Home › Categories › Security

Security

190 MCP servers and agent skills in the Security category, ranked by quality score.

Filters (1 active)
86 results (<1ms) · data updated 2026-08-14

Results

knowledgepa3/gia-mcp-server C MCP Server Active

knowledgepa3/gia-mcp-server

Enterprise AI governance layer with 29 tools: MAI decision classification (Mandatory/Advisory/Informational), hash-chained forensic audit trails, human-in-the-loop gates, compliance mapping (NIST AI RMF, EU AI Act, ISO 42001), governed memory packs, and site reliability tools.

★ 3 TypeScript Updated 14d ago Score 56 Security

I4cTime/quantum_ring C MCP Server Active

I4cTime/quantum_ring

Quantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation.

★ 3 TypeScript Updated 4d ago Score 56 Security

RoscoNL/intodns-mcp-server C MCP Server Active

RoscoNL/intodns-mcp-server

Free DNS and email security scanner for AI assistants. DNS, SPF, DKIM, DMARC, DNSSEC, MTA-STS, BIMI, TLS/STARTTLS, FCrDNS, CAA, TLSA/DANE, blacklist and full-deliverability checks, plus security-header/CSP analysis and bookmarkable report snapshots, via the IntoDNS.ai API. No signup or API key. `npx intodns-mcp`

★ 2 TypeScript Updated 27d ago Score 55 Security

beeswaxpat/chronoverify-mcp C MCP Server Active

beeswaxpat/chronoverify-mcp

Verify a photo's capture time and provenance before an agent trusts it: cryptographic C2PA Content Credentials validation against the official trust lists, EXIF and XMP consistency checks, and classical pixel forensics fused into one typed verdict with a 0 to 100 confidence. Free keyless tier, opt-in shareable verdict permalinks, and key-gated signed PDF audit reports. Provenance validation, not a

★ 2 JavaScript Updated 7d ago Score 55 Security

airblackbox/air-blackbox-mcp C MCP Server Active

airblackbox/air-blackbox-mcp

EU AI Act compliance scanner for Python AI agents. Scans, analyzes, and remediates LangChain/CrewAI/AutoGen/OpenAI code across 6 articles with 10 tools including prompt injection detection, risk classification, and trust layer integration. The only MCP compliance server that generates fix code, not just findings.

★ 2 Python Updated 8d ago Score 55 Security

Buggy1111/anonymize-mcp C MCP Server Active

Buggy1111/anonymize-mcp

Anonymize PII and redact text for GDPR across Czech and 35+ languages. Real NLP via ÚFAL/LINDAT (MasKIT + NameTag NER, not just regex), 80+ PII patterns, plus morphology, translation, and spellcheck. Czech-first, non-commercial. Install: `pip install anonymize-mcp`.

★ 2 Python Updated 2d ago Score 55 Security

Declade/lucairn-sdks C MCP Server Active

Declade/lucairn-sdks

Privacy-preserving AI gateway. Sanitises PII (German + English; Microsoft Presidio + custom recognisers) before prompts reach Anthropic / OpenAI / your LLM, then emits a signed cryptographic certificate per call (Ed25519 + RFC 3161 timestamp + Sigstore Rekor anchoring). EU GDPR + AI Act ready. Free tier 500 calls/month, BYOK. Install: `npx -y @lucairn/mcp-server`. Docs: https://lucairn.eu/develope

★ 2 TypeScript Updated 13d ago Score 55 Security

zw008/VMware-Harden C MCP Server Active

zw008/VMware-Harden

VMware vSphere compliance and hardening — read-only baseline scanning plus drift detection across CIS, vSphere SCG, China DJCP 2.0, and PCI-DSS frameworks. 6 read-only tools with LLM-powered remediation suggestions (apply-side gated through vmware-pilot approval workflow).

★ 2 Python Updated yesterday Score 55 Security

WRG-11/wrg-sigma-rules C MCP Server Active

WRG-11/wrg-sigma-rules

Sigma detection rule writing, validation, and conversion (Splunk/Elastic/Kibana/Wazuh) via 3 MCP tools (`draft_rule`, `validate_rule`, `convert_rule`) backed by a 61-rule production corpus across 11 MITRE ATT&CK tactic categories. Standalone server + Claude Code plugin distribution.

★ 2 Python Updated 2d ago Score 55 Security

calllint/calllint C MCP Server Active

calllint/calllint

Pre-flight security linter for MCP servers, agent tools, and skills. Scans a config *before* it runs — offline, deterministic, evidence-backed — and returns SAFE / REVIEW / BLOCK / UNKNOWN verdicts without executing the server it judges. CLI (`npx calllint scan`), MCP server (`npx calllint-mcp`), SARIF + CI gate. UNKNOWN is never SAFE.

★ 2 TypeScript Updated today Score 55 Security

shieldly-io/mcp C MCP Server Official Active

shieldly-io/mcp

Official [Shieldly](https://www.shieldly.io) MCP server: `analyze_iam_policy` and `analyze_cloudformation_template` tools flag AWS IAM privilege-escalation paths, wildcards, and over-permissive access. Free demo mode, no signup or API key needed. `npx -y @shieldly/mcp`.

★ 0 JavaScript Updated 26d ago Score 55 Security

trustscoreagent/trustscoreagent C MCP Server Official Active

trustscoreagent/trustscoreagent

Check the reputation of an AI microservice or public API *before* calling it, and submit ratings afterward — from a free, open trust registry (no account or API key). Scores combine Bayesian reputation and EigenTrust, strengthened by cryptographically signed service receipts and a Merkle audit trail. Install: `npx -y @trustscoreagent/mcp-server`.

★ 0 C# Updated today Score 55 Security

chasdaddy/basescope C MCP Server Active

chasdaddy/basescope

The read-only safety layer for onchain AI agents. 13 read-only tools on Base + EVM: token/contract safety (honeypot & rug-pull checks cross-referenced across GoPlus + honeypot.is), risky-approval detection, verified-source lookup, balances, ENS + Basenames, gas, and prices. No private keys, no required API keys. `npx -y basescope`

★ 1 TypeScript Updated 25d ago Score 53 Security

askalf/truecopy C MCP Server Active

askalf/truecopy

Supply-chain gate for agent skills and MCP servers — scans tool definitions for poisoned instructions, pins vetted servers by content hash in a committed lock, and verifies drift in CI; the bundled truecopy-mcp proxy exposes only pinned, unmodified tools from a live server.

★ 1 JavaScript Updated today Score 53 Security

Fronesis-Labs/dcl-webhook C MCP Server Active

Fronesis-Labs/dcl-webhook

Deterministic AI audit layer: evaluates LLM/agent outputs against configurable policies (jailbreak, safety, quality, wallet, trade, MEV compliance) and writes every verdict to a tamper-evident SHA-256 hash chain — metadata only, never raw content. 17 tools including a full crypto-trading compliance suite. Pay-per-call via x402 (USDC on Base), from $0.01. `mcp.fronesislabs.com/mcp`

★ 1 Python Updated today Score 53 Security

AgentValet/AgentValet C MCP Server Active

AgentValet/AgentValet

Identity and credential governance broker for MCP servers. Issues scoped, short-lived credentials per agent to stop credential inheritance. Audit log, human approval gates, AIMS-aligned.

★ 1 TypeScript Updated yesterday Score 53 Security

infai-tech/vulnfeed-mcp C MCP Server Active

infai-tech/vulnfeed-mcp

Dependency vulnerability scanner with EPSS exploit probability scoring. Scans lockfiles (npm, pip, Go, Cargo, Ruby, Composer, Gradle, NuGet, Mix), prioritizes by real-world exploit likelihood, recommends fix versions. 9 MCP tools for scanning, monitoring, and alerting. Free tier + x402 micropayments. `pip install vulnfeed-mcp`

★ 1 Python Updated 22d ago Score 53 Security

joergmichno/clawguard-mcp C MCP Server Active

joergmichno/clawguard-mcp

Security scanner for AI agents that detects prompt injections using 42+ regex patterns

★ 1 Python Updated 24d ago Score 53 Security

mrz1880/mcp-keycloak-admin C MCP Server Active

mrz1880/mcp-keycloak-admin

Administer Keycloak through its Admin REST API — users, roles, clients, groups, identity providers, federation and events. Safe by default: read-only mode, realm allow-list, and confirmation for destructive actions. `npx -y mcp-keycloak-admin`

★ 1 TypeScript Updated yesterday Score 53 Security

Pentagonal-ai/pentagonal C MCP Server Active

Pentagonal-ai/pentagonal

AI-powered smart contract security forge with 8-agent adversarial pen test. Generate, audit, fix, and compile contracts across 8 chains (Ethereum, Solana, Polygon, Base, Arbitrum, Optimism, BSC, Avalanche). Token intelligence with honeypot detection. x402 USDC payments for autonomous agents.

★ 1 TypeScript Updated 17d ago Score 53 Security

layervai/qurl-mcp C MCP Server Active

layervai/qurl-mcp

Mint, resolve, audit, and rotate expiring scope-limited access links (qURLs) for AI agents — secure URL gateway for the qURL API. 9 tools (create / resolve / list / get / delete / extend / update / mint-link / batch-create), 3 resources, 3 guided prompts. stdio transport, OIDC-attested npm provenance.

★ 4 TypeScript Updated yesterday Score 52 Security

agentgraph-co/agentgraph C MCP Server Active

agentgraph-co/agentgraph

Trust verification and security scanning for AI agents. Checks security posture of third-party MCP servers and tools with signed attestations (Ed25519/JWS) before interaction.

★ 3 Python Updated today Score 51 Security

datanexusmcp/mcp-server C MCP Server Active

datanexusmcp/mcp-server

55 tools for verified public data lookups — CVE/SBOM security audits, licence compliance, patents, federal contracts, NPI provider lookups, nonprofit 990 filings, and domain intelligence. No API key required.

★ 3 Python Updated 14d ago Score 51 Security

MoltyCel/moltrust-mcp-server C MCP Server Active

MoltyCel/moltrust-mcp-server

Trust infrastructure for AI agents — register DIDs, verify identities, query reputation scores, rate agents, manage W3C Verifiable Credentials, and handle USDC credit deposits on Base.

★ 3 Python Updated 16d ago Score 51 Security

shyshlakov/pci-dss-mcp C MCP Server Active

shyshlakov/pci-dss-mcp

PCI DSS v4.0.1 static-analysis MCP server for Go payment codebases. 12 scanners detect PAN/CVV exposure, weak crypto, missing audit logs, vulnerable deps, TLS misconfig, auth weaknesses, plus CycloneDX 1.6 SBOM generation - each finding mapped to the exact PCI requirement. AI-assisted triage via triage_findings. Keyless-signed multi-arch Docker image on ghcr.io.

★ 3 Go Updated 18d ago Score 51 Security

honeylabshq/honeylabs-mcp C MCP Server Active

honeylabshq/honeylabs-mcp

Honeypot threat intelligence for AI agents: 90 days of probe data from a sensor network for IP reputation, scanner classification, CVE probing trends, and JA4/JA4H/HASSH fingerprints. Remote MCP, free tier.

★ 2 Python Updated 4d ago Score 50 Security

moxno/privacyscrubber-mcp C MCP Server Active

moxno/privacyscrubber-mcp

Zero-trust local PII and secrets masking server for Cursor, Windsurf, and Claude Desktop. `npx pii-masking-run`

★ 0 JavaScript Updated 11d ago Score 50 Security

jamesdfinance-dev/lazaretto-mcp C MCP Server Active

jamesdfinance-dev/lazaretto-mcp

Check whether anything you depend on is known malware, before an agent installs it. `check_lockfile` takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. `scan_artifact` adds deterministic b

★ 0 JavaScript Updated yesterday Score 50 Security

alexar76/aimarket-oracle-gateway C MCP Server Active

alexar76/aimarket-oracle-gateway

Verifiable oracle MCP server**: Platon VRF (`get_random`), Chronos VDF (`compute_vdf` / `verify_vdf`), LUMEN reputation (`get_reputation_scores`) as agent tools. Pay-per-call over AIMarket Hub; every result independently verifiable. stdio · Python · [Glama](https://glama.ai/mcp/servers/alexar76/aimarket-oracle-gateway).

★ 0 Python Updated yesterday Score 50 Security

corewebvitals/state-of-cwv-mcp C MCP Server Active

corewebvitals/state-of-cwv-mcp

Free remote MCP for Core Web Vitals metrics by CMS, CDN, and framework (Chrome field data + multi-site crawl). No auth. Endpoint: `https://www.corewebvitals.io/api/state-of-cwv/mcp`.

★ 0 JavaScript Updated 28d ago Score 50 Security

rad-security/mcp-server D MCP Server Active

rad-security/mcp-server

MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for querying the Rad Security API and retrieving security findings, reports, runtime data and many more.

★ 6 TypeScript Updated 3d ago Score 48 Security

astafford8488/agentaegis-mcp D MCP Server Active

astafford8488/agentaegis-mcp

Security & trust layer for AI agents. Scan an MCP server or skill *before* you install it (`scan_mcp_plugin`, `scan_skill`) — flags exfiltration, prompt-injection sinks, dangerous capabilities, install hooks and obfuscation → PROCEED/CAUTION/BLOCK. Plus `vet_endpoint` (endpoint safety verdict before an agent calls or pays it) and 25 more tools: vuln scans, threat intel, compliance (SOC 2/ISO 27001

★ 1 TypeScript Updated 2d ago Score 48 Security

gautam-u/sieve-mcp D MCP Server Active

gautam-u/sieve-mcp

Local AI chat history secret scanner for macOS. Finds API keys and secrets leaked into Claude Code, Cursor, Copilot Chat, Cline, Codex, Gemini CLI, and other AI tool transcripts. 9 MCP tools: findings list with redacted previews, boolean secret detection (`sieve_check_text`), placeholder-only redaction (`sieve_redact_text` returns `sieve://project/key`, never raw values), vault-backed command exec

★ 1 JavaScript Updated 11d ago Score 48 Security

jonnybottles/patch-tuesday-mcp D MCP Server Active

jonnybottles/patch-tuesday-mcp

Microsoft Patch Tuesday triage from the official MSRC Security Update Guide. Monthly rollups, CVE/KB lookups, supersedence chains, product watchlists, and urgency-ranked results enriched with EPSS scores and the CISA KEV catalog. No API keys; also available as a free hosted remote endpoint. `uvx patch-tuesday-mcp`

★ 4 Python Updated yesterday Score 47 Security

Kjopstad-IT/rqwstr D MCP Server Active

Kjopstad-IT/rqwstr-mcp

AI-native HTTP security testing toolkit: 17 tools (send, intruder, race, chain, oob) with low-level control over HTTP/1.1 + HTTP/2 (raw framing, connection pinning).

★ 0 Dockerfile Updated 8d ago Score 45 Security

OksigeniaSL/checker-mcp D MCP Server Active

OksigeniaSL/checker-mcp

Domain security & privacy checker: 17 live checks (SPF, DMARC, DKIM, DNSSEC, TLS, CAA, security headers) scored 0-100 with remediation. Local-first, zero telemetry. In the official MCP Registry as `com.oksigenia/checker-mcp`; npm `@oksigenia/checker-mcp`.

★ 0 TypeScript Updated 22d ago Score 45 Security

mcpindex-ai/mcp-server-mcpindex D MCP Server Active

mcpindex-ai/mcp-server-mcpindex

Find MCP servers by natural-language task and get advisory trust screens (check_tool_trust, assess_server) before you connect. The directory client for mcpindex.ai; advisory, not a safety verdict.

★ 0 JavaScript Updated 15d ago Score 45 Security

teodorofodocrispin-cmyk/trustboost-pii-sanitizer D MCP Server Active

teodorofodocrispin-cmyk/trustboost-api

PII sanitization layer for autonomous AI agent pipelines. Detects and redacts emails, phone numbers, national IDs, private keys, and financial data before text reaches LLMs. Supports EN, ES (LATAM), PT (BR/PT), DE, JA. Solana-native payments via Helius oracle.

★ 2 Python Updated 25d ago Score 40 Security