Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 10 of 24.
  1. CVE scanning for npm/pip/cargo dependencies via OSV

    Active1Node.jsstdio
  2. Depscopecuttalo

    Package intelligence across many ecosystems: health, vulnerabilities (OSV, CISA KEV, EPSS), typosquats, malicious packages, alternatives and breaking changes.

    Slowing1Node.js
  3. Digidenonedigidenone

    AI-Powered Security Scanner for LLMs. Detects vulnerabilities and syncs with SynapseAudit.

    Stale1Node.jsstdio
  4. AI code review — security, quality, performance. Learns your patterns. Receipted.

    Maintained1Node.jsstdio
  5. AI security scanning and trust scoring. Stack-specific threat models. Free local scan.

    Maintained1Node.jsstdio
  6. Dockerfile Lintbasitalisandhu

    Lint Dockerfiles for root users, latest tags, secrets in ENV or ARG, missing HEALTHCHECK and more.

    Active1Dockerstdio
  7. Audit a domain's email and web security: SPF, DKIM, DMARC, MTA-STS, DNSSEC, TLS, WHOIS. No API keys.

    Active1Node.jsstdio
  8. MCP server for Drone CI/CD: 45 tools for builds, repos, secrets, users and templates

    Active1Dockerstdio
  9. Eidolonsudohnim

    Privacy-first OSINT scanner: breaches, credentials, Shodan, username sweep. Scored PDF report.

    Active1
  10. MCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs

    Active1Node.jsstdio
  11. 16 checks on a system-security-plan JSON, in your editor, before a validator returns the package

    Active1Node.jsstdio
  12. URL fetcher and HTML-to-Markdown converter with layered prompt injection defense: hidden-element sanitization, risk scanning and content boundary wrapping.

    Stale1Python
  13. Fetterfetter-io

    Real-time Python package and vulnerability data for AI coding agents.

    Stale1remote
  14. GhostFreeshane-js

    MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

    Stale1Node.jsstdio
  15. Grant Fit Scannerwyattpalm2-eng

    Find US federal grants your organization is actually eligible to apply for. Free, no API key.

    Maintained1remote
  16. Guard Coreguard-core

    Guard Core security MCP: SecurityConfig validation, docs search, live threat detection.

    Active1Pythonstdio
  17. Guardrailsexpertvagabond

    AI Agent Guardrails MCP server - security layer

    Maintained1Node.jsstdio
  18. Hejdararkalda

    Runtime policy enforcement for AI agents: evaluate actions against organization policies before execution, in observe or enforce mode.

    Active1Python
  19. Infinihash Kytinfinihash

    Screen crypto wallets vs OFAC SDN + threat intel; pre-payment checks, signed receipts; SAR drafts

    Active1Pythonstdioremote
  20. Jikidauneslam

    Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.

    Active1Node.jsstdio
  21. K8s ROyour-ko

    Read-only Kubernetes MCP server: inspect resources, logs, events, and metrics. Secrets are masked.

    Active1Dockerstdio
  22. Loaditoutloaditoutadmin

    Search and install 20,000+ security-graded MCP servers and agent skills.

    Stale1Node.jsstdio
  23. MCPSentinelgentaarnezzi

    Precision-first security scanning for Model Context Protocol servers.

    Active1Pythonstdio
  24. Scans agent code for untrusted input poisoning persistent cross-session memory

    Active1Node.jsstdio
  25. Find relevant security data from Sentinel data lake for building effective agents. More:aka.ms/s/de

    Stale1remote
  26. Mimecastwyre-technology

    MCP server for Mimecast email security: message queue, held messages, domains, and threats.

    Active1Dockerstdio
  27. Mimecastwyre-ai

    MCP server for Mimecast email security: message queue, held messages, domains, and threats.

    Active1Dockerstdio
  28. Scans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks

    Active1Node.jsstdio
  29. Modelsafetyitsalissonsilva

    Scan ML model artifacts, URLs and directories for unsafe serialization, malicious patterns and risky packaging using ModelScan, PickleScan and heuristics.

    Slowing1Python
  30. Mocap, rehab biomechanics, threat intel, fleet vision. 21 MCP tools, 10 free. x402/USDC paid.

    Maintained1remote
  31. Node Runtimemcp-protocol

    This package is intended for demonstration only. Maintained by JFrog Security.

    Stale1Node.jsstdio
  32. OSINTrjn32s

    26 free OSINT tools as MCP tools for AI agents. Auto-installs everything on first run.

    Slowing1Pythonstdio
  33. Developer and security utilities via the onlinecybertools.com API: encoding, hashing, JWT decoding, regex testing, formatters, network diagnostics and OSINT.

    Slowing1Node.js
  34. OpenAPI Lintbasitalisandhu

    Lint OpenAPI 3.x documents for missing security, responses, descriptions and versioning.

    Active1Dockerstdio
  35. Finds the lines in an OpenAPI file that publish an endpoint with no authentication, an API key in th

    Active1Node.jsstdio
  36. Orihimesrinivasan-sundaresan95

    Cross-repository code knowledge graph for Java, Kotlin, JavaScript and TypeScript: call-flow tracing, taint analysis, reachability and license compliance.

    Slowing1Python
  37. Package Guardmlawsonking

    Supply-chain guard for AI coding agents: verify packages, check vulns/malware, detect typosquats.

    Active1Node.jsstdio
  38. PageLens AIpagelens-ai

    AI website audit: security, SEO, performance, UX and accessibility checks with actionable fixes.

    Slowing1remote
  39. Pentestcyanheads

    Offline methodology engine for authorized penetration testing, CTF, and security research.

    Active1Node.jsstdioremote
  40. Podsuhui-organization

    Least-privilege compiler for agents: record real tool calls, compile a minimal policy, enforce it at an MCP gateway and keep a hash-chained audit.

    Active1Node.js
  41. Pqc Khepranouchix

    Post-quantum CMMC compliance scanner & AI agent attestation. FIPS 140-3, ML-DSA-65, 36K+ mappings.

    Active1Dockerstdio
  42. Scans RAG content/scraped pages for indirect prompt injection

    Active1Node.jsstdio
  43. Catches leaked credentials and PII in outbound LLM prompts

    Active1Node.jsstdio
  44. Proofport AIzkproofport

    Generate zero-knowledge proofs of identity claims (Coinbase KYC, country, Google OIDC, Microsoft 365) without revealing personal information.

    Active1Node.js
  45. Recon Kitnan786521

    Read-only network & security recon tools (DNS, TLS, headers, CORS) for AI agents, each graded.

    Maintained1Pythonstdio
  46. Connect AI assistants to the Rubrik Security Cloud GraphQL API to discover, query, and automate.

    Active1Pythonstdio
  47. Scamverifyscamverifyai

    Scam and threat checks for phone numbers, URLs, texts, emails, documents and QR codes using FTC/FCC complaints, URLhaus and ThreatFox, with risk scores.

    Stale1Node.js
  48. SecHelixomarmohelal

    Evidence-first security review of authorized repositories. Read-only, root-confined, no shell.

    Active1Pythonstdio

Related categories