Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf.
  1. Semgrepsemgrep

    Scan code for security vulnerabilities using Semgrep.

    Active17kPython
  2. Ida Promrexodia

    IDA Pro plugin for binary analysis: decompilation, disassembly and automatic malware analysis reports.

    Active13kPython
  3. Ghidralauriewired

    Autonomous reverse engineering with Ghidra: decompile binaries, rename methods and data, and list methods, classes, imports and exports.

    Abandoned11kJava
  4. Dark web OSINT over Tor: search onion engines, scrape pages, report with your own model.

    Active7.5kDockerstdio
  5. Search the Claude Code Ultimate Guide, official Anthropic documentation, releases, examples, security references, agent harness data, and translations from any MCP-compatible client.

    Active6.1kNode.jsstdio
  6. Jadx AIzinja-coder

    JADX decompiler plugin providing live, LLM-assisted reverse engineering.

    Active2.9kJava
  7. Toolhivestacklok

    A lightweight utility designed to simplify the deployment and management of MCP servers, ensuring ease of use, consistency, and security through containerization

    Active2.3k
  8. Beelzebubmariocandela

    Honeypot framework for building decoy MCP tools that an agent would never use in normal work, to detect prompt injection and malicious agent behavior.

    Active2.2k
  9. Jshookvmoranv

    MCP server for JavaScript analysis, security auditing, browser automation and hooks

    Active2.0kNode.jsstdio
  10. OpenOSINTopenosint

    AI-powered OSINT agent & MCP server. 21 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.

    Active1.7kPythonstdio
  11. MySQLdesigncomputer

    MySQL database integration with configurable access controls, schema inspection and security guidelines.

    Maintained1.4kPython
  12. Locally check npm and PyPI packages, such as those suggested by AI coding tools, for vulnerabilities and malicious code.

    Active1.1kDockerstdio
  13. Skylosduriantaco

    Dead code detection, security scanning and code quality analysis for Python, TypeScript and Go, with AI-assisted remediation.

    Active844Pythonstdio
  14. HOL Guardhashgraph-online

    Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.

    Active828Pythonstdio
  15. Driftdetectdadbodgeoff

    MCP server that gives AI agents (Claude, Cursor, Copilot) deep understanding of your codebase patterns, conventions, and architecture. Query patterns, security boundaries, call graphs in real-time.

    Maintained790Node.jsstdio
  16. Ghidrassistjtang613

    Native Ghidra integration with GUI configuration, logging and no external dependencies.

    Maintained764Java
  17. Kodykentcdodds

    Personal assistant MCP server with search, execute, packages, jobs, secrets, and integrations.

    Active750remote
  18. Semgrepsemgrep

    Enable AI agents to secure code with Semgrep.

    Abandoned687
  19. Apktoolzinja-coder

    Automate reverse engineering of Android APKs with Apktool.

    Slowing667Python
  20. Emilia Protocolemiliaprotocol

    Requires a named human's approval before irreversible agent actions such as payments or deploys, then issues an offline-verifiable Ed25519 trust receipt.

    Active612Node.jsstdio
  21. Blitzstrikeshinthink

    Blitz Strike — a universal MCP security-audit toolbelt. BLITZ sweeps the attack surface, EAGLE-EYE traces source-to-sink, STRIKE verifies live. 57 attack chains, 130-tool catalog, intelligence data layer. One server, every agent.

    Active501Node.jsstdio
  22. Binary Ninjafosdickio

    A Binary Ninja plugin, MCP server, and bridge that seamlessly integrates Binary Ninja with your favorite MCP client.

    Stale449Python
  23. Droidmindhyperb1iss

    Android device control, debugging, system analysis and UI automation, with a security framework.

    Stale435Python
  24. MCPProxysmart-mcp-proxy

    Local MCP proxy that routes multiple servers through one endpoint, with BM25 tool filtering, quarantine security, activity logging and a web UI.

    Active387Go
  25. integration that connects BloodHound with AI through MCP, allowing security professionals to analyze Active Directory attack paths using natural language queries instead of Cypher.

    Abandoned378
  26. Radare2radareorg

    Disassemble and inspect binaries for reverse engineering with the Radare2 disassembler.

    Active317C
  27. Ucsandmanucsandman

    Fail-closed approval layer for unattended agent runs: checks actions against org policy, requests human approval and logs every decision to a causal ledger.

    Active310Node.jsstdio
  28. Wiresharkbx33661

    Wireshark packet analysis: capture, protocol statistics, field extraction and security analysis.

    Maintained291Pythonstdio
  29. Verifiable execution protocol for agent tool calls: signed policy decisions, causal evidence chains and offline verification from a SQLite ledger.

    Active287Pythonstdio
  30. Niubizcodespar

    MCP server for Niubiz — Peru card acquirer: security token, session, authorize, reverse

    Active272Node.jsstdio
  31. squirrelscansquirrelscan

    Website QA for your coding agent: audit SEO, performance, security, accessibility over MCP.

    Active272remote
  32. Maigretburtthecoder

    Search usernames across social networks and analyze URLs with maigret, an OSINT tool that collects account information from public sources.

    Stale267Node.js
  33. Connects AI agents with CrowdStrike Falcon for security analysis and automation.

    Active266Pythonstdio
  34. Wazuhgbrigandi

    Access real-time security alerts and event data from Wazuh SIEM.

    Stale239Rust
  35. Secopssecurityfortech

    Security testing toolbox that combines open source tools behind a single interface for pentesting, bug bounty hunting and threat hunting.

    Abandoned216Python
  36. AI threat hunting & incident response for Elasticsearch/OpenSearch with endpoint & network forensics

    Maintained209Pythonstdio
  37. Reversecoresjkim1127

    Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.

    Active207Pythonstdio
  38. Sharkmcp-shark

    Security scanner for AI agent tools. Local static scan of MCP IDE configs (41 rules, toxic flow heuristics, AAuth visibility, auto-fix, tool pinning). Optional proxy + in-browser dashboard: traffic, findings, AAuth Explorer, YARA, Playground. Smart Scan o

    Slowing179Node.jsstdio
  39. Climladensu

    Command-line execution with customizable security policies.

    Abandoned177Python
  40. Shodanburtthecoder

    Query the Shodan API and Shodan CVEDB: IP lookups, device searches, DNS lookups, vulnerability queries and CPE lookups.

    Active174Node.jsstdio
  41. Rsigmatimescale

    Author, lint, validate and convert Sigma detection rules with RSigma, evaluate and explain detections against log events, and inspect correlation state.

    Active162Rust
  42. Virustotalburtthecoder

    Query the VirusTotal API: scan URLs, analyze file hashes and retrieve IP address reports.

    Active150Node.jsstdio
  43. Ghidra13bm

    Ghidra plugin for binary analysis: function inspection, decompilation, memory exploration and import/export analysis.

    Maintained145Python
  44. Shellwardjnmetacode

    Agent security middleware with layered defenses: prompt injection detection, DLP data flow tracking, command blocking and PII detection.

    Active140Node.jsstdio
  45. Securitydave-london

    MCP server for security scanning — structured Trivy, Semgrep, and Gitleaks findings for AI agents

    Maintained138Node.jsstdio
  46. AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.

    Maintained122Node.jsstdio
  47. Dvalincodearthurpanhku

    Deterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.

    Active120Node.jsstdio
  48. Gosqlxajitpratap0

    SQL validation, formatting, parsing, linting, security scanning and metadata extraction across multiple SQL dialects.

    Maintained118Go

Related categories