Home › Categories › Security

Security

190 MCP servers and agent skills in the Security category, ranked by quality score.

Filters (2 active)
Status
Official2
Install method
npm / npx30
30 results (<1ms) · data updated 2026-08-14

Results

Kzino/vorim-mcp-server B MCP Server Active

Kzino/vorim-mcp-server

AI agent identity, trust, and audit trail infrastructure. 17 MCP tools: register agents with Ed25519 keypairs, check permissions (sub-5ms), emit tamper-evident audit events, verify trust scores (0-100), delegate credentials, and manage ephemeral agents. IETF Internet-Draft filed (draft-vorim-vaip-00). Works with LangChain, OpenAI, CrewAI, Stripe ACP, and 4 more frameworks. `npx @vorim/mcp-server`.

★ 35 JavaScript Updated today Score 66 Security

aeoess/agent-passport-mcp C MCP Server Official Active

aeoess/agent-passport-mcp

Agent identity, scoped delegation, and governance: issue passports, build and verify narrowing-only delegation chains, enforce policy at a gateway, and emit signed admission and outcome records. 150 tools. `npx -y agent-passport-system-mcp`

★ 1 JavaScript Updated 12d ago Score 63 Security

zyx77550/sparda C MCP Server Active

zyx77550/sparda

Injects a live, reversible MCP server into a running Express / FastAPI / Next.js app — reads safe by default, writes gated behind human confirmation. The same engine also proves deploys and PRs (`apocalypse` / `review`).

★ 5 JavaScript Updated 14d ago Score 58 Security

BurtTheCoder/mcp-maigret C MCP Server Stale

BurtTheCoder/mcp-maigret

MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

★ 256 JavaScript Updated 6mo ago Score 57 Security

beeswaxpat/chronoverify-mcp C MCP Server Active

beeswaxpat/chronoverify-mcp

Verify a photo's capture time and provenance before an agent trusts it: cryptographic C2PA Content Credentials validation against the official trust lists, EXIF and XMP consistency checks, and classical pixel forensics fused into one typed verdict with a 0 to 100 confidence. Free keyless tier, opt-in shareable verdict permalinks, and key-gated signed PDF audit reports. Provenance validation, not a

★ 2 JavaScript Updated 7d ago Score 55 Security

shieldly-io/mcp C MCP Server Official Active

shieldly-io/mcp

Official [Shieldly](https://www.shieldly.io) MCP server: `analyze_iam_policy` and `analyze_cloudformation_template` tools flag AWS IAM privilege-escalation paths, wildcards, and over-permissive access. Free demo mode, no signup or API key needed. `npx -y @shieldly/mcp`.

★ 0 JavaScript Updated 26d ago Score 55 Security

askalf/truecopy C MCP Server Active

askalf/truecopy

Supply-chain gate for agent skills and MCP servers — scans tool definitions for poisoned instructions, pins vetted servers by content hash in a committed lock, and verifies drift in CI; the bundled truecopy-mcp proxy exposes only pinned, unmodified tools from a live server.

★ 1 JavaScript Updated today Score 53 Security

ScopeBlind/verify-mcp C MCP Server Maintained

ScopeBlind/verify-mcp

Offline verification of signed artifacts -- receipts, manifests, audit bundles. Ed25519 + JCS. No accounts, no API calls. Apache-2.0.

★ 5 JavaScript Updated 1mo ago Score 51 Security

moxno/privacyscrubber-mcp C MCP Server Active

moxno/privacyscrubber-mcp

Zero-trust local PII and secrets masking server for Cursor, Windsurf, and Claude Desktop. `npx pii-masking-run`

★ 0 JavaScript Updated 11d ago Score 50 Security

jamesdfinance-dev/lazaretto-mcp C MCP Server Active

jamesdfinance-dev/lazaretto-mcp

Check whether anything you depend on is known malware, before an agent installs it. `check_lockfile` takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. `scan_artifact` adds deterministic b

★ 0 JavaScript Updated yesterday Score 50 Security

corewebvitals/state-of-cwv-mcp C MCP Server Active

corewebvitals/state-of-cwv-mcp

Free remote MCP for Core Web Vitals metrics by CMS, CDN, and framework (Chrome field data + multi-site crawl). No auth. Endpoint: `https://www.corewebvitals.io/api/state-of-cwv/mcp`.

★ 0 JavaScript Updated 28d ago Score 50 Security

eliottreich/taskbounty-check D MCP Server Maintained

eliottreich/taskbounty-check

Local-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes `scan_repo`, `explain_finding`, and `generate_fix_plan` to MCP clients; reads only allowlisted workflow and update configuration, modifies nothing, makes no outbound requests by default, and has zero runtime dependencies. Run with `npx -y taskbounty-check@0.1.6 mcp`.

★ 2 JavaScript Updated 1mo ago Score 48 Security

gautam-u/sieve-mcp D MCP Server Active

gautam-u/sieve-mcp

Local AI chat history secret scanner for macOS. Finds API keys and secrets leaked into Claude Code, Cursor, Copilot Chat, Cline, Codex, Gemini CLI, and other AI tool transcripts. 9 MCP tools: findings list with redacted previews, boolean secret detection (`sieve_check_text`), placeholder-only redaction (`sieve_redact_text` returns `sieve://project/key`, never raw values), vault-backed command exec

★ 1 JavaScript Updated 11d ago Score 48 Security

vinaybhosle/agentstamp D MCP Server Maintained

vinaybhosle/agentstamp

Trust intelligence for AI agents — identity stamps, reputation scoring (0-100), registry, forensic audit trails, and A2A passports via x402 micropayments.

★ 1 JavaScript Updated 1mo ago Score 46 Security

Perufitlife/web-exposure-mcp D MCP Server Maintained

Perufitlife/web-exposure-mcp

Points an AI agent at a live URL and confirms publicly-served secret files by fetching the bytes — exposed `.git`, `.env`, JS source maps, backup/SQL dumps, directory listing, and dotfiles. Zero dependencies, read-only.

★ 1 JavaScript Updated 1mo ago Score 46 Security

BeBraveBeKind/mcpskills-server D MCP Server Maintained

BeBraveBeKind/mcpskills-server

Pre-install trust layer for MCP servers, AI skills, and npm packages. Scores any repo or package across 15 signals (incl. OSV/KEV/EPSS vulnerability intelligence) with safety scanning for prompt injection, credential theft, and supply-chain risk; the `auto_gate` tool returns a go/no-go install decision. Listed in the official MCP Registry as `io.mcpskills/server`. npm: `@mcpskillsio/server`. https

★ 1 JavaScript Updated 2mo ago Score 46 Security

mcpindex-ai/mcp-server-mcpindex D MCP Server Active

mcpindex-ai/mcp-server-mcpindex

Find MCP servers by natural-language task and get advisory trust screens (check_tool_trust, assess_server) before you connect. The directory client for mcpindex.ai; advisory, not a safety verdict.

★ 0 JavaScript Updated 15d ago Score 45 Security

BurtTheCoder/mcp-dnstwist D MCP Server Inactive

BurtTheCoder/mcp-dnstwist

MCP server for dnstwist, a powerful DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage.

★ 51 JavaScript Updated 1y ago Score 42 Security

rev2ret/SecureAudit-MCP D MCP Server Maintained

rev2ret/SecureAudit-MCP

Model Context Protocol (MCP) server for static C/C++ memory-safety scanning and compiled PE/ELF binary protections auditing (ASLR, DEP/NX, SafeSEH, PIE) with secure templates remediation.

★ 1 JavaScript Updated 2mo ago Score 41 Security

forgemeshlabs/x402-notary-mcp D MCP Server Maintained

forgemeshlabs/x402-notary-mcp

Cryptographic receipts for AI outputs: notarize any model inference with a signed Ed25519 attestation, sha256 content hash, and Merkle chain-anchor on Base or Solana. $0.001 per call via x402 USDC micropayments; verification is free and needs no wallet. Notarizes the hash, never your prompts. `npx -y @forgemeshlabs/x402-notary-mcp`

★ 0 JavaScript Updated 1mo ago Score 38 Security

node-man/dechonet-mcp D MCP Server Maintained

node-man/dechonet-mcp

Domain security reconnaissance for AI agents. 13 tools — DNS + DNSSEC, SSL/TLS chain & grade, HTTP security headers, SPF/DKIM/DMARC email auth, TCP port scan, ASN, RDAP/WHOIS — plus a one-shot `security_scan` returning a 0-100 Health Score (A–F). Free, no API key. `npx -y dechonet-mcp`

★ 1 JavaScript Updated 1mo ago Score 36 Security

zekebuilds-lab/captcha-mcp D MCP Server Stale

zekebuilds-lab/captcha-mcp

L402 Lightning paywall + Hashcash proof-of-work gate for MCP tool calls. Free tier solves a PoW challenge; paid tier pays a Lightning invoice via self-hosted LNBits. No accounts, no API keys, no third-party SaaS. Drop-in middleware for any MCP server. `npx @powforge/captcha-mcp`.

★ 1 JavaScript Updated 3mo ago Score 36 Security

bluetieroperations-create/blackwall-mcp F MCP Server Maintained

bluetieroperations-create/blackwall-mcp

Pre-action risk gate for AI agents. One `forecast` tool the agent calls before any irreversible action (send money, run SQL, delete data); returns a risk score (0–100), reversibility class, named red flags from 28 failure modes, and a gate: proceed / confirm / human-required.

★ 0 JavaScript Updated 1mo ago Score 33 Security

alberthild/shieldapi-mcp F MCP Server Stale

alberthild/shieldapi-mcp

Security intelligence for AI agents: password breach checks (900M+ HIBP hashes), email/domain/IP/URL reputation, prompt injection detection (200+ patterns), and skill supply chain scanning. Pay-per-request via x402 USDC micropayments or free demo mode, no API key needed.

★ 1 JavaScript Updated 5mo ago Score 31 Security

gridinsoft/mcp-inspector F MCP Server Stale

gridinsoft/mcp-inspector

MCP server for domain and URL security analysis powered by GridinSoft Inspector, enabling AI agents to verify website and link safety.

★ 1 JavaScript Updated 6mo ago Score 31 Security

JoeyBrar/agentseal-mcp F MCP Server Stale

JoeyBrar/agentseal-mcp

Action logs for AI agents. Records every agent action in a SHA-256 hash chain, making an audit trail. Install via `npx agentseal-mcp`.

★ 1 JavaScript Updated 3mo ago Score 31 Security

scamverifyai/scamverify-mcp F MCP Server Stale

scamverifyai/scamverify-mcp

AI-powered scam and threat verification MCP server. Check phone numbers, URLs, text messages, emails, documents, and QR codes against 8M+ threat intelligence records (FTC/FCC complaints, carrier analysis, URLhaus, ThreatFox). Returns risk scores, verdicts, and detailed signals. 10 tools, OAuth 2.1 + API key auth, Streamable HTTP transport.

★ 1 JavaScript Updated 4mo ago Score 31 Security

GUCCI-atlasv/skillssafe-mcp F MCP Server Stale

GUCCI-atlasv/skillssafe-mcp

Free AI agent skill security scanner. Scan SKILL.md, MCP configs, and system prompts for credential theft, prompt injection, zero-width character attacks, and ClawHavoc indicators. Supports OpenClaw, Claude Code, Cursor, and Codex. No signup required.

★ 1 JavaScript Updated 5mo ago Score 31 Security

hernaninverso/eleion-scanner-mcp F MCP Server Maintained

hernaninverso/eleion-scanner-mcp

Register/verify your domains, queue security scans (headers, TLS, DNS, ports, CVEs + AI-specific checks) and read findings, for AI agents. Install with `npx -y eleion-scanner-mcp`.

★ 0 JavaScript Updated 1mo ago Score 28 Security