Home › MCP Servers

MCP Servers

Browse all Model Context Protocol servers with quality scores, stars, languages and maintenance activity.

Filters (2 active)
Status
Official3
Install method
npm / npx59Docker2
61 results (<1ms) · data updated 2026-08-14

Results

emiliaprotocol/emilia-protocol B MCP Server Active

emiliaprotocol/emilia-protocol

Human sign-off + trust receipts for AI agents: requires a named human's approval before an irreversible action (payment release, record change, deploy), then mints an offline-verifiable Ed25519 Trust Receipt. Also exposes trust profiles, receipt verification, disputes, and delegation. Apache-2.0; policy engine formally verified. Install: `npx -y @emilia-protocol/mcp-server`.

★ 841 TypeScript Updated today Score 79 Security

mobb-dev/mobb-vibe-shield-mcp B MCP Server Official Active

mobb-dev/bugsy

[Mobb Vibe Shield](https://vibe.mobb.ai/) identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications remain secure without slowing development.

★ 68 TypeScript Updated today Score 78 Security

kastelldev/kastell B MCP Server Active

kastelldev/kastell

Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.

★ 56 TypeScript Updated yesterday Score 68 Security

Synvoya/codeinspectus B MCP Server Active

Synvoya/codeinspectus

Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.

★ 39 TypeScript Updated 8d ago Score 66 Security

arian-gogani/nobulex B MCP Server Active

arian-gogani/nobulex

Proof-of-behavior enforcement for AI agents. Define behavioral covenant rules (permit/forbid/require), enforce at runtime before execution, get SHA-256 hash-chained tamper-evident audit logs, and verify compliance independently. Cross-agent verification handshake — no proof, no transaction. MIT licensed, 4,244 tests.

★ 38 TypeScript Updated 10d ago Score 66 Security

BurtTheCoder/mcp-virustotal B MCP Server Maintained

BurtTheCoder/mcp-virustotal

MCP server for querying the VirusTotal API. This server provides tools for scanning URLs, analyzing file hashes, and retrieving IP address reports.

★ 143 TypeScript Updated 2mo ago Score 65 Security

jnMetaCode/shellward C MCP Server Maintained

jnMetaCode/shellward

AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.

★ 131 TypeScript Updated 1mo ago Score 64 Security

vespo92/OPNSenseMCP C MCP Server Active

vespo92/OPNSenseMCP

MCP Server for managing & interacting with Open Source NGFW OPNSense via Natural Language

★ 77 TypeScript Updated 23d ago Score 64 Security

mastyf-ai/mastyf.ai C MCP Server Active

mastyf-ai/mastyf.ai

Open-source runtime security proxy for MCP. Transparently intercepts every tools/call through an 18-class attack defense pipeline (prompt injection, SSRF, shell injection, SQL injection, credential exfil, polyglot attacks) with a YAML policy engine and 304-entry adversarial corpus. Trust scoring for npm MCP packages with 0-100 badges. Cloud dashboard, Docker image, Python SDK. MIT.

★ 17 TypeScript Updated 6d ago Score 63 Security

kakunin-ai/kakunin-mcp C MCP Server Official Active

kakunin-ai/kakunin-mcp

Compliance and identity for AI agents — verify an agent's certificate scope, read its behavioral risk score, and append to an immutable audit trail. X.509 identity issued via AWS KMS; MiCA / EU AI Act aligned. `npx -y @kakunin/mcp`

★ 1 TypeScript Updated 2d ago Score 63 Security

sgateway/s-gw C MCP Server Active

sgateway/s-gw

Local credential approval and execution gateway for AI coding agents. Agents receive typed handles instead of raw API tokens, SSH keys, and cloud credentials; one-time approvals bind the credential, command, arguments, working directory, environment bindings, and target. Injects credentials only into the approved child process, sanitizes output, and records a local audit trail. Install with `npm i

★ 15 TypeScript Updated today Score 62 Security

sidclawhq/platform C MCP Server Active

sidclawhq/platform

Governance proxy for MCP servers. Wraps any upstream server with policy evaluation, human approval workflows, and hash-chain audit trails. 18+ framework integrations. Apache 2.0 SDK.

★ 14 TypeScript Updated 3d ago Score 62 Security

getaegis/aegis C MCP Server Active

getaegis/aegis

Credential isolation proxy for AI agents. Injects secrets at the network boundary with domain restrictions, agent authentication, and audit logging. No SDK required — works as a transparent HTTP proxy or MCP server.

★ 13 TypeScript Updated 7d ago Score 61 Security

icoretech/warden-mcp C MCP Server Active

icoretech/warden-mcp

MCP server for Bitwarden and Vaultwarden vault management. Search, create, edit, and organize logins, notes, cards, identities, SSH keys, folders, collections, attachments, and Sends via the official `bw` CLI.

★ 12 TypeScript Updated yesterday Score 61 Security

sint-ai/sint-protocol C MCP Server Active

sint-ai/sint-protocol

Security-first MCP governance proxy (`sint-mcp`) with capability tokens, T0-T3 approval tiers, fail-closed execution, and tamper-evident audit receipts. Includes a separate `sint-scan` CLI for preflight MCP tool-risk audits.

★ 12 TypeScript Updated yesterday Score 61 Security

quantakrypto/pqc-tools C MCP Server Active

quantakrypto/pqc-tools

Post-quantum readiness for AI coding agents: scan code for quantum-vulnerable cryptography (RSA/ECDH/ECDSA/DH), explain the harvest-now-decrypt-later exposure, get NIST ML-KEM/ML-DSA/SLH-DSA (and hybrid) migration guidance, verify fixes, and check dependencies. Content-based/advisory tools only. Run local (`npx @quantakrypto/mcp`) or the hosted OAuth endpoint at [mcp.quantakrypto.com](https://mcp.

★ 10 TypeScript Updated 2d ago Score 60 Security

alexar76/argus C MCP Server Official Active

alexar76/argus

ARGUS-3 as a stdio MCP server** (`argus mcp` → `argus_ask`, `argus_status`). **WARDEN** vets third-party MCP servers before any tool runs (LUMEN-scored firewall, tool-def pinning, drift sentinel). Distinct from `aimarket-oracle-gateway` (oracle tools) and `aimarket-plugins` (hub packager). npm `@alexar76/argus3` · [live](https://magic-ai-factory.com/argus/).

★ 0 TypeScript Updated yesterday Score 60 Security

OrygnsCode/opa-mcp-server C MCP Server Active

OrygnsCode/opa-mcp-server

Open Policy Agent (OPA) and Rego policy toolkit. 32 tools spanning authoring (format, lint, check, deps), evaluation (eval, test, bench, coverage), and OPA REST control (policies, data, decisions, compile). Wraps the OPA CLI and the [Regal](https://github.com/StyraInc/regal) linter, with AI-assisted helpers for explaining decisions, generating test skeletons, and suggesting fixes.

★ 7 TypeScript Updated 7d ago Score 59 Security

mopanc/depguard C MCP Server Active

mopanc/depguard

Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.

★ 15 TypeScript Updated today Score 57 Security

goklab/guardvibe C MCP Server Active

goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

★ 4 TypeScript Updated 21d ago Score 57 Security

knowledgepa3/gia-mcp-server C MCP Server Active

knowledgepa3/gia-mcp-server

Enterprise AI governance layer with 29 tools: MAI decision classification (Mandatory/Advisory/Informational), hash-chained forensic audit trails, human-in-the-loop gates, compliance mapping (NIST AI RMF, EU AI Act, ISO 42001), governed memory packs, and site reliability tools.

★ 3 TypeScript Updated 14d ago Score 56 Security

I4cTime/quantum_ring C MCP Server Active

I4cTime/quantum_ring

Quantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation.

★ 3 TypeScript Updated 4d ago Score 56 Security

BurtTheCoder/mcp-shodan C MCP Server Stale

BurtTheCoder/mcp-shodan

MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.

★ 152 TypeScript Updated 4mo ago Score 55 Security

RoscoNL/intodns-mcp-server C MCP Server Active

RoscoNL/intodns-mcp-server

Free DNS and email security scanner for AI assistants. DNS, SPF, DKIM, DMARC, DNSSEC, MTA-STS, BIMI, TLS/STARTTLS, FCrDNS, CAA, TLSA/DANE, blacklist and full-deliverability checks, plus security-header/CSP analysis and bookmarkable report snapshots, via the IntoDNS.ai API. No signup or API key. `npx intodns-mcp`

★ 2 TypeScript Updated 27d ago Score 55 Security

Declade/lucairn-sdks C MCP Server Active

Declade/lucairn-sdks

Privacy-preserving AI gateway. Sanitises PII (German + English; Microsoft Presidio + custom recognisers) before prompts reach Anthropic / OpenAI / your LLM, then emits a signed cryptographic certificate per call (Ed25519 + RFC 3161 timestamp + Sigstore Rekor anchoring). EU GDPR + AI Act ready. Free tier 500 calls/month, BYOK. Install: `npx -y @lucairn/mcp-server`. Docs: https://lucairn.eu/develope

★ 2 TypeScript Updated 13d ago Score 55 Security

calllint/calllint C MCP Server Active

calllint/calllint

Pre-flight security linter for MCP servers, agent tools, and skills. Scans a config *before* it runs — offline, deterministic, evidence-backed — and returns SAFE / REVIEW / BLOCK / UNKNOWN verdicts without executing the server it judges. CLI (`npx calllint scan`), MCP server (`npx calllint-mcp`), SARIF + CI gate. UNKNOWN is never SAFE.

★ 2 TypeScript Updated today Score 55 Security

tomjwxf/scopeblind-gateway C MCP Server Maintained

tomjwxf/scopeblind-gateway

Security gateway that wraps any MCP server with per-tool policies, approval gates, and optional Ed25519-signed receipts. Shadow mode logs every tool call; enforce mode blocks, rate-limits, or requires approval.

★ 9 TypeScript Updated 1mo ago Score 53 Security

takleb3rry/zitadel-mcp C MCP Server Maintained

takleb3rry/zitadel-mcp

MCP server for Zitadel identity management — manage users, projects, OIDC apps, roles, and service accounts through natural language.

★ 9 TypeScript Updated 1mo ago Score 53 Security

chasdaddy/basescope C MCP Server Active

chasdaddy/basescope

The read-only safety layer for onchain AI agents. 13 read-only tools on Base + EVM: token/contract safety (honeypot & rug-pull checks cross-referenced across GoPlus + honeypot.is), risky-approval detection, verified-source lookup, balances, ENS + Basenames, gas, and prices. No private keys, no required API keys. `npx -y basescope`

★ 1 TypeScript Updated 25d ago Score 53 Security

AgentValet/AgentValet C MCP Server Active

AgentValet/AgentValet

Identity and credential governance broker for MCP servers. Issues scoped, short-lived credentials per agent to stop credential inheritance. Audit log, human approval gates, AIMS-aligned.

★ 1 TypeScript Updated yesterday Score 53 Security

mrz1880/mcp-keycloak-admin C MCP Server Active

mrz1880/mcp-keycloak-admin

Administer Keycloak through its Admin REST API — users, roles, clients, groups, identity providers, federation and events. Safe by default: read-only mode, realm allow-list, and confirmation for destructive actions. `npx -y mcp-keycloak-admin`

★ 1 TypeScript Updated yesterday Score 53 Security

Pentagonal-ai/pentagonal C MCP Server Active

Pentagonal-ai/pentagonal

AI-powered smart contract security forge with 8-agent adversarial pen test. Generate, audit, fix, and compile contracts across 8 chains (Ethereum, Solana, Polygon, Base, Arbitrum, Optimism, BSC, Avalanche). Token intelligence with honeypot detection. x402 USDC payments for autonomous agents.

★ 1 TypeScript Updated 17d ago Score 53 Security

piiiico/proof-of-commitment C MCP Server Maintained

piiiico/proof-of-commitment

Supply chain risk scoring for npm, PyPI, Cargo, and Go packages. 9 tools for behavioral trust signals — publisher depth, release consistency, maintenance patterns. Both axios and node-ipc scored CRITICAL before they got attacked. Free CLI, CI gate, REST API. No API key required.

★ 7 TypeScript Updated 1mo ago Score 52 Security

layervai/qurl-mcp C MCP Server Active

layervai/qurl-mcp

Mint, resolve, audit, and rotate expiring scope-limited access links (qURLs) for AI agents — secure URL gateway for the qURL API. 9 tools (create / resolve / list / get / delete / extend / update / mint-link / batch-create), 3 resources, 3 guided prompts. stdio transport, OIDC-attested npm provenance.

★ 4 TypeScript Updated yesterday Score 52 Security

behrensd/mcp-firewall C MCP Server Maintained

behrensd/mcp-firewall

Deterministic security proxy (iptables for MCP) that intercepts tool calls, enforces YAML policies, scans for secret leakage, and logs everything. No AI, no cloud.

★ 4 TypeScript Updated 1mo ago Score 50 Security

rudraneel93/mcp-guardian D MCP Server Maintained

rudraneel93/mcp-guardian

Security and governance proxy for MCP infrastructure. Enforces YAML-configurable policies (blocklists, rate limits, token budgets), tracks real token costs via tiktoken, monitors server health with live JSON-RPC probes. Features include OAuth 2.1/OIDC with RBAC, web dashboard with Prometheus metrics, payload normalization against encoding bypasses, semantic shell AST analysis, mTLS zero-trust netw

★ 3 TypeScript Updated 2mo ago Score 49 Security

inkog-io/inkog-mcp D MCP Server Maintained

inkog-io/inkog-mcp

AI agent security scanner. Audits MCP servers for vulnerabilities, detects prompt injection, infinite loops, token bombing, and missing human oversight across 20+ frameworks. Maps findings to EU AI Act, OWASP LLM Top 10.

★ 3 TypeScript Updated 2mo ago Score 49 Security

rad-security/mcp-server D MCP Server Active

rad-security/mcp-server

MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for querying the Rad Security API and retrieving security findings, reports, runtime data and many more.

★ 6 TypeScript Updated 3d ago Score 48 Security

ppcvote/misp-mcp-server D MCP Server Maintained

ppcvote/misp-mcp-server

MISP (Malware Information Sharing Platform) MCP server with built-in prompt injection defense via [prompt-defense-audit](https://github.com/ppcvote/prompt-defense-audit). 8 read-only threat-intel tools (events, attributes, search, tags, feeds, galaxies). Scans every MISP response for adversarial seeding before returning to LLM. Tracks [MISP/MISP#10745](https://github.com/MISP/MISP/issues/10745). M

★ 2 TypeScript Updated 2mo ago Score 48 Security

Chronolapse411/sicarius-guard D MCP Server Maintained

Chronolapse411/sicarius-guard

Solana token safety oracle for AI agents and trading bots. Byte-level SPL mint analysis, honeypot detection, freeze/mint authority checks, Birdeye market enrichment, and composite risk scoring. Deployed on Google Cloud Run.

★ 2 TypeScript Updated 2mo ago Score 48 Security

astafford8488/agentaegis-mcp D MCP Server Active

astafford8488/agentaegis-mcp

Security & trust layer for AI agents. Scan an MCP server or skill *before* you install it (`scan_mcp_plugin`, `scan_skill`) — flags exfiltration, prompt-injection sinks, dangerous capabilities, install hooks and obfuscation → PROCEED/CAUTION/BLOCK. Plus `vet_endpoint` (endpoint safety verdict before an agent calls or pays it) and 25 more tools: vuln scans, threat intel, compliance (SOC 2/ISO 27001

★ 1 TypeScript Updated 2d ago Score 48 Security

operantlabs/operant-mcp D MCP Server Stale

operantlabs/operant-mcp

Security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment.

★ 23 TypeScript Updated 4mo ago Score 47 Security

qinisolabs/qiniso D MCP Server Maintained

qinisolabs/qiniso

56 deterministic fact-checkers in one server (IBAN, VAT, VIN, GTIN/barcodes, national & tax IDs, crypto addresses, phone, dates, holidays) — verify the structured facts an agent emits against checksums and curated data.

★ 1 TypeScript Updated 1mo ago Score 46 Security

chrbailey/promptspeak-mcp-server D MCP Server Maintained

chrbailey/promptspeak-mcp-server

Pre-execution governance for AI agents. Intercepts and validates every agent tool call through an 8-stage pipeline before execution — risk classification, behavioral drift detection, hold queue for dangerous operations, and complete audit trail. 45 tools, 658 tests.

★ 1 TypeScript Updated 1mo ago Score 46 Security

OksigeniaSL/checker-mcp D MCP Server Active

OksigeniaSL/checker-mcp

Domain security & privacy checker: 17 live checks (SPF, DMARC, DKIM, DNSSEC, TLS, CAA, security headers) scored 0-100 with remediation. Local-first, zero telemetry. In the official MCP Registry as `com.oksigenia/checker-mcp`; npm `@oksigenia/checker-mcp`.

★ 0 TypeScript Updated 22d ago Score 45 Security

firstorderai/authenticator_mcp D MCP Server Stale

firstorderai/authenticator_mcp

A secure MCP (Model Context Protocol) server that enables AI agents to interact with the Authenticator App.

★ 42 TypeScript Updated 4mo ago Score 44 Security

qianniuspace/mcp-security-audit D MCP Server Inactive

qianniuspace/mcp-security-audit

A powerful MCP (Model Context Protocol) Server that audits npm package dependencies for security vulnerabilities. Built with remote npm registry integration for real-time security checks.

★ 56 TypeScript Updated 1y ago Score 43 Security

jamjet-labs/jamjet-policy D MCP Server Maintained

jamjet-labs/jamjet-policy/packages/mcp-shim

MCP stdio interceptor (`@jamjet/mcp-shim`) that applies one YAML policy file (block / require_approval / audit / budget cap) to `tools/call` requests before they reach the real MCP server. The same policy also runs in Claude Code PreToolUse hooks (`@jamjet/claude-code-hook`), OpenAI Agents SDK guardrails (`@jamjet/openai-guardrail`), and JamJet's Python/TS SDKs — `jamjet audit show` tails every de

★ 2 TypeScript Updated 1mo ago Score 43 Security