Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 11 of 24.
  1. Scans files for leaked secrets and API keys

    Active1Node.jsstdio
  2. Secrets Auditeltociear

    Detects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.

    Maintained1Dockerstdio
  3. Secrets-LEnolindnaidoo

    Detect hardcoded secrets in source and config. Reports masked previews, never the values.

    Active1Node.jsstdio
  4. Static C/C++ memory-safety scanning and PE/ELF binary protection audits (ASLR, DEP/NX, SafeSEH, PIE), with remediation via secure templates.

    Slowing1Node.js
  5. Security Headersbasitalisandhu

    Fetch a URL's response headers and grade CSP, HSTS, X-Frame-Options and related security headers.

    Active1Dockerstdio
  6. Reads security headers and CSP line by line in your config file and names the lines that silently do

    Active1Node.jsstdio
  7. MCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log

    Active1Node.jsstdio
  8. Bundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence

    Active1Node.jsstdio
  9. 13 rules that decide whether a vulnerability report ever reaches you

    Active1Node.jsstdio
  10. Shieldrob925

    Static security scanner for MCP servers and agent tools: detects secrets, shell execution, risky tool descriptions, environment access and prompt injection.

    Maintained1Python
  11. Shieldapialberthild

    Security intelligence: HIBP password breach checks, email/domain/IP/URL reputation, prompt injection detection and skill supply chain scanning.

    Stale1Node.js
  12. Sievegautam-u

    Local macOS scanner for secrets leaked into AI tool chat transcripts, with redacted findings, placeholder-only redaction and Keychain-backed command execution.

    Slowing1
  13. Skillguard Clirudrendupaul

    Security scanner for third-party AI agent-skill files (SKILL.md, hooks, scripts) via MCP.

    Active1Pythonstdio
  14. Skillssafegucci-atlasv

    Scan SKILL.md files, MCP configs and system prompts for credential theft, prompt injection, zero-width character attacks and ClawHavoc indicators.

    Stale1Node.js
  15. Checks declared npm/PyPI dependencies against real registries to catch slopsquatting

    Active1Node.jsstdio
  16. Taranis AItaranis-ai

    Search stories and discover OSINT sources in Taranis AI.

    Maintained1Pythonstdio
  17. The Code Registrythe-code-registry

    Enterprise code intelligence for M&A, security audits, and tech debt. Hosted server with 200k free.

    Slowing1remote
  18. Fail-closed MCP adapter for untrusted model output over a local Tkach runtime.

    Active1Ruststdio
  19. Scans MCP tool definitions for hidden instructions and confused-deputy sinks

    Active1Node.jsstdio
  20. Truecopyaskalf

    Supply-chain gate for agent skills and MCP servers: detects poisoned tool definitions, pins servers by hash, checks drift in CI and proxies only pinned tools.

    Active1Node.js
  21. AI URL safety validator: SAFE/SUSPICIOUS/DANGEROUS verdict, trust score, threat intel.

    Maintained1Node.jsstdioremote
  22. Universal DBfashad-ahmed

    Security-first MCP server for PostgreSQL, SQLite, MySQL, DuckDB with SQL injection prevention.

    Slowing1Pythonstdio
  23. Upi ID Osintanshumanatrey

    UPI ID OSINT - Phone to UPI VPAs + Bank Names (India)

    Active1remote
  24. Vaultedvaulted-fyi

    Share end-to-end encrypted, self-destructing secrets from an agent, reading them from env vars or files so they stay out of LLM context.

    Slowing1Node.js
  25. Vaultshellsowhati

    Injects secrets into shell commands at exec time; plaintext never reaches the LLM context

    Active1Dockerstdio
  26. Probes vector-database endpoints for unauthenticated exposure of embeddings/RAG data

    Active1Node.jsstdio
  27. Vibescanaguantar

    MCP server for VibeScan — scan projects for leaked secrets and security issues

    Stale1Pythonstdio
  28. Triggers GuardBee scans, queries findings, AI-assisted remediation guidance

    Active1Node.jsstdio
  29. Weavatrix Online extension: guarded sync, advisories, malware review, architecture contracts.

    Maintained1Node.jsstdio
  30. Web Exposureperufitlife

    Read-only check of a live URL for publicly exposed secret files: .git, .env, JS source maps, backup/SQL dumps, directory listings and dotfiles.

    Slowing1Node.js
  31. Yashauyashau

    Model Context Protocol server for a self-hosted secrets manager on Cloudflare Workers and D1. Lets an AI coding assistant list and write secrets without a value ever entering the conversation.

    Active1Node.jsstdio
  32. agentegressco2water

    See which AI agent and MCP server talks to what on Windows, with a rule-based security verdict

    Active1stdio
  33. dotrepomaxwellsantoro

    Trust-aware repository facts for agents: build, test, docs, license, and security, no scraping.

    Active1stdio
  34. hushomarei-omoto

    Team secrets your AI agent can use but never read: encrypted in the repo, value-blind tools.

    Active1Node.jsstdio
  35. Scan code for Korean compliance risks — PIPA/개인정보보호법, Network Act, Credit Info. Not legal advice.

    Slowing1Dockerstdio
  36. mcpcutrostislavmatov

    Journals every MCP tool call with secrets redacted; with a policy, holds risky calls for approval

    Active1Node.jsstdio
  37. rowstilerowstile

    Check, test, prove and review a rowstile policy: access rules for Postgres row-level security

    Active1Node.jsstdio
  38. Gostanosgostanos

    Query the Small Print record: versioned, diffed tool descriptions and schemas of MCP servers, skills and plugins, with graded changes and public advisories.

    Active0Node.jsstdio
  39. Lazarettojamesdfinance-dev

    Check lockfiles against malicious-package advisories and scan artifacts for credential theft, exfiltration, obfuscation, prompt injection and droppers.

    Active0Node.jsstdioremote
  40. Ssiddrumworks

    MAC address (OUI) vendor lookup with randomized-address detection, plus router default login IPs and admin credentials cited to manufacturer documentation.

    Active0Node.jsstdioremote
  41. 4da4da-systems

    Dependency intelligence for coding agents: live CVE scanning, dependency health, upgrade planning, ecosystem news and decision memory.

    Active0Node.jsstdio
  42. AI Supplyai-supply-store

    MCP server for ai-supply.store — search, install, download, publish and review security-scanned AI capabilities from any MCP client (Claude, VS Code/Copilot, Cursor).

    Slowing0Node.jsstdio
  43. Verifiable oracle tools via AIMarket Hub: Platon VRF randomness, Chronos VDF computation and verification, and LUMEN reputation scores.

    Active0Pythonstdio
  44. Agent Securitymdfifty50-boop

    MCP server providing security scanning, prompt injection detection, secret leak detection, and agent permission auditing for AI agent workflows

    Slowing0Node.jsstdio
  45. Agent Toolkitwhite-hat-lab

    MCP server exposing pay-per-call developer and npm supply-chain security tools for coding agents, over x402.

    Maintained0Node.jsstdio
  46. Algentathyn-ai

    Algenta decision engine: dataset discovery, exact queries, utility models, decision memory and governed agent runs with approvals and execution receipts.

    Active0Pythonstdioremote
  47. Alienvault Otxpipeworx-io

    AlienVault OTX MCP — Open Threat Exchange (free with key)

    Active0Node.jsstdioremote
  48. Blackwallbluetieroperations-create

    Risk gate that agents call before irreversible actions, returning a risk score, reversibility class, red flags and a proceed/confirm/human-required decision.

    Active0Node.jsstdio

Related categories