Home › Categories › Security

Security

190 MCP servers and agent skills in the Security category, ranked by quality score.

Filters
190 results (<1ms) · data updated 2026-08-14

Results

shyshlakov/pci-dss-mcp C MCP Server Active

shyshlakov/pci-dss-mcp

PCI DSS v4.0.1 static-analysis MCP server for Go payment codebases. 12 scanners detect PAN/CVV exposure, weak crypto, missing audit logs, vulnerable deps, TLS misconfig, auth weaknesses, plus CycloneDX 1.6 SBOM generation - each finding mapped to the exact PCI requirement. AI-assisted triage via triage_findings. Keyless-signed multi-arch Docker image on ghcr.io.

★ 3 Go Updated 18d ago Score 51 Security

behrensd/mcp-firewall C MCP Server Maintained

behrensd/mcp-firewall

Deterministic security proxy (iptables for MCP) that intercepts tool calls, enforces YAML policies, scans for secret leakage, and logs everything. No AI, no cloud.

★ 4 TypeScript Updated 1mo ago Score 50 Security

toan203/osv-ui C MCP Server Maintained

toan203/osv-ui

Visual CVE audit dashboard for npm, Python, Go, and Rust. Scan from Claude/Cursor, opens a browser UI for human review (human-in-the-loop), applies fixes with explicit confirmation. Powered by OSV.dev.

★ 4 HTML Updated 2mo ago Score 50 Security

honeylabshq/honeylabs-mcp C MCP Server Active

honeylabshq/honeylabs-mcp

Honeypot threat intelligence for AI agents: 90 days of probe data from a sensor network for IP reputation, scanner classification, CVE probing trends, and JA4/JA4H/HASSH fingerprints. Remote MCP, free tier.

★ 2 Python Updated 4d ago Score 50 Security

moxno/privacyscrubber-mcp C MCP Server Active

moxno/privacyscrubber-mcp

Zero-trust local PII and secrets masking server for Cursor, Windsurf, and Claude Desktop. `npx pii-masking-run`

★ 0 JavaScript Updated 11d ago Score 50 Security

jamesdfinance-dev/lazaretto-mcp C MCP Server Active

jamesdfinance-dev/lazaretto-mcp

Check whether anything you depend on is known malware, before an agent installs it. `check_lockfile` takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. `scan_artifact` adds deterministic b

★ 0 JavaScript Updated yesterday Score 50 Security

alexar76/aimarket-oracle-gateway C MCP Server Active

alexar76/aimarket-oracle-gateway

Verifiable oracle MCP server**: Platon VRF (`get_random`), Chronos VDF (`compute_vdf` / `verify_vdf`), LUMEN reputation (`get_reputation_scores`) as agent tools. Pay-per-call over AIMarket Hub; every result independently verifiable. stdio · Python · [Glama](https://glama.ai/mcp/servers/alexar76/aimarket-oracle-gateway).

★ 0 Python Updated yesterday Score 50 Security

corewebvitals/state-of-cwv-mcp C MCP Server Active

corewebvitals/state-of-cwv-mcp

Free remote MCP for Core Web Vitals metrics by CMS, CDN, and framework (Chrome field data + multi-site crawl). No auth. Endpoint: `https://www.corewebvitals.io/api/state-of-cwv/mcp`.

★ 0 JavaScript Updated 28d ago Score 50 Security

kent-tokyo/shohei D MCP Server Maintained

kent-tokyo/shohei

Rust infrastructure diagnostics MCP server for AI agents: DNS checks, TLS certificate chain inspection, email security, global DNS propagation, and DNS latency benchmarking.

★ 3 Rust Updated 2mo ago Score 49 Security

rudraneel93/mcp-guardian D MCP Server Maintained

rudraneel93/mcp-guardian

Security and governance proxy for MCP infrastructure. Enforces YAML-configurable policies (blocklists, rate limits, token budgets), tracks real token costs via tiktoken, monitors server health with live JSON-RPC probes. Features include OAuth 2.1/OIDC with RBAC, web dashboard with Prometheus metrics, payload normalization against encoding bypasses, semantic shell AST analysis, mTLS zero-trust netw

★ 3 TypeScript Updated 2mo ago Score 49 Security

inkog-io/inkog-mcp D MCP Server Maintained

inkog-io/inkog-mcp

AI agent security scanner. Audits MCP servers for vulnerabilities, detects prompt injection, infinite loops, token bombing, and missing human oversight across 20+ frameworks. Maps findings to EU AI Act, OWASP LLM Top 10.

★ 3 TypeScript Updated 2mo ago Score 49 Security

coreyhines/opnsense-mcp D MCP Server Maintained

coreyhines/opnsense-mcp

OPNsense firewall operations via API. Query ARP, DHCP, firewall rules, logs, interfaces, system status, and packet capture via STDIO or SSE.

★ 9 Python Updated 1mo ago Score 48 Security

rad-security/mcp-server D MCP Server Active

rad-security/mcp-server

MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for querying the Rad Security API and retrieving security findings, reports, runtime data and many more.

★ 6 TypeScript Updated 3d ago Score 48 Security

eliottreich/taskbounty-check D MCP Server Maintained

eliottreich/taskbounty-check

Local-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes `scan_repo`, `explain_finding`, and `generate_fix_plan` to MCP clients; reads only allowlisted workflow and update configuration, modifies nothing, makes no outbound requests by default, and has zero runtime dependencies. Run with `npx -y taskbounty-check@0.1.6 mcp`.

★ 2 JavaScript Updated 1mo ago Score 48 Security

ppcvote/misp-mcp-server D MCP Server Maintained

ppcvote/misp-mcp-server

MISP (Malware Information Sharing Platform) MCP server with built-in prompt injection defense via [prompt-defense-audit](https://github.com/ppcvote/prompt-defense-audit). 8 read-only threat-intel tools (events, attributes, search, tags, feeds, galaxies). Scans every MISP response for adversarial seeding before returning to LLM. Tracks [MISP/MISP#10745](https://github.com/MISP/MISP/issues/10745). M

★ 2 TypeScript Updated 2mo ago Score 48 Security

Chronolapse411/sicarius-guard D MCP Server Maintained

Chronolapse411/sicarius-guard

Solana token safety oracle for AI agents and trading bots. Byte-level SPL mint analysis, honeypot detection, freeze/mint authority checks, Birdeye market enrichment, and composite risk scoring. Deployed on Google Cloud Run.

★ 2 TypeScript Updated 2mo ago Score 48 Security

astafford8488/agentaegis-mcp D MCP Server Active

astafford8488/agentaegis-mcp

Security & trust layer for AI agents. Scan an MCP server or skill *before* you install it (`scan_mcp_plugin`, `scan_skill`) — flags exfiltration, prompt-injection sinks, dangerous capabilities, install hooks and obfuscation → PROCEED/CAUTION/BLOCK. Plus `vet_endpoint` (endpoint safety verdict before an agent calls or pays it) and 25 more tools: vuln scans, threat intel, compliance (SOC 2/ISO 27001

★ 1 TypeScript Updated 2d ago Score 48 Security

gautam-u/sieve-mcp D MCP Server Active

gautam-u/sieve-mcp

Local AI chat history secret scanner for macOS. Finds API keys and secrets leaked into Claude Code, Cursor, Copilot Chat, Cline, Codex, Gemini CLI, and other AI tool transcripts. 9 MCP tools: findings list with redacted previews, boolean secret detection (`sieve_check_text`), placeholder-only redaction (`sieve_redact_text` returns `sieve://project/key`, never raw values), vault-backed command exec

★ 1 JavaScript Updated 11d ago Score 48 Security

operantlabs/operant-mcp D MCP Server Stale

operantlabs/operant-mcp

Security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment.

★ 23 TypeScript Updated 4mo ago Score 47 Security

jonnybottles/patch-tuesday-mcp D MCP Server Active

jonnybottles/patch-tuesday-mcp

Microsoft Patch Tuesday triage from the official MSRC Security Update Guide. Monthly rollups, CVE/KB lookups, supersedence chains, product watchlists, and urgency-ranked results enriched with EPSS scores and the CISA KEV catalog. No API keys; also available as a free hosted remote endpoint. `uvx patch-tuesday-mcp`

★ 4 Python Updated yesterday Score 47 Security

co-browser/attestable-mcp-server D MCP Server Maintained

co-browser/attestable-mcp-server

An MCP server running inside a trusted execution environment (TEE) via Gramine, showcasing remote attestation using [RA-TLS](https://gramine.readthedocs.io/en/stable/attestation.html). This allows an MCP client to verify the server before conencting.

★ 21 Python Updated 2mo ago Score 46 Security

qinisolabs/qiniso D MCP Server Maintained

qinisolabs/qiniso

56 deterministic fact-checkers in one server (IBAN, VAT, VIN, GTIN/barcodes, national & tax IDs, crypto addresses, phone, dates, holidays) — verify the structured facts an agent emits against checksums and curated data.

★ 1 TypeScript Updated 1mo ago Score 46 Security

vinaybhosle/agentstamp D MCP Server Maintained

vinaybhosle/agentstamp

Trust intelligence for AI agents — identity stamps, reputation scoring (0-100), registry, forensic audit trails, and A2A passports via x402 micropayments.

★ 1 JavaScript Updated 1mo ago Score 46 Security

Perufitlife/web-exposure-mcp D MCP Server Maintained

Perufitlife/web-exposure-mcp

Points an AI agent at a live URL and confirms publicly-served secret files by fetching the bytes — exposed `.git`, `.env`, JS source maps, backup/SQL dumps, directory listing, and dotfiles. Zero dependencies, read-only.

★ 1 JavaScript Updated 1mo ago Score 46 Security

chrbailey/promptspeak-mcp-server D MCP Server Maintained

chrbailey/promptspeak-mcp-server

Pre-execution governance for AI agents. Intercepts and validates every agent tool call through an 8-stage pipeline before execution — risk classification, behavioral drift detection, hold queue for dangerous operations, and complete audit trail. 45 tools, 658 tests.

★ 1 TypeScript Updated 1mo ago Score 46 Security

rob925/mcp-shield D MCP Server Maintained

rob925/mcp-shield

Static security scanner and MCP server for MCP servers and AI agent tools. Detects secrets, shell execution, risky tool descriptions, environment access, and prompt-injection phrases. `mcp-shield-server`

★ 1 Python Updated 1mo ago Score 46 Security

BeBraveBeKind/mcpskills-server D MCP Server Maintained

BeBraveBeKind/mcpskills-server

Pre-install trust layer for MCP servers, AI skills, and npm packages. Scores any repo or package across 15 signals (incl. OSV/KEV/EPSS vulnerability intelligence) with safety scanning for prompt injection, credential theft, and supply-chain risk; the `auto_gate` tool returns a go/no-go install decision. Listed in the official MCP Registry as `io.mcpskills/server`. npm: `@mcpskillsio/server`. https

★ 1 JavaScript Updated 2mo ago Score 46 Security

roadwy/cve-search_mcp D MCP Server Inactive

roadwy/cve-search_mcp

A Model Context Protocol (MCP) server for querying the CVE-Search API. This server provides comprehensive access to CVE-Search, browse vendor and product、get CVE per CVE-ID、get the last updated CVEs.

★ 103 Python Updated 1y ago Score 45 Security

girste/mcp-cybersec-watchdog D MCP Server Stale

girste/mcp-cybersec-watchdog

Comprehensive Linux server security audit with 89 CIS Benchmark controls, NIST 800-53, and PCI-DSS compliance checks. Real-time monitoring with anomaly detection across 23 analyzers: firewall, SSH, fail2ban, Docker, CVE, rootkit, SSL/TLS, filesystem, network, and more.

★ 53 Go Updated 6mo ago Score 45 Security

slouchd/cyberchef-api-mcp-server D MCP Server Stale

slouchd/cyberchef-api-mcp-server

MCP server for interacting with the CyberChef server API which will allow an MCP client to utilise the CyberChef operations.

★ 44 Python Updated 4mo ago Score 45 Security

jimmyracheta/AI-Runtime-Guard D MCP Server Maintained

runtimeguard/runtime-guard

Runtime policy enforcement for AI agents - prevents accidental damage to your systems, unauthorized agent access and automates backup-before-write for any touched files.

★ 15 Python Updated 2mo ago Score 45 Security

Kjopstad-IT/rqwstr D MCP Server Active

Kjopstad-IT/rqwstr-mcp

AI-native HTTP security testing toolkit: 17 tools (send, intruder, race, chain, oob) with low-level control over HTTP/1.1 + HTTP/2 (raw framing, connection pinning).

★ 0 Dockerfile Updated 8d ago Score 45 Security

OksigeniaSL/checker-mcp D MCP Server Active

OksigeniaSL/checker-mcp

Domain security & privacy checker: 17 live checks (SPF, DMARC, DKIM, DNSSEC, TLS, CAA, security headers) scored 0-100 with remediation. Local-first, zero telemetry. In the official MCP Registry as `com.oksigenia/checker-mcp`; npm `@oksigenia/checker-mcp`.

★ 0 TypeScript Updated 22d ago Score 45 Security

mcpindex-ai/mcp-server-mcpindex D MCP Server Active

mcpindex-ai/mcp-server-mcpindex

Find MCP servers by natural-language task and get advisory trust screens (check_tool_trust, assess_server) before you connect. The directory client for mcpindex.ai; advisory, not a safety verdict.

★ 0 JavaScript Updated 15d ago Score 45 Security

firstorderai/authenticator_mcp D MCP Server Stale

firstorderai/authenticator_mcp

A secure MCP (Model Context Protocol) server that enables AI agents to interact with the Authenticator App.

★ 42 TypeScript Updated 4mo ago Score 44 Security

semgrep/mcp D MCP Server Archived

semgrep/mcp

Allow AI agents to scan code for security vulnerabilites using [Semgrep](https://semgrep.dev).

★ 683 Python Updated 9mo ago Score 43 Security

qianniuspace/mcp-security-audit D MCP Server Inactive

qianniuspace/mcp-security-audit

A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.

★ 56 TypeScript Updated 1y ago Score 43 Security

sanyambassi/ciphertrust-manager-mcp-server D MCP Server Stale

sanyambassi/ciphertrust-manager-mcp-server

MCP server for Thales CipherTrust Manager integration, enabling secure key management, cryptographic operations, and compliance monitoring through AI assistants.

★ 9 Python Updated 11mo ago Score 43 Security

forest6511/secretctl D MCP Server Stale

forest6511/secretctl

AI-safe secrets manager with MCP integration. Run commands with credentials injected as environment variables - AI agents never see plaintext secrets. Features output sanitization, AES-256-GCM encryption, and Argon2id key derivation.

★ 8 Go Updated 6mo ago Score 43 Security

jamjet-labs/jamjet-policy D MCP Server Maintained

jamjet-labs/jamjet-policy/packages/mcp-shim

MCP stdio interceptor (`@jamjet/mcp-shim`) that applies one YAML policy file (block / require_approval / audit / budget cap) to `tools/call` requests before they reach the real MCP server. The same policy also runs in Claude Code PreToolUse hooks (`@jamjet/claude-code-hook`), OpenAI Agents SDK guardrails (`@jamjet/openai-guardrail`), and JamJet's Python/TS SDKs — `jamjet audit show` tails every de

★ 2 TypeScript Updated 1mo ago Score 43 Security

Skyrxin/sast-mcp-server D MCP Server Maintained

Skyrxin/sast-mcp-server

SAST/DAST server exposing 11 security scanners (Bandit, Semgrep, Trivy, CodeQL, Checkov, Gitleaks, OSV-Scanner, Grype, OWASP ZAP, and more) with closed-loop remediation (scan→patch→re-scan→verify), SARIF/SBOM/VEX export, compliance reporting, and CI integrations (GitHub Advanced Security, DefectDojo, Slack, Jira).

★ 2 Python Updated 1mo ago Score 43 Security

BurtTheCoder/mcp-dnstwist D MCP Server Inactive

BurtTheCoder/mcp-dnstwist

MCP server for dnstwist, a powerful DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage.

★ 51 JavaScript Updated 1y ago Score 42 Security

intruder-io/intruder-mcp D MCP Server Stale

intruder-io/intruder-mcp

MCP server to access [Intruder](https://www.intruder.io/), helping you identify, understand, and fix security vulnerabilities in your infrastructure.

★ 26 Python Updated 3mo ago Score 42 Security

velvetway/minreestr-mcp D MCP Server Stale

velvetway/minreestr-mcp

Search каталогпо.рф (Russian software registry, 26k+ products) for import-substitution and ФСТЭК/ФСБ-certified software discovery. Three tools: full-text search, manufacturer listing, featured products. Ideal for Russian security/compliance teams (152-ФЗ, 187-ФЗ) using Claude.

★ 7 Python Updated 3mo ago Score 42 Security

AIM-Intelligence/AIM-Guard-MCP D MCP Server Stale

AIM-Intelligence/AIM-MCP

Security-focused MCP server that provides safety guidelines and content analysis for AI agents.

★ 21 TypeScript Updated 10mo ago Score 41 Security

KOVY/agentforge-trust-mcp D MCP Server Maintained

KOVY/agentforge-trust-mcp

Query the AgentForge Trust Score (0-100 across five dimensions: security, code health, behavioral audit, community trust, EU compliance) for any MCP server before connecting. Exposes `check_trust`, `evaluate_policy`, `list_trusted`, and `recommend` tools. 3,600+ servers audited, free public API.

★ 1 TypeScript Updated 2mo ago Score 41 Security

Bichev/agentradar-mcp D MCP Server Maintained

Bichev/agentradar-mcp

On-chain trust oracle for the ERC-8004 + x402 agent economy. 18 tools for verifying AI agents: 6-signal composite trust scoring (0-100), 272-wallet scam database, ERC-8004 identity lookup, EAS attestations on Base mainnet. x402-payable. Free `get_score` / `check_scam`. Live at [vvpro.ai](https://vvpro.ai) · npm [`@agentradar/mcp`](https://www.npmjs.com/package/@agentradar/mcp).

★ 1 TypeScript Updated 1mo ago Score 41 Security

rev2ret/SecureAudit-MCP D MCP Server Maintained

rev2ret/SecureAudit-MCP

Model Context Protocol (MCP) server for static C/C++ memory-safety scanning and compiled PE/ELF binary protections auditing (ASLR, DEP/NX, SafeSEH, PIE) with secure templates remediation.

★ 1 JavaScript Updated 2mo ago Score 41 Security