork | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Crypto Hash | v1.0.0 | utility | 0 | 2 | Valid |
| Hackernews | v1.0.0 | search | 0 | 2 | Valid |
| Airbyte | v1.0.0 | analytics | 0 | 2 | Valid |
| Qr Code | v1.0.0 | utility | 0 | 2 | Valid |
| Esp Rainmaker | v1.0.0 | api | 0 | 2 | Valid |
| Tree Sitter | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Snowflake | v1.0.0 | database | 0 | 2 | Valid |
| Playwright | v1.0.0 | browser | 0 | 2 | Valid |
| Multimail | v1.0.0 | communication | 0 | 2 | Valid |
| Sanity | v1.0.0 | productivity | 0 | 3 | Valid |
| Forge Terminal | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Matrix | v1.0.0 | communication | 0 | 2 | Valid |
| Mlflow | v1.0.0 | ai | 0 | 3 | Valid |
| Patternfly | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Exchangerate | v1.0.0 | finance | 0 | 2 | Valid |
| Docker Compose | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Opsgenie | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Math | v1.0.0 | utility | 0 | 2 | Valid |
| Image Magick | v1.0.0 | media | 0 | 2 | Valid |
| Etherscan | v1.0.0 | finance | 0 | 3 | Valid |
| Mqtt | v1.0.0 | iot | 0 | 2 | Valid |
| Imap | v1.0.0 | communication | 0 | 2 | Valid |
| Apple Notes | v1.0.0 | productivity | 0 | 2 | Valid |
| Crisp | v1.0.0 | communication | 0 | 2 | Valid |
| Gcp | v1.0.0 | cloud | 0 | 2 | Valid |
| Calendar | v1.0.0 | productivity | 0 | 2 | Valid |
| Semgrep | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Confluence | v1.0.0 | productivity | 0 | 3 | Valid |
| Android Emulator | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Desktop Commander | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Drizzle | v1.0.0 | database | 0 | 2 | Valid |
| Imgur | v1.0.0 | media | 0 | 2 | Valid |
| Elastic Apm | v1.0.0 | analytics | 0 | 3 | Valid |
| Npm Audit | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Rabbitmq | v1.0.0 | cloud | 0 | 2 | Valid |
| Better Email | v1.0.0 | communication | 0 | 3 | Valid |
| Audiense Insights | v1.0.0 | analytics | 0 | 3 | Valid |
| Open Meteo | v1.0.0 | api | 0 | 2 | Valid |
| Nodit Blockchain | v1.0.0 | finance | 0 | 3 | Valid |
| Zoom | v1.0.0 | communication | 0 | 2 | Valid |
| Rag | v1.0.0 | ai | 0 | 2 | Valid |
| Adobe Creative | v1.0.0 | media | 0 | 2 | Valid |
| Snipcart | v1.0.0 | finance | 0 | 2 | Valid |
| Aws Bedrock | v1.0.0 | ai | 0 | 3 | Valid |
| Redshift | v1.0.0 | database | 0 | 3 | Valid |
| Contacts | v1.0.0 | productivity | 0 | 2 | Valid |
| Neo4j | v1.0.0 | database | 0 | 2 | Valid |
| Emoji | v1.0.0 | utility | 0 | 2 | Valid |
| Unicode | v1.0.0 | utility | 0 | 2 | Valid |
| Airwallex | v1.0.0 | finance | 0 | 3 | Valid |
| Courier | v1.0.0 | communication | 0 | 3 | Valid |
| Cheerio | v1.0.0 | search | 0 | 2 | Valid |
| Redis | v1.0.0 | database | 0 | 2 | Valid |
| Spaceflightnews | v1.0.0 | api | 0 | 2 | Valid |
| Woocommerce | v1.0.0 | finance | 0 | 2 | Valid |
| Ghost | v1.0.0 | productivity | 0 | 2 | Valid |
| Algolia | v1.0.0 | search | 0 | 3 | Valid |
| Basecamp | v1.0.0 | productivity | 0 | 2 | Valid |
| Readwise | v1.0.0 | productivity | 0 | 3 | Valid |
| Fal Ai | v1.0.0 | media | 0 | 3 | Valid |
| Vercel Ai Sdk | v1.0.0 | ai | 0 | 2 | Valid |
| Qdrant | v1.0.0 | database | 0 | 2 | Valid |
| Giphy | v1.0.0 | media | 0 | 3 | Valid |
| Wandb | v1.0.0 | ai | 0 | 3 | Valid |
| Mysql | v1.0.0 | database | 0 | 2 | Valid |
| Splunk | v1.0.0 | analytics | 0 | 2 | Valid |
| Shell | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Storybook | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Whois | v1.0.0 | utility | 0 | 2 | Valid |
| Langchain | v1.0.0 | ai | 0 | 2 | Valid |
| Tavily | v1.0.0 | search | 0 | 3 | Valid |
| Firebase | v1.0.0 | database | 0 | 2 | Valid |
| Mindsdb | v1.0.0 | ai | 0 | 3 | Valid |
| Faker | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Replicate | v1.0.0 | ai | 0 | 3 | Valid |
| Fauna | v1.0.0 | database | 0 | 2 | Valid |
| Comfyui | v1.0.0 | ai | 0 | 2 | Valid |
| Ffmpeg | v1.0.0 | media | 0 | 2 | Valid |
| Milvus | v1.0.0 | ai | 0 | 3 | Valid |
| Coinmarketcap | v1.0.0 | finance | 0 | 3 | Valid |
| Pexels | v1.0.0 | media | 0 | 3 | Valid |
| Wistia | v1.0.0 | media | 0 | 2 | Valid |
| Diff | v1.0.0 | utility | 0 | 2 | Valid |
| Figma | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Anilist | v1.0.0 | media | 0 | 2 | Valid |
| Zotero | v1.0.0 | productivity | 0 | 3 | Valid |
| Wolfram Alpha | v1.0.0 | api | 0 | 3 | Valid |
| Markdown | v1.0.0 | utility | 0 | 2 | Valid |
| Tavily Search | v1.0.0 | search | 0 | 3 | Valid |
| Renovate | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Prettier | v1.0.0 | dev-tools | 0 | 2 | Valid |
| 2slides | v1.0.0 | productivity | 0 | 2 | Valid |
| Speech To Text | v1.0.0 | ai | 0 | 2 | Valid |
| Npm Search | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Pandoc | v1.0.0 | utility | 0 | 2 | Valid |
| Kubernetes Strowk | v1.0.0 | cloud | 0 | 2 | Valid |
| Myinstants | v1.0.0 | media | 0 | 2 | Valid |
| v1.0.0 | communication | 0 | 2 | Valid | |
| Aws Ccapi | v1.0.0 | cloud | 0 | 3 | Valid |
| Anyscale | v1.0.0 | ai | 0 | 3 | Valid |
| Salesforce | v1.0.0 | productivity | 0 | 2 | Valid |
| Framer | v1.0.0 | productivity | 0 | 2 | Valid |
| Tailscale | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Netlify | v1.0.0 | cloud | 0 | 2 | Valid |
| Intercom | v1.0.0 | communication | 0 | 2 | Valid |
| Ner | v1.0.0 | ai | 0 | 2 | Valid |
| Macos | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Cockroachdb | v1.0.0 | database | 0 | 2 | Valid |
| Coda | v1.0.0 | productivity | 0 | 2 | Valid |
| Sns | v1.0.0 | communication | 0 | 3 | Valid |
| Linear | v1.0.0 | productivity | 0 | 3 | Valid |
| Sentry Official | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Duckdb | v1.0.0 | database | 0 | 2 | Valid |
| Dns Lookup | v1.0.0 | api | 0 | 2 | Valid |
| Git | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Microsoft Clarity | v1.0.0 | analytics | 0 | 3 | Valid |
| Gitlab Ci | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Jest | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Nile Database | v1.0.0 | database | 0 | 3 | Valid |
| Aws Cost Explorer | v1.0.0 | finance | 0 | 3 | Valid |
| Philips Hue | v1.0.0 | api | 0 | 3 | Valid |
| Hubspot | v1.0.0 | productivity | 0 | 3 | Valid |
| Apollo | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Plotly | v1.0.0 | analytics | 0 | 2 | Valid |
| Telegram | v1.0.0 | communication | 0 | 3 | Valid |
| Screenshot | v1.0.0 | browser | 0 | 2 | Valid |
| Brave Search | v1.0.0 | search | 0 | 3 | Valid |
| Hyperbrowser | v1.0.0 | search | 0 | 3 | Valid |
| Jupyter | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Aws Lambda Tool | v1.0.0 | cloud | 0 | 3 | Valid |
| Polygon Io | v1.0.0 | finance | 0 | 3 | Valid |
| Piston Code Exec | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Aws Support | v1.0.0 | cloud | 0 | 3 | Valid |
| Apache Pinot | v1.0.0 | database | 0 | 3 | Valid |
| Units | v1.0.0 | utility | 0 | 2 | Valid |
| Date Parser | v1.0.0 | utility | 0 | 2 | Valid |
| Chromatic | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Posthog | v1.0.0 | analytics | 0 | 3 | Valid |
| Prisma | v1.0.0 | database | 0 | 2 | Valid |
| Web Research | v1.0.0 | search | 0 | 2 | Valid |
| Uv Package Manager | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Github Copilot | v1.0.0 | ai | 0 | 2 | Valid |
| Csv | v1.0.0 | utility | 0 | 2 | Valid |
| Ast Grep | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Postgres | v1.0.0 | database | 0 | 2 | Valid |
| Image Analysis | v1.0.0 | media | 0 | 2 | Valid |
| Notion | v1.0.0 | productivity | 0 | 3 | Valid |
| Imgbb | v1.0.0 | media | 0 | 3 | Valid |
| Hotjar | v1.0.0 | analytics | 0 | 3 | Valid |
| Sharp | v1.0.0 | media | 0 | 2 | Valid |
| Shortcut | v1.0.0 | productivity | 0 | 2 | Valid |
| Pipedream | v1.0.0 | api | 0 | 3 | Valid |
| Cassandra | v1.0.0 | database | 0 | 3 | Valid |
| Serper | v1.0.0 | search | 0 | 3 | Valid |
| Wikipedia | v1.0.0 | search | 0 | 2 | Valid |
| Aqara Iot | v1.0.0 | api | 0 | 3 | Valid |
| Apache Doris | v1.0.0 | database | 0 | 3 | Valid |
| Codepen | v1.0.0 | dev-tools | 0 | 2 | Valid |
| v1.0.0 | communication | 0 | 2 | Valid | |
| Mcp Remote | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Aws Serverless | v1.0.0 | cloud | 0 | 3 | Valid |
| Youtube | v1.0.0 | media | 0 | 3 | Valid |
| Contentful | v1.0.0 | productivity | 0 | 3 | Valid |
| v1.0.0 | communication | 0 | 2 | Valid | |
| Hashing | v1.0.0 | utility | 0 | 2 | Valid |
| Just Prompt | v1.0.0 | ai | 0 | 2 | Valid |
| Aws Iac | v1.0.0 | cloud | 0 | 3 | Valid |
| Tailwindcss | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Grpc | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Aws Lambda | v1.0.0 | cloud | 0 | 3 | Valid |
| Slack Zencoder | v1.0.0 | communication | 0 | 3 | Valid |
| Codeinterpreter | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Codeql | v1.0.0 | dev-tools | 0 | 2 | Valid |
| v1.0.0 | communication | 0 | 2 | Valid | |
| Claude Concilium | v1.0.0 | ai | 0 | 2 | Valid |
| Aws Ecs | v1.0.0 | cloud | 0 | 3 | Valid |
| Uuid Generator | v1.0.0 | utility | 0 | 2 | Valid |
| Ip Geolocation | v1.0.0 | api | 0 | 2 | Valid |
| Arxiv | v1.0.0 | search | 0 | 2 | Valid |
| Bluesky | v1.0.0 | communication | 0 | 2 | Valid |
| Google Cloud Platform | v1.0.0 | cloud | 0 | 3 | Valid |
| Openai | v1.0.0 | ai | 0 | 3 | Valid |
| Tar | v1.0.0 | utility | 0 | 2 | Valid |
| Kafka | v1.0.0 | cloud | 0 | 2 | Valid |
| Scrapy | v1.0.0 | search | 0 | 2 | Valid |
| Sonarqube | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Aws Sns | v1.0.0 | cloud | 0 | 3 | Valid |
| Graphlit | v1.0.0 | ai | 0 | 3 | Valid |
| Asana | v1.0.0 | productivity | 0 | 3 | Valid |
| Azure Openai | v1.0.0 | ai | 0 | 3 | Valid |
| Imgix | v1.0.0 | media | 0 | 2 | Valid |
| Yahoo Finance | v1.0.0 | finance | 0 | 2 | Valid |
| Apache Kafka | v1.0.0 | api | 0 | 3 | Valid |
| Astronomy Oracle | v1.0.0 | api | 0 | 2 | Valid |
| Aws Kb Retrieval | v1.0.0 | cloud | 0 | 3 | Valid |
| Iterm | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Sendgrid | v1.0.0 | communication | 0 | 3 | Valid |
| Pagespeed | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Todoist | v1.0.0 | productivity | 0 | 3 | Valid |
| Railway | v1.0.0 | cloud | 0 | 2 | Valid |
| Vercel Blob | v1.0.0 | cloud | 0 | 3 | Valid |
| Supabase | v1.0.0 | database | 0 | 3 | Valid |
| Plaid | v1.0.0 | finance | 0 | 3 | Valid |
| Ios Simulator | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Duckduckgo | v1.0.0 | search | 0 | 2 | Valid |
| Dynamodb | v1.0.0 | database | 0 | 3 | Valid |
| Sqs | v1.0.0 | cloud | 0 | 3 | Valid |
| Google Drive | v1.0.0 | productivity | 0 | 2 | Valid |
| Cohere | v1.0.0 | ai | 0 | 3 | Valid |
| Adfin | v1.0.0 | finance | 0 | 3 | Valid |
| Everything | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Uptimerobot | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Github Gist | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Paypal | v1.0.0 | finance | 0 | 3 | Valid |
| Logseq | v1.0.0 | productivity | 0 | 2 | Valid |
| Minio | v1.0.0 | cloud | 0 | 3 | Valid |
| Fly Io | v1.0.0 | cloud | 0 | 2 | Valid |
| Auth0 | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Bear Notes | v1.0.0 | productivity | 0 | 2 | Valid |
| Excel | v1.0.0 | utility | 0 | 2 | Valid |
| Influxdb | v1.0.0 | database | 0 | 2 | Valid |
| Selenium | v1.0.0 | browser | 0 | 2 | Valid |
| Postman | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Raycast | v1.0.0 | productivity | 0 | 2 | Valid |
| Spotify | v1.0.0 | media | 0 | 3 | Valid |
| Consul | v1.0.0 | cloud | 0 | 2 | Valid |
| Cloudflare | v1.0.0 | cloud | 0 | 3 | Valid |
| Pandas | v1.0.0 | analytics | 0 | 2 | Valid |
| Mux | v1.0.0 | media | 0 | 3 | Valid |
| Aws Cloudformation | v1.0.0 | cloud | 0 | 3 | Valid |
| Alpha Vantage | v1.0.0 | finance | 0 | 3 | Valid |
| Podcast | v1.0.0 | media | 0 | 2 | Valid |
| Ip Api | v1.0.0 | api | 0 | 2 | Valid |
| Waystation | v1.0.0 | productivity | 0 | 2 | Valid |
| Drawio | v1.0.0 | productivity | 0 | 2 | Valid |
| Plantuml | v1.0.0 | utility | 0 | 2 | Valid |
| Make Integromat | v1.0.0 | productivity | 0 | 3 | Valid |
| Aws Mcp Proxy | v1.0.0 | cloud | 0 | 2 | Valid |
| Brightdata | v1.0.0 | search | 0 | 2 | Valid |
| Eslint | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Freshdesk | v1.0.0 | communication | 0 | 2 | Valid |
| Elasticsearch | v1.0.0 | database | 0 | 2 | Valid |
| Kv Cloudflare | v1.0.0 | database | 0 | 3 | Valid |
| Neon | v1.0.0 | database | 0 | 2 | Valid |
| Prefect | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Wordpress | v1.0.0 | productivity | 0 | 2 | Valid |
| Bitwarden | v1.0.0 | utility | 0 | 2 | Valid |
| Redis Cloud | v1.0.0 | database | 0 | 3 | Valid |
| Profullstack | v1.0.0 | dev-tools | 0 | 2 | Valid |
| v1.0.0 | communication | 0 | 3 | Valid | |
| Todoist Ext | v1.0.0 | productivity | 0 | 3 | Valid |
| Bcrypt | v1.0.0 | utility | 0 | 2 | Valid |
| Random User | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Lorem Ipsum | v1.0.0 | utility | 0 | 2 | Valid |
| Aws Dynamodb | v1.0.0 | cloud | 0 | 3 | Valid |
| Huggingface | v1.0.0 | ai | 0 | 3 | Valid |
| Sitbon Magg | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Console Automation | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Turso | v1.0.0 | database | 0 | 2 | Valid |
| Facebook Ads | v1.0.0 | analytics | 0 | 2 | Valid |
| Voyage Ai | v1.0.0 | ai | 0 | 3 | Valid |
| Alphavantage | v1.0.0 | finance | 0 | 3 | Valid |
| Aws S3 | v1.0.0 | cloud | 0 | 3 | Valid |
| Youtube Transcript | v1.0.0 | media | 0 | 2 | Valid |
| Dns | v1.0.0 | utility | 0 | 2 | Valid |
| Moralis Web3 | v1.0.0 | finance | 0 | 3 | Valid |
| Cloudwatch | v1.0.0 | analytics | 0 | 3 | Valid |
| Zendesk | v1.0.0 | communication | 0 | 2 | Valid |
| Time | v1.0.0 | utility | 0 | 2 | Valid |
| S3 Advanced | v1.0.0 | cloud | 0 | 3 | Valid |
| Snyk | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Websocket | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Mongodb | v1.0.0 | database | 0 | 2 | Valid |
| v1.0.0 | communication | 0 | 3 | Valid | |
| Typeform | v1.0.0 | api | 0 | 3 | Valid |
| Planetscale | v1.0.0 | database | 0 | 2 | Valid |
| Puppeteer | v1.0.0 | browser | 0 | 2 | Valid |
| Vscode | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Supabase Community | v1.0.0 | database | 0 | 3 | Valid |
| Color Palette | v1.0.0 | utility | 0 | 2 | Valid |
| Openweather | v1.0.0 | api | 0 | 3 | Valid |
| Personalization Mcp | v1.0.0 | api | 0 | 2 | Valid |
| Teams | v1.0.0 | communication | 0 | 3 | Valid |
| Coingecko | v1.0.0 | finance | 0 | 2 | Valid |
| Timezone | v1.0.0 | utility | 0 | 2 | Valid |
| Composio | v1.0.0 | api | 0 | 3 | Valid |
| Fullstory | v1.0.0 | analytics | 0 | 3 | Valid |
| Webflow | v1.0.0 | productivity | 0 | 2 | Valid |
| Text To Speech | v1.0.0 | ai | 0 | 2 | Valid |
| Calendly | v1.0.0 | productivity | 0 | 2 | Valid |
| Github Actions | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Timescaledb | v1.0.0 | database | 0 | 2 | Valid |
| Soundcloud | v1.0.0 | media | 0 | 2 | Valid |
| Markitdown | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Openapi | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Jenkins | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Openstreetmap | v1.0.0 | api | 0 | 2 | Valid |
| Discord | v1.0.0 | communication | 0 | 3 | Valid |
| Alpaca | v1.0.0 | finance | 0 | 3 | Valid |
| Curl | v1.0.0 | api | 0 | 2 | Valid |
| Restcountries | v1.0.0 | api | 0 | 2 | Valid |
| Anthropic | v1.0.0 | ai | 0 | 3 | Valid |
| Clickup | v1.0.0 | productivity | 0 | 2 | Valid |
| Aws Finch | v1.0.0 | cloud | 0 | 3 | Valid |
| Npm Helper | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Tui Mcp | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Terraform | v1.0.0 | cloud | 0 | 2 | Valid |
| Microsoft Teams | v1.0.0 | communication | 0 | 2 | Valid |
| Nats | v1.0.0 | cloud | 0 | 2 | Valid |
| Mastodon | v1.0.0 | communication | 0 | 2 | Valid |
| Aws Eks | v1.0.0 | cloud | 0 | 3 | Valid |
| Context7 | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Cron | v1.0.0 | utility | 0 | 2 | Valid |
| Kibana | v1.0.0 | analytics | 0 | 2 | Valid |
| Stackblitz | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Sequelize | v1.0.0 | database | 0 | 2 | Valid |
| Wappalyzer | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Readability | v1.0.0 | utility | 0 | 2 | Valid |
| Google News | v1.0.0 | search | 0 | 2 | Valid |
| Dbt | v1.0.0 | analytics | 0 | 2 | Valid |
| Vercel Kv | v1.0.0 | database | 0 | 3 | Valid |
| Filesystem | v1.0.0 | filesystem | 0 | 2 | Valid |
| Weatherxm | v1.0.0 | api | 0 | 3 | Valid |
| Lighthouse | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Azure | v1.0.0 | cloud | 0 | 2 | Valid |
| Jwt | v1.0.0 | utility | 0 | 2 | Valid |
| Weather | v1.0.0 | api | 0 | 3 | Valid |
| Anthropic Api | v1.0.0 | ai | 0 | 3 | Valid |
| Bitbucket | v1.0.0 | dev-tools | 0 | 2 | Valid |
| 1mcp Agent | v1.0.0 | dev-tools | 0 | 2 | Valid |
| Deepl | v1.0.0 | utility | 0 | 3 | Valid |
| Latex | v1.0.0 | utility | 0 | 2 | Valid |
| Ollama | v1.0.0 | ai | 0 | 2 | Valid |
| Couchdb | v1.0.0 | database | 0 | 3 | Valid |
| Hashicorp Vault | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Stripe | v1.0.0 | finance | 0 | 3 | Valid |
| Kaspersky Opentip | v1.0.0 | dev-tools | 0 | 3 | Valid |
| Taskmanager | v1.0.0 | productivity | 0 | 2 | Valid |
| Amplitude | v1.0.0 | analytics | 0 | 3 | Valid |
| Fivetran | v1.0.0 | analytics | 0 | 2 | Valid |
| Resend Email | v1.0.0 | communication | 0 | 3 | Valid |
| Apify | v1.0.0 | search | 0 | 3 | Valid |
| Alfred | v1.0.0 | productivity | 0 | 2 | Valid |
| Shopify | v1.0.0 | finance | 0 | 3 | Valid |
| E2b | v0.0.0 | code-execution | 0 | 0 | Expired |
| Firecrawl | v0.0.0 | web-scraping | 0 | 0 | Expired |
Enterprise Compliance
ddot's security model maps directly to industry compliance frameworks:
CMMC Level 1
We started with the Department of Defense's security standards. ddot's architecture meets all 14 CMMC Level 1 requirements. Not 13 out of 14. All 14. Audit chain, access control, identification, media protection, physical protection, system integrity — covered.
14/14SOC 2 Type II
Hash-chained audit trail, cryptographic verification, and least-privilege capability model map to SOC 2 trust principles.
ReadyNIST 800-88
Built-in data purge command (ddot purge) with NIST 800-88 compliant media sanitization for audit and memory data.
Built-inStart Securing Your Agents Today
Open source. Self-hosted. No data leaves your machine. Install ddot and secure your MCP stack in minutes.