Home › MCP Servers

MCP Servers

Browse all Model Context Protocol servers with quality scores, stars, languages and maintenance activity.

Filters (2 active)
86 results (<1ms) · data updated 2026-08-14

Results

mrexodia/ida-pro-mcp A MCP Server Active

mrexodia/ida-pro-mcp

MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

★ 11.3k Python Updated 4d ago Score 90 Security

safedep/vet A MCP Server Official Active

safedep/vet

vet-mcp checks open source packages—like those suggested by AI coding tools—for vulnerabilities and malicious code. It supports npm and PyPI, and runs locally via Docker or as a standalone binary for fast, automated vetting.

★ 1.1k Go Updated today Score 90 Security

zinja-coder/jadx-ai-mcp A MCP Server Active

zinja-coder/jadx-ai-mcp

JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

★ 2.7k Java Updated 7d ago Score 84 Security

mariocandela/beelzebub A MCP Server Active

mariocandela/beelzebub

Beelzebub is a honeypot framework that lets you build honeypot tools using MCP. Its purpose is to detect prompt injection or malicious agent behavior. The underlying idea is to provide the agent with tools it would never use in its normal work.

★ 2.1k Go Updated 2d ago Score 83 Security

timescale/rsigma A MCP Server Official Active

timescale/rsigma

Exposes the RSigma Sigma detection-engineering toolkit to AI agents over stdio or Streamable HTTP with `rsigma mcp serve`. Tools to author, lint, validate, and convert Sigma detection rules, evaluate and explain detections against log events, and inspect correlation state, all backed by a native Rust engine.

★ 133 Rust Updated today Score 81 Security

emiliaprotocol/emilia-protocol B MCP Server Active

emiliaprotocol/emilia-protocol

Human sign-off + trust receipts for AI agents: requires a named human's approval before an irreversible action (payment release, record change, deploy), then mints an offline-verifiable Ed25519 Trust Receipt. Also exposes trust profiles, receipt verification, disputes, and delegation. Apache-2.0; policy engine formally verified. Install: `npx -y @emilia-protocol/mcp-server`.

★ 841 TypeScript Updated today Score 79 Security

jtang613/GhidrAssistMCP B MCP Server Active

jtang613/GhidrAssistMCP

A native Model Context Protocol server for Ghidra. Includes GUI configuration and logging, 31 powerful tools and no external dependencies.

★ 717 Java Updated 10d ago Score 79 Security

mobb-dev/mobb-vibe-shield-mcp B MCP Server Official Active

mobb-dev/bugsy

[Mobb Vibe Shield](https://vibe.mobb.ai/) identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications remain secure without slowing development.

★ 68 TypeScript Updated today Score 78 Security

duriantaco/skylos B MCP Server Active

duriantaco/skylos

Dead code detection, security scanning, and code quality analysis for Python, TypeScript, and Go. 98% recall with fewer false positives than Vulture. Includes AI-powered remediation.

★ 536 Python Updated today Score 77 Security

bx33661/Wireshark-MCP B MCP Server Active

bx33661/Wireshark-MCP

Wireshark network packet analysis MCP Server with capture, protocol stats, field extraction, and security analysis capabilities.

★ 198 Python Updated 10d ago Score 73 Security

snyk/studio-mcp B MCP Server Official Active

snyk/studio-mcp

Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs.

★ 54 Go Updated 6d ago Score 72 Security

arthurpanhku/DocSentinel B MCP Server Active

arthurpanhku/DocSentinel

MCP server for AI agent for cybersecurity: automate assessment of documents, questionnaires & reports. Multi-format parsing, RAG knowledge base,Risks, compliance gaps, remediations.

★ 90 Python Updated yesterday Score 70 Security

gebalamariusz/cloud-audit B MCP Server Active

gebalamariusz/cloud-audit

Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.

★ 68 Python Updated 23d ago Score 68 Security

82ch/MCP-Dandan B MCP Server Active

82ch/MCP-Dandan

Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across multiple threat detection engines.

★ 65 Python Updated 3d ago Score 68 Security

kastelldev/kastell B MCP Server Active

kastelldev/kastell

Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.

★ 56 TypeScript Updated yesterday Score 68 Security

Synvoya/codeinspectus B MCP Server Active

Synvoya/codeinspectus

Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.

★ 39 TypeScript Updated 8d ago Score 66 Security

arian-gogani/nobulex B MCP Server Active

arian-gogani/nobulex

Proof-of-behavior enforcement for AI agents. Define behavioral covenant rules (permit/forbid/require), enforce at runtime before execution, get SHA-256 hash-chained tamper-evident audit logs, and verify compliance independently. Cross-agent verification handshake — no proof, no transaction. MIT licensed, 4,244 tests.

★ 38 TypeScript Updated 10d ago Score 66 Security

Kzino/vorim-mcp-server B MCP Server Active

Kzino/vorim-mcp-server

AI agent identity, trust, and audit trail infrastructure. 17 MCP tools: register agents with Ed25519 keypairs, check permissions (sub-5ms), emit tamper-evident audit events, verify trust scores (0-100), delegate credentials, and manage ephemeral agents. IETF Internet-Draft filed (draft-vorim-vaip-00). Works with LangChain, OpenAI, CrewAI, Stripe ACP, and 4 more frameworks. `npx @vorim/mcp-server`.

★ 35 JavaScript Updated today Score 66 Security

radareorg/r2mcp B MCP Server Active

radareorg/radare2-mcp

MCP server for Radare2 disassembler. Provides AI with capability to disassemble and look into binaries for reverse engineering.

★ 286 C Updated 6d ago Score 65 Security

UPinar/contrastapi B MCP Server Active

UPinar/contrastapi

Security intelligence API with 31 MCP tools for CVE/EPSS/KEV lookup, domain recon (DNS/WHOIS/SSL/subdomains/CT logs), IOC/threat intel, OSINT (email/phone/username), and code security scanning (secrets, injection). Free 100 req/hr.

★ 32 Python Updated 3d ago Score 65 Security

msaad00/agent-bom B MCP Server Active

msaad00/agent-bom

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

★ 29 Python Updated today Score 65 Security

FoundryNet/mint-mcp B MCP Server Official Active

FoundryNet/mint-mcp

MINT Protocol — universal work attestation for autonomous agents. Cryptographically attest, verify, rate, and discover agent work to build portable, on-chain trust and reputation across the agent economy. 6 tools.

★ 2 Python Updated 2d ago Score 65 Security

sekera-radim/impri B MCP Server Official Active

sekera-radim/impri

Human-in-the-loop approval inbox for AI agents. An agent submits a proposed action (send email, post comment, run a command) via `impri_push_action`, a human approves, rejects, or edits it from a web, mobile, or Slack/Discord/Telegram inbox, and the agent only proceeds on an approved decision. The gate is a data dependency, not a prompt. Full audit trail, self-hostable (MIT, Docker Compose). `npx

★ 2 HTML Updated 2d ago Score 65 Security

vespo92/OPNSenseMCP C MCP Server Active

vespo92/OPNSenseMCP

MCP Server for managing & interacting with Open Source NGFW OPNSense via Natural Language

★ 77 TypeScript Updated 23d ago Score 64 Security

gaoharimran29-glitch/Cybersecurity-MCP-Server C MCP Server Active

gaoharimran29-glitch/Cybersecurity-MCP-Server

Cybersecurity reconnaissance server for Claude. WHOIS lookup, DNS enumeration with subdomain brute-forcing, Nmap port scanning with service detection, SSL/TLS certificate inspection, technology stack fingerprinting, CVE lookup, and IP reputation checking. Runs fully locally via FastMCP.

★ 21 Python Updated yesterday Score 63 Security

mastyf-ai/mastyf.ai C MCP Server Active

mastyf-ai/mastyf.ai

Open-source runtime security proxy for MCP. Transparently intercepts every tools/call through an 18-class attack defense pipeline (prompt injection, SSRF, shell injection, SQL injection, credential exfil, polyglot attacks) with a YAML policy engine and 304-entry adversarial corpus. Trust scoring for npm MCP packages with 0-100 badges. Cloud dashboard, Docker image, Python SDK. MIT.

★ 17 TypeScript Updated 6d ago Score 63 Security

kakunin-ai/kakunin-mcp C MCP Server Official Active

kakunin-ai/kakunin-mcp

Compliance and identity for AI agents — verify an agent's certificate scope, read its behavioral risk score, and append to an immutable audit trail. X.509 identity issued via AWS KMS; MiCA / EU AI Act aligned. `npx -y @kakunin/mcp`

★ 1 TypeScript Updated 2d ago Score 63 Security

alexar76/aimarket-mcp C MCP Server Official Active

alexar76/aimarket-mcp

SSRF-hardened web gateway MCP** — `web_fetch`, `web_search`, `metis_verify`; one audited security core for Metis, ARGUS, and the ecosystem. stdio + optional HTTP · Python · [Glama](https://glama.ai/mcp/servers/alexar76/aimarket-mcp) · Registry `io.github.alexar76/aimarket-mcp`.

★ 1 Python Updated yesterday Score 63 Security

aeoess/agent-passport-mcp C MCP Server Official Active

aeoess/agent-passport-mcp

Agent identity, scoped delegation, and governance: issue passports, build and verify narrowing-only delegation chains, enforce policy at a gateway, and emit signed admission and outcome records. 150 tools. `npx -y agent-passport-system-mcp`

★ 1 JavaScript Updated 12d ago Score 63 Security

Acacian/aegis C MCP Server Active

Acacian/aegis

Policy-based governance for AI agent tool calls. YAML policies, approval gates, risk assessment, and audit logging. Cross-platform: LangChain, OpenAI, Anthropic, MCP.

★ 15 Python Updated 4d ago Score 62 Security

sgateway/s-gw C MCP Server Active

sgateway/s-gw

Local credential approval and execution gateway for AI coding agents. Agents receive typed handles instead of raw API tokens, SSH keys, and cloud credentials; one-time approvals bind the credential, command, arguments, working directory, environment bindings, and target. Injects credentials only into the approved child process, sanitizes output, and records a local audit trail. Install with `npm i

★ 15 TypeScript Updated today Score 62 Security

creatorrmode-lead/avp-sdk C MCP Server Active

creatorrmode-lead/avp-sdk

Trust, identity (W3C DID), and EigenTrust reputation for AI agents. Attestations, disputes, sybil detection, IPFS audit anchoring.

★ 14 Python Updated 3d ago Score 62 Security

sidclawhq/platform C MCP Server Active

sidclawhq/platform

Governance proxy for MCP servers. Wraps any upstream server with policy evaluation, human approval workflows, and hash-chain audit trails. 18+ framework integrations. Apache 2.0 SDK.

★ 14 TypeScript Updated 3d ago Score 62 Security

getaegis/aegis C MCP Server Active

getaegis/aegis

Credential isolation proxy for AI agents. Injects secrets at the network boundary with domain restrictions, agent authentication, and audit logging. No SDK required — works as a transparent HTTP proxy or MCP server.

★ 13 TypeScript Updated 7d ago Score 61 Security

icoretech/warden-mcp C MCP Server Active

icoretech/warden-mcp

MCP server for Bitwarden and Vaultwarden vault management. Search, create, edit, and organize logins, notes, cards, identities, SSH keys, folders, collections, attachments, and Sends via the official `bw` CLI.

★ 12 TypeScript Updated yesterday Score 61 Security

sint-ai/sint-protocol C MCP Server Active

sint-ai/sint-protocol

Security-first MCP governance proxy (`sint-mcp`) with capability tokens, T0-T3 approval tiers, fail-closed execution, and tamper-evident audit receipts. Includes a separate `sint-scan` CLI for preflight MCP tool-risk audits.

★ 12 TypeScript Updated yesterday Score 61 Security

quantakrypto/pqc-tools C MCP Server Active

quantakrypto/pqc-tools

Post-quantum readiness for AI coding agents: scan code for quantum-vulnerable cryptography (RSA/ECDH/ECDSA/DH), explain the harvest-now-decrypt-later exposure, get NIST ML-KEM/ML-DSA/SLH-DSA (and hybrid) migration guidance, verify fixes, and check dependencies. Content-based/advisory tools only. Run local (`npx @quantakrypto/mcp`) or the hosted OAuth endpoint at [mcp.quantakrypto.com](https://mcp.

★ 10 TypeScript Updated 2d ago Score 60 Security

Rul1an/assay C MCP Server Active

Rul1an/assay

Policy-as-code gate for MCP. A fail-closed proxy that denies risky tool calls before they run, produces offline-verifiable evidence bundles of what executed, and enforces IPv4/TCP egress in-kernel via eBPF/LSM and Landlock on Linux. Deterministic and offline-first.

★ 9 Rust Updated today Score 60 Security

alexar76/argus C MCP Server Official Active

alexar76/argus

ARGUS-3 as a stdio MCP server** (`argus mcp` → `argus_ask`, `argus_status`). **WARDEN** vets third-party MCP servers before any tool runs (LUMEN-scored firewall, tool-def pinning, drift sentinel). Distinct from `aimarket-oracle-gateway` (oracle tools) and `aimarket-plugins` (hub packager). npm `@alexar76/argus3` · [live](https://magic-ai-factory.com/argus/).

★ 0 TypeScript Updated yesterday Score 60 Security

OrygnsCode/opa-mcp-server C MCP Server Active

OrygnsCode/opa-mcp-server

Open Policy Agent (OPA) and Rego policy toolkit. 32 tools spanning authoring (format, lint, check, deps), evaluation (eval, test, bench, coverage), and OPA REST control (policies, data, decisions, compile). Wraps the OPA CLI and the [Regal](https://github.com/StyraInc/regal) linter, with AI-assisted helpers for explaining decisions, generating test skeletons, and suggesting fixes.

★ 7 TypeScript Updated 7d ago Score 59 Security

taniwhaai/arai C MCP Server Active

taniwhaai/arai

Policy enforcement for AI coding agents derived from existing instruction files (CLAUDE.md, .cursorrules, .windsurfrules, .github/copilot-instructions.md) — no separate YAML to maintain. Rules with prohibitive predicates (`never`, `forbids`, `must_not`) emit `permissionDecision: deny` to block tool calls in Claude Code; advisory rules inject context. PostToolUse is correlated with PreToolUse to pr

★ 7 Rust Updated today Score 59 Security

jyjune/mcp_vms C MCP Server Active

jyjune/mcp_vms

A Model Context Protocol (MCP) server designed to connect to a CCTV recording program (VMS) to retrieve recorded and live video streams. It also provides tools to control the VMS software, such as showing live or playback dialogs for specific channels at specified times.

★ 17 Python Updated yesterday Score 58 Security

AperionAI/shield C MCP Server Active

AperionAI/shield

Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or Streamable HTTP) and blocks destructive tool calls — DROP TABLE, rm -rf, force-push — before they execute. MCP supply-chain protection: TOFU tool-catalog pinning against rug pulls, plus tool-description and tool-result scanning for tool poisoning and prompt injection. 51 starter rules, approval gates, audit logging. Single

★ 6 Rust Updated 9d ago Score 58 Security

zyx77550/sparda C MCP Server Active

zyx77550/sparda

Injects a live, reversible MCP server into a running Express / FastAPI / Next.js app — reads safe by default, writes gated behind human confirmation. The same engine also proves deploys and PRs (`apocalypse` / `review`).

★ 5 JavaScript Updated 14d ago Score 58 Security

mopanc/depguard C MCP Server Active

mopanc/depguard

Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.

★ 15 TypeScript Updated today Score 57 Security

goklab/guardvibe C MCP Server Active

goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

★ 4 TypeScript Updated 21d ago Score 57 Security

StacklokLabs/osv-mcp C MCP Server Active

StacklokLabs/osv-mcp

Access the OSV (Open Source Vulnerabilities) database for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID.

★ 38 Go Updated today Score 56 Security

nagameTW/mcp-server-malcolm C MCP Server Active

nagameTW/mcp-server-malcolm

The first MCP server for [Malcolm](https://malcolm.fyi), the open-source network traffic analysis suite (Zeek + Suricata + Arkime + OpenSearch + NetBox). Gives AI agents structured, threat-hunting access: search and aggregate traffic, discover fields, query Suricata alerts, browse Arkime sessions, and resolve NetBox assets. Read-only by default; opt-in, audited write classes for alerts, tagging, h

★ 3 Python Updated 2d ago Score 56 Security