Home › MCP Servers

MCP Servers

Browse all Model Context Protocol servers with quality scores, stars, languages and maintenance activity.

Filters (1 active)
190 results (<1ms) · data updated 2026-08-14

Results

AperionAI/shield C MCP Server Active

AperionAI/shield

Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or Streamable HTTP) and blocks destructive tool calls — DROP TABLE, rm -rf, force-push — before they execute. MCP supply-chain protection: TOFU tool-catalog pinning against rug pulls, plus tool-description and tool-result scanning for tool poisoning and prompt injection. 51 starter rules, approval gates, audit logging. Single

★ 6 Rust Updated 9d ago Score 58 Security

zyx77550/sparda C MCP Server Active

zyx77550/sparda

Injects a live, reversible MCP server into a running Express / FastAPI / Next.js app — reads safe by default, writes gated behind human confirmation. The same engine also proves deploys and PRs (`apocalypse` / `review`).

★ 5 JavaScript Updated 14d ago Score 58 Security

BurtTheCoder/mcp-maigret C MCP Server Stale

BurtTheCoder/mcp-maigret

MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

★ 256 JavaScript Updated 6mo ago Score 57 Security

mopanc/depguard C MCP Server Active

mopanc/depguard

Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer is implemented natively against the public CycloneDX schema.

★ 15 TypeScript Updated today Score 57 Security

goklab/guardvibe C MCP Server Active

goklab/guardvibe

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

★ 4 TypeScript Updated 21d ago Score 57 Security

StacklokLabs/osv-mcp C MCP Server Active

StacklokLabs/osv-mcp

Access the OSV (Open Source Vulnerabilities) database for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID.

★ 38 Go Updated today Score 56 Security

nagameTW/mcp-server-malcolm C MCP Server Active

nagameTW/mcp-server-malcolm

The first MCP server for [Malcolm](https://malcolm.fyi), the open-source network traffic analysis suite (Zeek + Suricata + Arkime + OpenSearch + NetBox). Gives AI agents structured, threat-hunting access: search and aggregate traffic, discover fields, query Suricata alerts, browse Arkime sessions, and resolve NetBox assets. Read-only by default; opt-in, audited write classes for alerts, tagging, h

★ 3 Python Updated 2d ago Score 56 Security

knowledgepa3/gia-mcp-server C MCP Server Active

knowledgepa3/gia-mcp-server

Enterprise AI governance layer with 29 tools: MAI decision classification (Mandatory/Advisory/Informational), hash-chained forensic audit trails, human-in-the-loop gates, compliance mapping (NIST AI RMF, EU AI Act, ISO 42001), governed memory packs, and site reliability tools.

★ 3 TypeScript Updated 14d ago Score 56 Security

I4cTime/quantum_ring C MCP Server Active

I4cTime/quantum_ring

Quantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation.

★ 3 TypeScript Updated 4d ago Score 56 Security

LaurieWired/GhidraMCP C MCP Server Inactive

LaurieWired/GhidraMCP

A Model Context Protocol server for Ghidra that enables LLMs to autonomously reverse engineer applications. Provides tools for decompiling binaries, renaming methods and data, and listing methods, classes, imports, and exports.

★ 9.8k Java Updated 1y ago Score 55 Security

BurtTheCoder/mcp-shodan C MCP Server Stale

BurtTheCoder/mcp-shodan

MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.

★ 152 TypeScript Updated 4mo ago Score 55 Security

Chimera-Protocol/csl-core C MCP Server Maintained

Chimera-Protocol/csl-core

Deterministic AI safety policy engine with Z3 formal verification. Write, verify, and enforce machine-verifiable constraints for AI agents via MCP.

★ 16 Python Updated 2mo ago Score 55 Security

RoscoNL/intodns-mcp-server C MCP Server Active

RoscoNL/intodns-mcp-server

Free DNS and email security scanner for AI assistants. DNS, SPF, DKIM, DMARC, DNSSEC, MTA-STS, BIMI, TLS/STARTTLS, FCrDNS, CAA, TLSA/DANE, blacklist and full-deliverability checks, plus security-header/CSP analysis and bookmarkable report snapshots, via the IntoDNS.ai API. No signup or API key. `npx intodns-mcp`

★ 2 TypeScript Updated 27d ago Score 55 Security

beeswaxpat/chronoverify-mcp C MCP Server Active

beeswaxpat/chronoverify-mcp

Verify a photo's capture time and provenance before an agent trusts it: cryptographic C2PA Content Credentials validation against the official trust lists, EXIF and XMP consistency checks, and classical pixel forensics fused into one typed verdict with a 0 to 100 confidence. Free keyless tier, opt-in shareable verdict permalinks, and key-gated signed PDF audit reports. Provenance validation, not a

★ 2 JavaScript Updated 7d ago Score 55 Security

airblackbox/air-blackbox-mcp C MCP Server Active

airblackbox/air-blackbox-mcp

EU AI Act compliance scanner for Python AI agents. Scans, analyzes, and remediates LangChain/CrewAI/AutoGen/OpenAI code across 6 articles with 10 tools including prompt injection detection, risk classification, and trust layer integration. The only MCP compliance server that generates fix code, not just findings.

★ 2 Python Updated 8d ago Score 55 Security

Buggy1111/anonymize-mcp C MCP Server Active

Buggy1111/anonymize-mcp

Anonymize PII and redact text for GDPR across Czech and 35+ languages. Real NLP via ÚFAL/LINDAT (MasKIT + NameTag NER, not just regex), 80+ PII patterns, plus morphology, translation, and spellcheck. Czech-first, non-commercial. Install: `pip install anonymize-mcp`.

★ 2 Python Updated 2d ago Score 55 Security

Declade/lucairn-sdks C MCP Server Active

Declade/lucairn-sdks

Privacy-preserving AI gateway. Sanitises PII (German + English; Microsoft Presidio + custom recognisers) before prompts reach Anthropic / OpenAI / your LLM, then emits a signed cryptographic certificate per call (Ed25519 + RFC 3161 timestamp + Sigstore Rekor anchoring). EU GDPR + AI Act ready. Free tier 500 calls/month, BYOK. Install: `npx -y @lucairn/mcp-server`. Docs: https://lucairn.eu/develope

★ 2 TypeScript Updated 13d ago Score 55 Security

zw008/VMware-Harden C MCP Server Active

zw008/VMware-Harden

VMware vSphere compliance and hardening — read-only baseline scanning plus drift detection across CIS, vSphere SCG, China DJCP 2.0, and PCI-DSS frameworks. 6 read-only tools with LLM-powered remediation suggestions (apply-side gated through vmware-pilot approval workflow).

★ 2 Python Updated yesterday Score 55 Security

WRG-11/wrg-sigma-rules C MCP Server Active

WRG-11/wrg-sigma-rules

Sigma detection rule writing, validation, and conversion (Splunk/Elastic/Kibana/Wazuh) via 3 MCP tools (`draft_rule`, `validate_rule`, `convert_rule`) backed by a 61-rule production corpus across 11 MITRE ATT&CK tactic categories. Standalone server + Claude Code plugin distribution.

★ 2 Python Updated 2d ago Score 55 Security

calllint/calllint C MCP Server Active

calllint/calllint

Pre-flight security linter for MCP servers, agent tools, and skills. Scans a config *before* it runs — offline, deterministic, evidence-backed — and returns SAFE / REVIEW / BLOCK / UNKNOWN verdicts without executing the server it judges. CLI (`npx calllint scan`), MCP server (`npx calllint-mcp`), SARIF + CI gate. UNKNOWN is never SAFE.

★ 2 TypeScript Updated today Score 55 Security

shieldly-io/mcp C MCP Server Official Active

shieldly-io/mcp

Official [Shieldly](https://www.shieldly.io) MCP server: `analyze_iam_policy` and `analyze_cloudformation_template` tools flag AWS IAM privilege-escalation paths, wildcards, and over-permissive access. Free demo mode, no signup or API key needed. `npx -y @shieldly/mcp`.

★ 0 JavaScript Updated 26d ago Score 55 Security

trustscoreagent/trustscoreagent C MCP Server Official Active

trustscoreagent/trustscoreagent

Check the reputation of an AI microservice or public API *before* calling it, and submit ratings afterward — from a free, open trust registry (no account or API key). Scores combine Bayesian reputation and EigenTrust, strengthened by cryptographically signed service receipts and a Merkle audit trail. Install: `npx -y @trustscoreagent/mcp-server`.

★ 0 C# Updated today Score 55 Security

fosdickio/binary_ninja_mcp C MCP Server Stale

fosdickio/binary_ninja_mcp

A Binary Ninja plugin, MCP server, and bridge that seamlessly integrates [Binary Ninja](https://binary.ninja) with your favorite MCP client. It enables you to automate the process of performing binary analysis and reverse engineering.

★ 417 Python Updated 4mo ago Score 54 Security

loglux/authmcp-gateway C MCP Server Maintained

loglux/authmcp-gateway

Auth proxy for MCP servers: OAuth2 + DCR, JWT, RBAC, rate limiting, multi-server aggregation, and monitoring dashboard.

★ 11 Python Updated 1mo ago Score 54 Security

rafapra3008/cervellaswarm C MCP Server Maintained

rafapra3008/cervellaswarm/packages/mcp-server

Verify AI agent communication protocols using session types. Formal specification with Lean 4 proofs, linter, formatter, and LSP. Catches deadlocks and role violations before deployment.

★ 10 Python Updated 2mo ago Score 53 Security

tomjwxf/scopeblind-gateway C MCP Server Maintained

tomjwxf/scopeblind-gateway

Security gateway that wraps any MCP server with per-tool policies, approval gates, and optional Ed25519-signed receipts. Shadow mode logs every tool call; enforce mode blocks, rate-limits, or requires approval.

★ 9 TypeScript Updated 1mo ago Score 53 Security

takleb3rry/zitadel-mcp C MCP Server Maintained

takleb3rry/zitadel-mcp

MCP server for Zitadel identity management — manage users, projects, OIDC apps, roles, and service accounts through natural language.

★ 9 TypeScript Updated 1mo ago Score 53 Security

chasdaddy/basescope C MCP Server Active

chasdaddy/basescope

The read-only safety layer for onchain AI agents. 13 read-only tools on Base + EVM: token/contract safety (honeypot & rug-pull checks cross-referenced across GoPlus + honeypot.is), risky-approval detection, verified-source lookup, balances, ENS + Basenames, gas, and prices. No private keys, no required API keys. `npx -y basescope`

★ 1 TypeScript Updated 25d ago Score 53 Security

askalf/truecopy C MCP Server Active

askalf/truecopy

Supply-chain gate for agent skills and MCP servers — scans tool definitions for poisoned instructions, pins vetted servers by content hash in a committed lock, and verifies drift in CI; the bundled truecopy-mcp proxy exposes only pinned, unmodified tools from a live server.

★ 1 JavaScript Updated today Score 53 Security

Fronesis-Labs/dcl-webhook C MCP Server Active

Fronesis-Labs/dcl-webhook

Deterministic AI audit layer: evaluates LLM/agent outputs against configurable policies (jailbreak, safety, quality, wallet, trade, MEV compliance) and writes every verdict to a tamper-evident SHA-256 hash chain — metadata only, never raw content. 17 tools including a full crypto-trading compliance suite. Pay-per-call via x402 (USDC on Base), from $0.01. `mcp.fronesislabs.com/mcp`

★ 1 Python Updated today Score 53 Security

AgentValet/AgentValet C MCP Server Active

AgentValet/AgentValet

Identity and credential governance broker for MCP servers. Issues scoped, short-lived credentials per agent to stop credential inheritance. Audit log, human approval gates, AIMS-aligned.

★ 1 TypeScript Updated yesterday Score 53 Security

infai-tech/vulnfeed-mcp C MCP Server Active

infai-tech/vulnfeed-mcp

Dependency vulnerability scanner with EPSS exploit probability scoring. Scans lockfiles (npm, pip, Go, Cargo, Ruby, Composer, Gradle, NuGet, Mix), prioritizes by real-world exploit likelihood, recommends fix versions. 9 MCP tools for scanning, monitoring, and alerting. Free tier + x402 micropayments. `pip install vulnfeed-mcp`

★ 1 Python Updated 22d ago Score 53 Security

joergmichno/clawguard-mcp C MCP Server Active

joergmichno/clawguard-mcp

Security scanner for AI agents that detects prompt injections using 42+ regex patterns

★ 1 Python Updated 24d ago Score 53 Security

mrz1880/mcp-keycloak-admin C MCP Server Active

mrz1880/mcp-keycloak-admin

Administer Keycloak through its Admin REST API — users, roles, clients, groups, identity providers, federation and events. Safe by default: read-only mode, realm allow-list, and confirmation for destructive actions. `npx -y mcp-keycloak-admin`

★ 1 TypeScript Updated yesterday Score 53 Security

Pentagonal-ai/pentagonal C MCP Server Active

Pentagonal-ai/pentagonal

AI-powered smart contract security forge with 8-agent adversarial pen test. Generate, audit, fix, and compile contracts across 8 chains (Ethereum, Solana, Polygon, Base, Arbitrum, Optimism, BSC, Avalanche). Token intelligence with honeypot detection. x402 USDC payments for autonomous agents.

★ 1 TypeScript Updated 17d ago Score 53 Security

gbrigandi/mcp-server-wazuh C MCP Server Stale

gbrigandi/mcp-server-wazuh

A Rust-based MCP server bridging Wazuh SIEM with AI assistants, providing real-time security alerts and event data for enhanced contextual understanding.

★ 233 Rust Updated 8mo ago Score 52 Security

P4ST4S/mcp-audit C MCP Server Maintained

P4ST4S/mcp-audit

Transparent Go proxy that intercepts, signs, rate-limits, redacts, and audits all MCP JSON-RPC tool calls without modifying client or server.

★ 7 Go Updated 1mo ago Score 52 Security

piiiico/proof-of-commitment C MCP Server Maintained

piiiico/proof-of-commitment

Supply chain risk scoring for npm, PyPI, Cargo, and Go packages. 9 tools for behavioral trust signals — publisher depth, release consistency, maintenance patterns. Both axios and node-ipc scored CRITICAL before they got attacked. Free CLI, CI gate, REST API. No API key required.

★ 7 TypeScript Updated 1mo ago Score 52 Security

yessGlory17/job-verify C MCP Server Maintained

yessGlory17/job-verify

Check whether a recruiter or job offer is a scam before you reply. Extracts entities (company, links, email, phone, wallets) from a pasted message and cross-checks company registration, domain age, look-alike/typosquat domains, phishing & malware blocklists, email deliverability, crypto-scam databases, and Internet Archive history — free OSINT, no API keys.

★ 7 Python Updated 1mo ago Score 52 Security

layervai/qurl-mcp C MCP Server Active

layervai/qurl-mcp

Mint, resolve, audit, and rotate expiring scope-limited access links (qURLs) for AI agents — secure URL gateway for the qURL API. 9 tools (create / resolve / list / get / delete / extend / update / mint-link / batch-create), 3 resources, 3 guided prompts. stdio transport, OIDC-attested npm provenance.

★ 4 TypeScript Updated yesterday Score 52 Security

securityfortech/secops-mcp C MCP Server Stale

securityfortech/secops-mcp

All-in-one security testing toolbox that brings together popular open source tools through a single MCP interface. Connected to an AI agent, it enables tasks like pentesting, bug bounty hunting, threat hunting, and more.

★ 206 Python Updated 11mo ago Score 51 Security

agentward-ai/agentward C MCP Server Maintained

agentward-ai/agentward

Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

★ 19 Python Updated 1mo ago Score 51 Security

ajipurn/fida C MCP Server Maintained

ajipurn/fida

Local-first MCP gateway for coding agents that redacts detected secrets from file reads and command output before they reach model context.

★ 18 Rust Updated 1mo ago Score 51 Security

MARUCIE/authbox C MCP Server Maintained

MARUCIE/authbox

Zero-knowledge password manager with MCP credential gateway. BIP-39 seed phrase recovery, deterministic passwords, policy-gated AI agent access (scope, rate limits, time windows, step-up approval), 70+ API key providers, and hash-chain audit trail. Go + Next.js + TypeScript.

★ 5 HTML Updated 1mo ago Score 51 Security

ScopeBlind/verify-mcp C MCP Server Maintained

ScopeBlind/verify-mcp

Offline verification of signed artifacts -- receipts, manifests, audit bundles. Ed25519 + JCS. No accounts, no API calls. Apache-2.0.

★ 5 JavaScript Updated 1mo ago Score 51 Security

agentgraph-co/agentgraph C MCP Server Active

agentgraph-co/agentgraph

Trust verification and security scanning for AI agents. Checks security posture of third-party MCP servers and tools with signed attestations (Ed25519/JWS) before interaction.

★ 3 Python Updated today Score 51 Security

datanexusmcp/mcp-server C MCP Server Active

datanexusmcp/mcp-server

55 tools for verified public data lookups — CVE/SBOM security audits, licence compliance, patents, federal contracts, NPI provider lookups, nonprofit 990 filings, and domain intelligence. No API key required.

★ 3 Python Updated 14d ago Score 51 Security

MoltyCel/moltrust-mcp-server C MCP Server Active

MoltyCel/moltrust-mcp-server

Trust infrastructure for AI agents — register DIDs, verify identities, query reputation scores, rate agents, manage W3C Verifiable Credentials, and handle USDC credit deposits on Base.

★ 3 Python Updated 16d ago Score 51 Security