Home › Categories › Security

Security

190 MCP servers and agent skills in the Security category, ranked by quality score.

Filters (1 active)
Status
Official7
92 results (<1ms) · data updated 2026-08-14

Results

inkog-io/inkog-mcp D MCP Server Maintained

inkog-io/inkog-mcp

AI agent security scanner. Audits MCP servers for vulnerabilities, detects prompt injection, infinite loops, token bombing, and missing human oversight across 20+ frameworks. Maps findings to EU AI Act, OWASP LLM Top 10.

★ 3 TypeScript Updated 2mo ago Score 49 Security

rad-security/mcp-server D MCP Server Active

rad-security/mcp-server

MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for querying the Rad Security API and retrieving security findings, reports, runtime data and many more.

★ 6 TypeScript Updated 3d ago Score 48 Security

eliottreich/taskbounty-check D MCP Server Maintained

eliottreich/taskbounty-check

Local-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes `scan_repo`, `explain_finding`, and `generate_fix_plan` to MCP clients; reads only allowlisted workflow and update configuration, modifies nothing, makes no outbound requests by default, and has zero runtime dependencies. Run with `npx -y taskbounty-check@0.1.6 mcp`.

★ 2 JavaScript Updated 1mo ago Score 48 Security

ppcvote/misp-mcp-server D MCP Server Maintained

ppcvote/misp-mcp-server

MISP (Malware Information Sharing Platform) MCP server with built-in prompt injection defense via [prompt-defense-audit](https://github.com/ppcvote/prompt-defense-audit). 8 read-only threat-intel tools (events, attributes, search, tags, feeds, galaxies). Scans every MISP response for adversarial seeding before returning to LLM. Tracks [MISP/MISP#10745](https://github.com/MISP/MISP/issues/10745). M

★ 2 TypeScript Updated 2mo ago Score 48 Security

Chronolapse411/sicarius-guard D MCP Server Maintained

Chronolapse411/sicarius-guard

Solana token safety oracle for AI agents and trading bots. Byte-level SPL mint analysis, honeypot detection, freeze/mint authority checks, Birdeye market enrichment, and composite risk scoring. Deployed on Google Cloud Run.

★ 2 TypeScript Updated 2mo ago Score 48 Security

astafford8488/agentaegis-mcp D MCP Server Active

astafford8488/agentaegis-mcp

Security & trust layer for AI agents. Scan an MCP server or skill *before* you install it (`scan_mcp_plugin`, `scan_skill`) — flags exfiltration, prompt-injection sinks, dangerous capabilities, install hooks and obfuscation → PROCEED/CAUTION/BLOCK. Plus `vet_endpoint` (endpoint safety verdict before an agent calls or pays it) and 25 more tools: vuln scans, threat intel, compliance (SOC 2/ISO 27001

★ 1 TypeScript Updated 2d ago Score 48 Security

gautam-u/sieve-mcp D MCP Server Active

gautam-u/sieve-mcp

Local AI chat history secret scanner for macOS. Finds API keys and secrets leaked into Claude Code, Cursor, Copilot Chat, Cline, Codex, Gemini CLI, and other AI tool transcripts. 9 MCP tools: findings list with redacted previews, boolean secret detection (`sieve_check_text`), placeholder-only redaction (`sieve_redact_text` returns `sieve://project/key`, never raw values), vault-backed command exec

★ 1 JavaScript Updated 11d ago Score 48 Security

operantlabs/operant-mcp D MCP Server Stale

operantlabs/operant-mcp

Security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment.

★ 23 TypeScript Updated 4mo ago Score 47 Security

qinisolabs/qiniso D MCP Server Maintained

qinisolabs/qiniso

56 deterministic fact-checkers in one server (IBAN, VAT, VIN, GTIN/barcodes, national & tax IDs, crypto addresses, phone, dates, holidays) — verify the structured facts an agent emits against checksums and curated data.

★ 1 TypeScript Updated 1mo ago Score 46 Security

vinaybhosle/agentstamp D MCP Server Maintained

vinaybhosle/agentstamp

Trust intelligence for AI agents — identity stamps, reputation scoring (0-100), registry, forensic audit trails, and A2A passports via x402 micropayments.

★ 1 JavaScript Updated 1mo ago Score 46 Security

Perufitlife/web-exposure-mcp D MCP Server Maintained

Perufitlife/web-exposure-mcp

Points an AI agent at a live URL and confirms publicly-served secret files by fetching the bytes — exposed `.git`, `.env`, JS source maps, backup/SQL dumps, directory listing, and dotfiles. Zero dependencies, read-only.

★ 1 JavaScript Updated 1mo ago Score 46 Security

chrbailey/promptspeak-mcp-server D MCP Server Maintained

chrbailey/promptspeak-mcp-server

Pre-execution governance for AI agents. Intercepts and validates every agent tool call through an 8-stage pipeline before execution — risk classification, behavioral drift detection, hold queue for dangerous operations, and complete audit trail. 45 tools, 658 tests.

★ 1 TypeScript Updated 1mo ago Score 46 Security

BeBraveBeKind/mcpskills-server D MCP Server Maintained

BeBraveBeKind/mcpskills-server

Pre-install trust layer for MCP servers, AI skills, and npm packages. Scores any repo or package across 15 signals (incl. OSV/KEV/EPSS vulnerability intelligence) with safety scanning for prompt injection, credential theft, and supply-chain risk; the `auto_gate` tool returns a go/no-go install decision. Listed in the official MCP Registry as `io.mcpskills/server`. npm: `@mcpskillsio/server`. https

★ 1 JavaScript Updated 2mo ago Score 46 Security

OksigeniaSL/checker-mcp D MCP Server Active

OksigeniaSL/checker-mcp

Domain security & privacy checker: 17 live checks (SPF, DMARC, DKIM, DNSSEC, TLS, CAA, security headers) scored 0-100 with remediation. Local-first, zero telemetry. In the official MCP Registry as `com.oksigenia/checker-mcp`; npm `@oksigenia/checker-mcp`.

★ 0 TypeScript Updated 22d ago Score 45 Security

mcpindex-ai/mcp-server-mcpindex D MCP Server Active

mcpindex-ai/mcp-server-mcpindex

Find MCP servers by natural-language task and get advisory trust screens (check_tool_trust, assess_server) before you connect. The directory client for mcpindex.ai; advisory, not a safety verdict.

★ 0 JavaScript Updated 15d ago Score 45 Security

firstorderai/authenticator_mcp D MCP Server Stale

firstorderai/authenticator_mcp

A secure MCP (Model Context Protocol) server that enables AI agents to interact with the Authenticator App.

★ 42 TypeScript Updated 4mo ago Score 44 Security

qianniuspace/mcp-security-audit D MCP Server Inactive

qianniuspace/mcp-security-audit

A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.

★ 56 TypeScript Updated 1y ago Score 43 Security

jamjet-labs/jamjet-policy D MCP Server Maintained

jamjet-labs/jamjet-policy/packages/mcp-shim

MCP stdio interceptor (`@jamjet/mcp-shim`) that applies one YAML policy file (block / require_approval / audit / budget cap) to `tools/call` requests before they reach the real MCP server. The same policy also runs in Claude Code PreToolUse hooks (`@jamjet/claude-code-hook`), OpenAI Agents SDK guardrails (`@jamjet/openai-guardrail`), and JamJet's Python/TS SDKs — `jamjet audit show` tails every de

★ 2 TypeScript Updated 1mo ago Score 43 Security

BurtTheCoder/mcp-dnstwist D MCP Server Inactive

BurtTheCoder/mcp-dnstwist

MCP server for dnstwist, a powerful DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage.

★ 51 JavaScript Updated 1y ago Score 42 Security

AIM-Intelligence/AIM-Guard-MCP D MCP Server Stale

AIM-Intelligence/AIM-MCP

Security-focused MCP server that provides safety guidelines and content analysis for AI agents.

★ 21 TypeScript Updated 10mo ago Score 41 Security

KOVY/agentforge-trust-mcp D MCP Server Maintained

KOVY/agentforge-trust-mcp

Query the AgentForge Trust Score (0-100 across five dimensions: security, code health, behavioral audit, community trust, EU compliance) for any MCP server before connecting. Exposes `check_trust`, `evaluate_policy`, `list_trusted`, and `recommend` tools. 3,600+ servers audited, free public API.

★ 1 TypeScript Updated 2mo ago Score 41 Security

Bichev/agentradar-mcp D MCP Server Maintained

Bichev/agentradar-mcp

On-chain trust oracle for the ERC-8004 + x402 agent economy. 18 tools for verifying AI agents: 6-signal composite trust scoring (0-100), 272-wallet scam database, ERC-8004 identity lookup, EAS attestations on Base mainnet. x402-payable. Free `get_score` / `check_scam`. Live at [vvpro.ai](https://vvpro.ai) · npm [`@agentradar/mcp`](https://www.npmjs.com/package/@agentradar/mcp).

★ 1 TypeScript Updated 1mo ago Score 41 Security

rev2ret/SecureAudit-MCP D MCP Server Maintained

rev2ret/SecureAudit-MCP

Model Context Protocol (MCP) server for static C/C++ memory-safety scanning and compiled PE/ELF binary protections auditing (ASLR, DEP/NX, SafeSEH, PIE) with secure templates remediation.

★ 1 JavaScript Updated 2mo ago Score 41 Security

uchit/mcp-regulated-ai-compliance D MCP Server Maintained

uchit/mcp-regulated-ai-compliance

Regulated-industry AI compliance knowledge as MCP. 6 tools (lookup_control · classify_use_case · crosswalk · walk_playbook · get_anti_pattern · list_regulations), 53 resources, 5 prompts. Covers EU AI Act, APRA CPS 230/234, NIST AI RMF, ISO 42001, AU AI Safety Standard (DISR Aug 2024), OWASP LLM Top 10, SLSA, SSDF, OAIC APPs, GDPR, DORA + 17 more frameworks. 56 controls × 28 regulations × 261 tool

★ 1 TypeScript Updated 2mo ago Score 41 Security

forgemeshlabs/x402-notary-mcp D MCP Server Maintained

forgemeshlabs/x402-notary-mcp

Cryptographic receipts for AI outputs: notarize any model inference with a signed Ed25519 attestation, sha256 content hash, and Merkle chain-anchor on Base or Solana. $0.001 per call via x402 USDC micropayments; verification is free and needs no wallet. Notarizes the hash, never your prompts. `npx -y @forgemeshlabs/x402-notary-mcp`

★ 0 JavaScript Updated 1mo ago Score 38 Security

node-man/dechonet-mcp D MCP Server Maintained

node-man/dechonet-mcp

Domain security reconnaissance for AI agents. 13 tools — DNS + DNSSEC, SSL/TLS chain & grade, HTTP security headers, SPF/DKIM/DMARC email auth, TCP port scan, ASN, RDAP/WHOIS — plus a one-shot `security_scan` returning a 0-100 Health Score (A–F). Free, no API key. `npx -y dechonet-mcp`

★ 1 JavaScript Updated 1mo ago Score 36 Security

zekebuilds-lab/captcha-mcp D MCP Server Stale

zekebuilds-lab/captcha-mcp

L402 Lightning paywall + Hashcash proof-of-work gate for MCP tool calls. Free tier solves a PoW challenge; paid tier pays a Lightning invoice via self-hosted LNBits. No accounts, no API keys, no third-party SaaS. Drop-in middleware for any MCP server. `npx @powforge/captcha-mcp`.

★ 1 JavaScript Updated 3mo ago Score 36 Security

cuttalo/depscope D MCP Server Stale

cuttalo/depscope

Package Intelligence for AI agents. 22 tools across 17 ecosystems (npm/pypi/cargo/go/maven/nuget/rubygems/composer/pub/hex/swift/cocoapods/cpan/hackage/cran/conda/homebrew) — check health, vulnerabilities (OSV + CISA KEV + EPSS), typosquats, malicious flags, alternatives, known bugs, breaking changes, stack compatibility and error-to-fix. 31k+ packages, 2.2k+ CVEs enriched. Zero auth, MIT. Remote

★ 1 TypeScript Updated 3mo ago Score 36 Security

pullkitsan/mobsf-mcp-server F MCP Server Inactive

pullkitsan/mobsf-mcp-server

A MCP server for MobSF which can be used for static and dynamic analysis of Android and iOS application.

★ 21 TypeScript Updated 1y ago Score 33 Security

muhannad-hash/mcp-shield F MCP Server Stale

muhannad-hash/mcp-shield

Security scanner for MCP servers. Detects backdoors, exfiltration code, obfuscation, dangerous code execution, prompt injection, and supply chain risks before you install. Four tools: scan npm packages, scan local directories, check prompt injection, and audit supply chain trust score. `npx @muhannad-hash/mcp-shield`

★ 2 TypeScript Updated 4mo ago Score 33 Security

bluetieroperations-create/blackwall-mcp F MCP Server Maintained

bluetieroperations-create/blackwall-mcp

Pre-action risk gate for AI agents. One `forecast` tool the agent calls before any irreversible action (send money, run SQL, delete data); returns a risk score (0–100), reversibility class, named red flags from 28 failure modes, and a gate: proceed / confirm / human-required.

★ 0 JavaScript Updated 1mo ago Score 33 Security

123Ergo/unphurl-mcp F MCP Server Stale

123Ergo/unphurl-mcp

URL intelligence for AI agents. 13 tools for security signals and data quality: redirect behaviour, brand impersonation detection, domain age, SSL validation, parked detection, URL structural analysis, DNS enrichment.

★ 1 TypeScript Updated 3mo ago Score 31 Security

agntor/mcp F MCP Server Stale

agntor/mcp

MCP audit server for agent discovery and certification. Provides trust and payment rail for AI agents including identity verification, escrow, settlement, and reputation management.

★ 1 TypeScript Updated 5mo ago Score 31 Security

alberthild/shieldapi-mcp F MCP Server Stale

alberthild/shieldapi-mcp

Security intelligence for AI agents: password breach checks (900M+ HIBP hashes), email/domain/IP/URL reputation, prompt injection detection (200+ patterns), and skill supply chain scanning. Pay-per-request via x402 USDC micropayments or free demo mode, no API key needed.

★ 1 JavaScript Updated 5mo ago Score 31 Security

gridinsoft/mcp-inspector F MCP Server Stale

gridinsoft/mcp-inspector

MCP server for domain and URL security analysis powered by GridinSoft Inspector, enabling AI agents to verify website and link safety.

★ 1 JavaScript Updated 6mo ago Score 31 Security

JoeyBrar/agentseal-mcp F MCP Server Stale

JoeyBrar/agentseal-mcp

Action logs for AI agents. Records every agent action in a SHA-256 hash chain, making an audit trail. Install via `npx agentseal-mcp`.

★ 1 JavaScript Updated 3mo ago Score 31 Security

juanisidoro/securecode-mcp F MCP Server Stale

juanisidoro/securecode-mcp

Secrets vault for Claude Code with audit logs, MCP access rules, and AES-256 encryption. Secrets are injected to local files so the AI never sees raw values. Includes session lock, device approval, and per-model access policies.

★ 1 TypeScript Updated 4mo ago Score 31 Security

scamverifyai/scamverify-mcp F MCP Server Stale

scamverifyai/scamverify-mcp

AI-powered scam and threat verification MCP server. Check phone numbers, URLs, text messages, emails, documents, and QR codes against 8M+ threat intelligence records (FTC/FCC complaints, carrier analysis, URLhaus, ThreatFox). Returns risk scores, verdicts, and detailed signals. 10 tools, OAuth 2.1 + API key auth, Streamable HTTP transport.

★ 1 JavaScript Updated 4mo ago Score 31 Security

Thezenmonster/agentscore-mcp-server F MCP Server Stale

Thezenmonster/agentscore-mcp-server

MCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions with OIDC auto-provisioning. 5 MCP tools, no API key required.

★ 1 TypeScript Updated 3mo ago Score 31 Security

GUCCI-atlasv/skillssafe-mcp F MCP Server Stale

GUCCI-atlasv/skillssafe-mcp

Free AI agent skill security scanner. Scan SKILL.md, MCP configs, and system prompts for credential theft, prompt injection, zero-width character attacks, and ClawHavoc indicators. Supports OpenClaw, Claude Code, Cursor, and Codex. No signup required.

★ 1 JavaScript Updated 5mo ago Score 31 Security

iamredmh/volta-mcp-server F MCP Server Stale

iamredmh/volta-mcp-server

Burn-after-read encrypted notes for AI agents. Create and read self-destructing notes via Volta Notes with AES-256-GCM E2E encryption — the decryption key never leaves the URL fragment. Secure credential handoff between users and agents without secrets appearing in chat history.

★ 1 TypeScript Updated 3mo ago Score 31 Security

vaulted-fyi/vaulted-mcp-server F MCP Server Stale

vaulted-fyi/vaulted-mcp-server

Share encrypted, self-destructing secrets from your AI agent. Zero-knowledge E2E encryption. Agent-blind input sources (env:, file:, dotenv:) keep secrets out of LLM context.

★ 1 TypeScript Updated 3mo ago Score 31 Security

hernaninverso/eleion-scanner-mcp F MCP Server Maintained

hernaninverso/eleion-scanner-mcp

Register/verify your domains, queue security scans (headers, TLS, DNS, ports, CVEs + AI-specific checks) and read findings, for AI agents. Install with `npx -y eleion-scanner-mcp`.

★ 0 JavaScript Updated 1mo ago Score 28 Security