Category
Security MCP servers
- 01
Active17kPython - 02
Ida PromrexodiaIDA Pro plugin for binary analysis: decompilation, disassembly and automatic malware analysis reports.
Active13kPythonActive13kPython - 03
GhidralauriewiredAutonomous reverse engineering with Ghidra: decompile binaries, rename methods and data, and list methods, classes, imports and exports.
Abandoned11kJavaAbandoned11kJava - 04
Robin: AI-Powered Dark Web OSINTapurvsinghgautamDark web OSINT over Tor: search onion engines, scrape pages, report with your own model.
Active7.5kDockerstdioActive7.5kDockerstdio - 05
Claude Code Ultimate GuideflorianbruniauxSearch the Claude Code Ultimate Guide, official Anthropic documentation, releases, examples, security references, agent harness data, and translations from any MCP-compatible client.
Active6.1kNode.jsstdioActive6.1kNode.jsstdio - 06
Jadx AIzinja-coderJADX decompiler plugin providing live, LLM-assisted reverse engineering.
Active2.9kJavaActive2.9kJava - 07
ToolhivestacklokA lightweight utility designed to simplify the deployment and management of MCP servers, ensuring ease of use, consistency, and security through containerization
Active2.3kActive2.3k - 08
BeelzebubmariocandelaHoneypot framework for building decoy MCP tools that an agent would never use in normal work, to detect prompt injection and malicious agent behavior.
Active2.2kActive2.2k - 09
JshookvmoranvMCP server for JavaScript analysis, security auditing, browser automation and hooks
Active2.0kNode.jsstdioActive2.0kNode.jsstdio - 10
OpenOSINTopenosintAI-powered OSINT agent & MCP server. 21 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.
Active1.7kPythonstdioActive1.7kPythonstdio - 11
MySQLdesigncomputerMySQL database integration with configurable access controls, schema inspection and security guidelines.
Maintained1.4kPythonMaintained1.4kPython - 12SafeDep Vetsafedep
Locally check npm and PyPI packages, such as those suggested by AI coding tools, for vulnerabilities and malicious code.
Active1.1kDockerstdioActive1.1kDockerstdio - 13
SkylosduriantacoDead code detection, security scanning and code quality analysis for Python, TypeScript and Go, with AI-assisted remediation.
Active844PythonstdioActive844Pythonstdio - 14
HOL Guardhashgraph-onlineLocal-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.
Active828PythonstdioActive828Pythonstdio - 15
DriftdetectdadbodgeoffMCP server that gives AI agents (Claude, Cursor, Copilot) deep understanding of your codebase patterns, conventions, and architecture. Query patterns, security boundaries, call graphs in real-time.
Maintained790Node.jsstdioMaintained790Node.jsstdio - 16
Ghidrassistjtang613Native Ghidra integration with GUI configuration, logging and no external dependencies.
Maintained764JavaMaintained764Java - 17
KodykentcdoddsPersonal assistant MCP server with search, execute, packages, jobs, secrets, and integrations.
Active750remoteActive750remote - 18
Abandoned687 - 19
Slowing667Python - 20
Emilia ProtocolemiliaprotocolRequires a named human's approval before irreversible agent actions such as payments or deploys, then issues an offline-verifiable Ed25519 trust receipt.
Active612Node.jsstdioActive612Node.jsstdio - 21
BlitzstrikeshinthinkBlitz Strike — a universal MCP security-audit toolbelt. BLITZ sweeps the attack surface, EAGLE-EYE traces source-to-sink, STRIKE verifies live. 57 attack chains, 130-tool catalog, intelligence data layer. One server, every agent.
Active501Node.jsstdioActive501Node.jsstdio - 22
Binary NinjafosdickioA Binary Ninja plugin, MCP server, and bridge that seamlessly integrates Binary Ninja with your favorite MCP client.
Stale449PythonStale449Python - 23
Droidmindhyperb1issAndroid device control, debugging, system analysis and UI automation, with a security framework.
Stale435PythonStale435Python - 24
MCPProxysmart-mcp-proxyLocal MCP proxy that routes multiple servers through one endpoint, with BM25 tool filtering, quarantine security, activity logging and a web UI.
Active387GoActive387Go - 25
Bloodhound MCP AImordavidintegration that connects BloodHound with AI through MCP, allowing security professionals to analyze Active Directory attack paths using natural language queries instead of Cypher.
Abandoned378Abandoned378 - 26
Radare2radareorgDisassemble and inspect binaries for reverse engineering with the Radare2 disassembler.
Active317CActive317C - 27
UcsandmanucsandmanFail-closed approval layer for unattended agent runs: checks actions against org policy, requests human approval and logs every decision to a causal ledger.
Active310Node.jsstdioActive310Node.jsstdio - 28
Wiresharkbx33661Wireshark packet analysis: capture, protocol statistics, field extraction and security analysis.
Maintained291PythonstdioMaintained291Pythonstdio - 29
OpenworkproofdengyierVerifiable execution protocol for agent tool calls: signed policy decisions, causal evidence chains and offline verification from a SQLite ledger.
Active287PythonstdioActive287Pythonstdio - 30
NiubizcodesparMCP server for Niubiz — Peru card acquirer: security token, session, authorize, reverse
Active272Node.jsstdioActive272Node.jsstdio - 31
squirrelscansquirrelscanWebsite QA for your coding agent: audit SEO, performance, security, accessibility over MCP.
Active272remoteActive272remote - 32
MaigretburtthecoderSearch usernames across social networks and analyze URLs with maigret, an OSINT tool that collects account information from public sources.
Stale267Node.jsStale267Node.js - 33
CrowdStrike FalconcrowdstrikeConnects AI agents with CrowdStrike Falcon for security analysis and automation.
Active266PythonstdioActive266Pythonstdio - 34
Stale239Rust - 35
SecopssecurityfortechSecurity testing toolbox that combines open source tools behind a single interface for pentesting, bug bounty hunting and threat hunting.
Abandoned216PythonAbandoned216Python - 36
CrowdsentinelthomasxmAI threat hunting & incident response for Elasticsearch/OpenSearch with endpoint & network forensics
Maintained209PythonstdioMaintained209Pythonstdio - 37
Reversecoresjkim1127Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
Active207PythonstdioActive207Pythonstdio - 38
Sharkmcp-sharkSecurity scanner for AI agent tools. Local static scan of MCP IDE configs (41 rules, toxic flow heuristics, AAuth visibility, auto-fix, tool pinning). Optional proxy + in-browser dashboard: traffic, findings, AAuth Explorer, YARA, Playground. Smart Scan o
Slowing179Node.jsstdioSlowing179Node.jsstdio - 39
Abandoned177Python - 40
ShodanburtthecoderQuery the Shodan API and Shodan CVEDB: IP lookups, device searches, DNS lookups, vulnerability queries and CPE lookups.
Active174Node.jsstdioActive174Node.jsstdio - 41
RsigmatimescaleAuthor, lint, validate and convert Sigma detection rules with RSigma, evaluate and explain detections against log events, and inspect correlation state.
Active162RustActive162Rust - 42
VirustotalburtthecoderQuery the VirusTotal API: scan URLs, analyze file hashes and retrieve IP address reports.
Active150Node.jsstdioActive150Node.jsstdio - 43
Ghidra13bmGhidra plugin for binary analysis: function inspection, decompilation, memory exploration and import/export analysis.
Maintained145PythonMaintained145Python - 44
ShellwardjnmetacodeAgent security middleware with layered defenses: prompt injection detection, DLP data flow tracking, command blocking and PII detection.
Active140Node.jsstdioActive140Node.jsstdio - 45
Securitydave-londonMCP server for security scanning — structured Trivy, Semgrep, and Gitleaks findings for AI agents
Maintained138Node.jsstdioMaintained138Node.jsstdio - 46
Agent Security ScannersinewaveaiAI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.
Maintained122Node.jsstdioMaintained122Node.jsstdio - 47
DvalincodearthurpanhkuDeterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.
Active120Node.jsstdioActive120Node.jsstdio - 48
Gosqlxajitpratap0SQL validation, formatting, parsing, linting, security scanning and metadata extraction across multiple SQL dialects.
Maintained118GoMaintained118Go