Home › Categories › Security

Security

190 MCP servers and agent skills in the Security category, ranked by quality score.

Filters (2 active)
27 results (<1ms) · data updated 2026-08-14

Results

BurtTheCoder/mcp-virustotal B MCP Server Maintained

BurtTheCoder/mcp-virustotal

MCP server for querying the VirusTotal API. This server provides tools for scanning URLs, analyzing file hashes, and retrieving IP address reports.

★ 143 TypeScript Updated 2mo ago Score 65 Security

jnMetaCode/shellward C MCP Server Maintained

jnMetaCode/shellward

AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.

★ 131 TypeScript Updated 1mo ago Score 64 Security

tomjwxf/scopeblind-gateway C MCP Server Maintained

tomjwxf/scopeblind-gateway

Security gateway that wraps any MCP server with per-tool policies, approval gates, and optional Ed25519-signed receipts. Shadow mode logs every tool call; enforce mode blocks, rate-limits, or requires approval.

★ 9 TypeScript Updated 1mo ago Score 53 Security

takleb3rry/zitadel-mcp C MCP Server Maintained

takleb3rry/zitadel-mcp

MCP server for Zitadel identity management — manage users, projects, OIDC apps, roles, and service accounts through natural language.

★ 9 TypeScript Updated 1mo ago Score 53 Security

piiiico/proof-of-commitment C MCP Server Maintained

piiiico/proof-of-commitment

Supply chain risk scoring for npm, PyPI, Cargo, and Go packages. 9 tools for behavioral trust signals — publisher depth, release consistency, maintenance patterns. Both axios and node-ipc scored CRITICAL before they got attacked. Free CLI, CI gate, REST API. No API key required.

★ 7 TypeScript Updated 1mo ago Score 52 Security

ScopeBlind/verify-mcp C MCP Server Maintained

ScopeBlind/verify-mcp

Offline verification of signed artifacts -- receipts, manifests, audit bundles. Ed25519 + JCS. No accounts, no API calls. Apache-2.0.

★ 5 JavaScript Updated 1mo ago Score 51 Security

behrensd/mcp-firewall C MCP Server Maintained

behrensd/mcp-firewall

Deterministic security proxy (iptables for MCP) that intercepts tool calls, enforces YAML policies, scans for secret leakage, and logs everything. No AI, no cloud.

★ 4 TypeScript Updated 1mo ago Score 50 Security

toan203/osv-ui C MCP Server Maintained

toan203/osv-ui

Visual CVE audit dashboard for npm, Python, Go, and Rust. Scan from Claude/Cursor, opens a browser UI for human review (human-in-the-loop), applies fixes with explicit confirmation. Powered by OSV.dev.

★ 4 HTML Updated 2mo ago Score 50 Security

rudraneel93/mcp-guardian D MCP Server Maintained

rudraneel93/mcp-guardian

Security and governance proxy for MCP infrastructure. Enforces YAML-configurable policies (blocklists, rate limits, token budgets), tracks real token costs via tiktoken, monitors server health with live JSON-RPC probes. Features include OAuth 2.1/OIDC with RBAC, web dashboard with Prometheus metrics, payload normalization against encoding bypasses, semantic shell AST analysis, mTLS zero-trust netw

★ 3 TypeScript Updated 2mo ago Score 49 Security

inkog-io/inkog-mcp D MCP Server Maintained

inkog-io/inkog-mcp

AI agent security scanner. Audits MCP servers for vulnerabilities, detects prompt injection, infinite loops, token bombing, and missing human oversight across 20+ frameworks. Maps findings to EU AI Act, OWASP LLM Top 10.

★ 3 TypeScript Updated 2mo ago Score 49 Security

eliottreich/taskbounty-check D MCP Server Maintained

eliottreich/taskbounty-check

Local-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes `scan_repo`, `explain_finding`, and `generate_fix_plan` to MCP clients; reads only allowlisted workflow and update configuration, modifies nothing, makes no outbound requests by default, and has zero runtime dependencies. Run with `npx -y taskbounty-check@0.1.6 mcp`.

★ 2 JavaScript Updated 1mo ago Score 48 Security

ppcvote/misp-mcp-server D MCP Server Maintained

ppcvote/misp-mcp-server

MISP (Malware Information Sharing Platform) MCP server with built-in prompt injection defense via [prompt-defense-audit](https://github.com/ppcvote/prompt-defense-audit). 8 read-only threat-intel tools (events, attributes, search, tags, feeds, galaxies). Scans every MISP response for adversarial seeding before returning to LLM. Tracks [MISP/MISP#10745](https://github.com/MISP/MISP/issues/10745). M

★ 2 TypeScript Updated 2mo ago Score 48 Security

Chronolapse411/sicarius-guard D MCP Server Maintained

Chronolapse411/sicarius-guard

Solana token safety oracle for AI agents and trading bots. Byte-level SPL mint analysis, honeypot detection, freeze/mint authority checks, Birdeye market enrichment, and composite risk scoring. Deployed on Google Cloud Run.

★ 2 TypeScript Updated 2mo ago Score 48 Security

qinisolabs/qiniso D MCP Server Maintained

qinisolabs/qiniso

56 deterministic fact-checkers in one server (IBAN, VAT, VIN, GTIN/barcodes, national & tax IDs, crypto addresses, phone, dates, holidays) — verify the structured facts an agent emits against checksums and curated data.

★ 1 TypeScript Updated 1mo ago Score 46 Security

vinaybhosle/agentstamp D MCP Server Maintained

vinaybhosle/agentstamp

Trust intelligence for AI agents — identity stamps, reputation scoring (0-100), registry, forensic audit trails, and A2A passports via x402 micropayments.

★ 1 JavaScript Updated 1mo ago Score 46 Security

Perufitlife/web-exposure-mcp D MCP Server Maintained

Perufitlife/web-exposure-mcp

Points an AI agent at a live URL and confirms publicly-served secret files by fetching the bytes — exposed `.git`, `.env`, JS source maps, backup/SQL dumps, directory listing, and dotfiles. Zero dependencies, read-only.

★ 1 JavaScript Updated 1mo ago Score 46 Security

chrbailey/promptspeak-mcp-server D MCP Server Maintained

chrbailey/promptspeak-mcp-server

Pre-execution governance for AI agents. Intercepts and validates every agent tool call through an 8-stage pipeline before execution — risk classification, behavioral drift detection, hold queue for dangerous operations, and complete audit trail. 45 tools, 658 tests.

★ 1 TypeScript Updated 1mo ago Score 46 Security

BeBraveBeKind/mcpskills-server D MCP Server Maintained

BeBraveBeKind/mcpskills-server

Pre-install trust layer for MCP servers, AI skills, and npm packages. Scores any repo or package across 15 signals (incl. OSV/KEV/EPSS vulnerability intelligence) with safety scanning for prompt injection, credential theft, and supply-chain risk; the `auto_gate` tool returns a go/no-go install decision. Listed in the official MCP Registry as `io.mcpskills/server`. npm: `@mcpskillsio/server`. https

★ 1 JavaScript Updated 2mo ago Score 46 Security

jamjet-labs/jamjet-policy D MCP Server Maintained

jamjet-labs/jamjet-policy/packages/mcp-shim

MCP stdio interceptor (`@jamjet/mcp-shim`) that applies one YAML policy file (block / require_approval / audit / budget cap) to `tools/call` requests before they reach the real MCP server. The same policy also runs in Claude Code PreToolUse hooks (`@jamjet/claude-code-hook`), OpenAI Agents SDK guardrails (`@jamjet/openai-guardrail`), and JamJet's Python/TS SDKs — `jamjet audit show` tails every de

★ 2 TypeScript Updated 1mo ago Score 43 Security

KOVY/agentforge-trust-mcp D MCP Server Maintained

KOVY/agentforge-trust-mcp

Query the AgentForge Trust Score (0-100 across five dimensions: security, code health, behavioral audit, community trust, EU compliance) for any MCP server before connecting. Exposes `check_trust`, `evaluate_policy`, `list_trusted`, and `recommend` tools. 3,600+ servers audited, free public API.

★ 1 TypeScript Updated 2mo ago Score 41 Security

Bichev/agentradar-mcp D MCP Server Maintained

Bichev/agentradar-mcp

On-chain trust oracle for the ERC-8004 + x402 agent economy. 18 tools for verifying AI agents: 6-signal composite trust scoring (0-100), 272-wallet scam database, ERC-8004 identity lookup, EAS attestations on Base mainnet. x402-payable. Free `get_score` / `check_scam`. Live at [vvpro.ai](https://vvpro.ai) · npm [`@agentradar/mcp`](https://www.npmjs.com/package/@agentradar/mcp).

★ 1 TypeScript Updated 1mo ago Score 41 Security

rev2ret/SecureAudit-MCP D MCP Server Maintained

rev2ret/SecureAudit-MCP

Model Context Protocol (MCP) server for static C/C++ memory-safety scanning and compiled PE/ELF binary protections auditing (ASLR, DEP/NX, SafeSEH, PIE) with secure templates remediation.

★ 1 JavaScript Updated 2mo ago Score 41 Security

uchit/mcp-regulated-ai-compliance D MCP Server Maintained

uchit/mcp-regulated-ai-compliance

Regulated-industry AI compliance knowledge as MCP. 6 tools (lookup_control · classify_use_case · crosswalk · walk_playbook · get_anti_pattern · list_regulations), 53 resources, 5 prompts. Covers EU AI Act, APRA CPS 230/234, NIST AI RMF, ISO 42001, AU AI Safety Standard (DISR Aug 2024), OWASP LLM Top 10, SLSA, SSDF, OAIC APPs, GDPR, DORA + 17 more frameworks. 56 controls × 28 regulations × 261 tool

★ 1 TypeScript Updated 2mo ago Score 41 Security

forgemeshlabs/x402-notary-mcp D MCP Server Maintained

forgemeshlabs/x402-notary-mcp

Cryptographic receipts for AI outputs: notarize any model inference with a signed Ed25519 attestation, sha256 content hash, and Merkle chain-anchor on Base or Solana. $0.001 per call via x402 USDC micropayments; verification is free and needs no wallet. Notarizes the hash, never your prompts. `npx -y @forgemeshlabs/x402-notary-mcp`

★ 0 JavaScript Updated 1mo ago Score 38 Security

node-man/dechonet-mcp D MCP Server Maintained

node-man/dechonet-mcp

Domain security reconnaissance for AI agents. 13 tools — DNS + DNSSEC, SSL/TLS chain & grade, HTTP security headers, SPF/DKIM/DMARC email auth, TCP port scan, ASN, RDAP/WHOIS — plus a one-shot `security_scan` returning a 0-100 Health Score (A–F). Free, no API key. `npx -y dechonet-mcp`

★ 1 JavaScript Updated 1mo ago Score 36 Security

bluetieroperations-create/blackwall-mcp F MCP Server Maintained

bluetieroperations-create/blackwall-mcp

Pre-action risk gate for AI agents. One `forecast` tool the agent calls before any irreversible action (send money, run SQL, delete data); returns a risk score (0–100), reversibility class, named red flags from 28 failure modes, and a gate: proceed / confirm / human-required.

★ 0 JavaScript Updated 1mo ago Score 33 Security

hernaninverso/eleion-scanner-mcp F MCP Server Maintained

hernaninverso/eleion-scanner-mcp

Register/verify your domains, queue security scans (headers, TLS, DNS, ports, CVEs + AI-specific checks) and read findings, for AI agents. Install with `npx -y eleion-scanner-mcp`.

★ 0 JavaScript Updated 1mo ago Score 28 Security