Home › Categories › Security

Security

190 MCP servers and agent skills in the Security category, ranked by quality score.

Filters (2 active)
20 results (<1ms) · data updated 2026-08-14

Results

BurtTheCoder/mcp-maigret C MCP Server Stale

BurtTheCoder/mcp-maigret

MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

★ 256 JavaScript Updated 6mo ago Score 57 Security

BurtTheCoder/mcp-shodan C MCP Server Stale

BurtTheCoder/mcp-shodan

MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.

★ 152 TypeScript Updated 4mo ago Score 55 Security

operantlabs/operant-mcp D MCP Server Stale

operantlabs/operant-mcp

Security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment.

★ 23 TypeScript Updated 4mo ago Score 47 Security

firstorderai/authenticator_mcp D MCP Server Stale

firstorderai/authenticator_mcp

A secure MCP (Model Context Protocol) server that enables AI agents to interact with the Authenticator App.

★ 42 TypeScript Updated 4mo ago Score 44 Security

AIM-Intelligence/AIM-Guard-MCP D MCP Server Stale

AIM-Intelligence/AIM-MCP

Security-focused MCP server that provides safety guidelines and content analysis for AI agents.

★ 21 TypeScript Updated 10mo ago Score 41 Security

zekebuilds-lab/captcha-mcp D MCP Server Stale

zekebuilds-lab/captcha-mcp

L402 Lightning paywall + Hashcash proof-of-work gate for MCP tool calls. Free tier solves a PoW challenge; paid tier pays a Lightning invoice via self-hosted LNBits. No accounts, no API keys, no third-party SaaS. Drop-in middleware for any MCP server. `npx @powforge/captcha-mcp`.

★ 1 JavaScript Updated 3mo ago Score 36 Security

cuttalo/depscope D MCP Server Stale

cuttalo/depscope

Package Intelligence for AI agents. 22 tools across 17 ecosystems (npm/pypi/cargo/go/maven/nuget/rubygems/composer/pub/hex/swift/cocoapods/cpan/hackage/cran/conda/homebrew) — check health, vulnerabilities (OSV + CISA KEV + EPSS), typosquats, malicious flags, alternatives, known bugs, breaking changes, stack compatibility and error-to-fix. 31k+ packages, 2.2k+ CVEs enriched. Zero auth, MIT. Remote

★ 1 TypeScript Updated 3mo ago Score 36 Security

muhannad-hash/mcp-shield F MCP Server Stale

muhannad-hash/mcp-shield

Security scanner for MCP servers. Detects backdoors, exfiltration code, obfuscation, dangerous code execution, prompt injection, and supply chain risks before you install. Four tools: scan npm packages, scan local directories, check prompt injection, and audit supply chain trust score. `npx @muhannad-hash/mcp-shield`

★ 2 TypeScript Updated 4mo ago Score 33 Security

123Ergo/unphurl-mcp F MCP Server Stale

123Ergo/unphurl-mcp

URL intelligence for AI agents. 13 tools for security signals and data quality: redirect behaviour, brand impersonation detection, domain age, SSL validation, parked detection, URL structural analysis, DNS enrichment.

★ 1 TypeScript Updated 3mo ago Score 31 Security

agntor/mcp F MCP Server Stale

agntor/mcp

MCP audit server for agent discovery and certification. Provides trust and payment rail for AI agents including identity verification, escrow, settlement, and reputation management.

★ 1 TypeScript Updated 5mo ago Score 31 Security

alberthild/shieldapi-mcp F MCP Server Stale

alberthild/shieldapi-mcp

Security intelligence for AI agents: password breach checks (900M+ HIBP hashes), email/domain/IP/URL reputation, prompt injection detection (200+ patterns), and skill supply chain scanning. Pay-per-request via x402 USDC micropayments or free demo mode, no API key needed.

★ 1 JavaScript Updated 5mo ago Score 31 Security

gridinsoft/mcp-inspector F MCP Server Stale

gridinsoft/mcp-inspector

MCP server for domain and URL security analysis powered by GridinSoft Inspector, enabling AI agents to verify website and link safety.

★ 1 JavaScript Updated 6mo ago Score 31 Security

JoeyBrar/agentseal-mcp F MCP Server Stale

JoeyBrar/agentseal-mcp

Action logs for AI agents. Records every agent action in a SHA-256 hash chain, making an audit trail. Install via `npx agentseal-mcp`.

★ 1 JavaScript Updated 3mo ago Score 31 Security

juanisidoro/securecode-mcp F MCP Server Stale

juanisidoro/securecode-mcp

Secrets vault for Claude Code with audit logs, MCP access rules, and AES-256 encryption. Secrets are injected to local files so the AI never sees raw values. Includes session lock, device approval, and per-model access policies.

★ 1 TypeScript Updated 4mo ago Score 31 Security

scamverifyai/scamverify-mcp F MCP Server Stale

scamverifyai/scamverify-mcp

AI-powered scam and threat verification MCP server. Check phone numbers, URLs, text messages, emails, documents, and QR codes against 8M+ threat intelligence records (FTC/FCC complaints, carrier analysis, URLhaus, ThreatFox). Returns risk scores, verdicts, and detailed signals. 10 tools, OAuth 2.1 + API key auth, Streamable HTTP transport.

★ 1 JavaScript Updated 4mo ago Score 31 Security

Thezenmonster/agentscore-mcp-server F MCP Server Stale

Thezenmonster/agentscore-mcp-server

MCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions with OIDC auto-provisioning. 5 MCP tools, no API key required.

★ 1 TypeScript Updated 3mo ago Score 31 Security

GUCCI-atlasv/skillssafe-mcp F MCP Server Stale

GUCCI-atlasv/skillssafe-mcp

Free AI agent skill security scanner. Scan SKILL.md, MCP configs, and system prompts for credential theft, prompt injection, zero-width character attacks, and ClawHavoc indicators. Supports OpenClaw, Claude Code, Cursor, and Codex. No signup required.

★ 1 JavaScript Updated 5mo ago Score 31 Security

iamredmh/volta-mcp-server F MCP Server Stale

iamredmh/volta-mcp-server

Burn-after-read encrypted notes for AI agents. Create and read self-destructing notes via Volta Notes with AES-256-GCM E2E encryption — the decryption key never leaves the URL fragment. Secure credential handoff between users and agents without secrets appearing in chat history.

★ 1 TypeScript Updated 3mo ago Score 31 Security

vaulted-fyi/vaulted-mcp-server F MCP Server Stale

vaulted-fyi/vaulted-mcp-server

Share encrypted, self-destructing secrets from your AI agent. Zero-knowledge E2E encryption. Agent-blind input sources (env:, file:, dotenv:) keep secrets out of LLM context.

★ 1 TypeScript Updated 3mo ago Score 31 Security