Category
Security MCP servers
- 481Active1Node.jsstdio
- 482Secrets Auditeltociear
Detects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.
Maintained1DockerstdioMaintained1Dockerstdio - 483
Secrets-LEnolindnaidooDetect hardcoded secrets in source and config. Reports masked previews, never the values.
Active1Node.jsstdioActive1Node.jsstdio - 484Secureauditrev2ret
Static C/C++ memory-safety scanning and PE/ELF binary protection audits (ASLR, DEP/NX, SafeSEH, PIE), with remediation via secure templates.
Slowing1Node.jsSlowing1Node.js - 485Security Headersbasitalisandhu
Fetch a URL's response headers and grade CSP, HSTS, X-Frame-Options and related security headers.
Active1DockerstdioActive1Dockerstdio - 486Security Headers Csp Lintjmshinhwa
Reads security headers and CSP line by line in your config file and names the lines that silently do
Active1Node.jsstdioActive1Node.jsstdio - 487Security Proxyguardbee
MCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log
Active1Node.jsstdioActive1Node.jsstdio - 488Security Suiteguardbee
Bundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence
Active1Node.jsstdioActive1Node.jsstdio - 489Security Txt Cra Lintjmshinhwa
13 rules that decide whether a vulnerability report ever reaches you
Active1Node.jsstdioActive1Node.jsstdio - 490Shieldrob925
Static security scanner for MCP servers and agent tools: detects secrets, shell execution, risky tool descriptions, environment access and prompt injection.
Maintained1PythonMaintained1Python - 491Shieldapialberthild
Security intelligence: HIBP password breach checks, email/domain/IP/URL reputation, prompt injection detection and skill supply chain scanning.
Stale1Node.jsStale1Node.js - 492Sievegautam-u
Local macOS scanner for secrets leaked into AI tool chat transcripts, with redacted findings, placeholder-only redaction and Keychain-backed command execution.
Slowing1Slowing1 - 493Skillguard Clirudrendupaul
Security scanner for third-party AI agent-skill files (SKILL.md, hooks, scripts) via MCP.
Active1PythonstdioActive1Pythonstdio - 494Skillssafegucci-atlasv
Scan SKILL.md files, MCP configs and system prompts for credential theft, prompt injection, zero-width character attacks and ClawHavoc indicators.
Stale1Node.jsStale1Node.js - 495Slopsquat Scannerguardbee
Checks declared npm/PyPI dependencies against real registries to catch slopsquatting
Active1Node.jsstdioActive1Node.jsstdio - 496Maintained1Pythonstdio
- 497The Code Registrythe-code-registry
Enterprise code intelligence for M&A, security audits, and tech debt. Hosted server with 200k free.
Slowing1remoteSlowing1remote - 498Tkach Securityecd5a
Fail-closed MCP adapter for untrusted model output over a local Tkach runtime.
Active1RuststdioActive1Ruststdio - 499Tool Poisoning Scannerguardbee
Scans MCP tool definitions for hidden instructions and confused-deputy sinks
Active1Node.jsstdioActive1Node.jsstdio - 500Truecopyaskalf
Supply-chain gate for agent skills and MCP servers: detects poisoned tool definitions, pins servers by hash, checks drift in CI and proxies only pinned tools.
Active1Node.jsActive1Node.js - 501URL Safety Validatorojaskord
AI URL safety validator: SAFE/SUSPICIOUS/DANGEROUS verdict, trust score, threat intel.
Maintained1Node.jsstdioremoteMaintained1Node.jsstdioremote - 502Universal DBfashad-ahmed
Security-first MCP server for PostgreSQL, SQLite, MySQL, DuckDB with SQL injection prevention.
Slowing1PythonstdioSlowing1Pythonstdio - 503Active1remote
- 504Vaultedvaulted-fyi
Share end-to-end encrypted, self-destructing secrets from an agent, reading them from env vars or files so they stay out of LLM context.
Slowing1Node.jsSlowing1Node.js - 505Vaultshellsowhati
Injects secrets into shell commands at exec time; plaintext never reaches the LLM context
Active1DockerstdioActive1Dockerstdio - 506Vector Store Scannerguardbee
Probes vector-database endpoints for unauthenticated exposure of embeddings/RAG data
Active1Node.jsstdioActive1Node.jsstdio - 507Vibescanaguantar
MCP server for VibeScan — scan projects for leaked secrets and security issues
Stale1PythonstdioStale1Pythonstdio - 508Vulnerability Scannerguardbee
Triggers GuardBee scans, queries findings, AI-assisted remediation guidance
Active1Node.jsstdioActive1Node.jsstdio - 509Weavatrix Onlineweavatrix
Weavatrix Online extension: guarded sync, advisories, malware review, architecture contracts.
Maintained1Node.jsstdioMaintained1Node.jsstdio - 510Web Exposureperufitlife
Read-only check of a live URL for publicly exposed secret files: .git, .env, JS source maps, backup/SQL dumps, directory listings and dotfiles.
Slowing1Node.jsSlowing1Node.js - 511Yashauyashau
Model Context Protocol server for a self-hosted secrets manager on Cloudflare Workers and D1. Lets an AI coding assistant list and write secrets without a value ever entering the conversation.
Active1Node.jsstdioActive1Node.jsstdio - 512agentegressco2water
See which AI agent and MCP server talks to what on Windows, with a rule-based security verdict
Active1stdioActive1stdio - 513dotrepomaxwellsantoro
Trust-aware repository facts for agents: build, test, docs, license, and security, no scraping.
Active1stdioActive1stdio - 514hushomarei-omoto
Team secrets your AI agent can use but never read: encrypted in the repo, value-blind tools.
Active1Node.jsstdioActive1Node.jsstdio - 515klaws — Korean compliance risk scannerrostradamus
Scan code for Korean compliance risks — PIPA/개인정보보호법, Network Act, Credit Info. Not legal advice.
Slowing1DockerstdioSlowing1Dockerstdio - 516mcpcutrostislavmatov
Journals every MCP tool call with secrets redacted; with a policy, holds risky calls for approval
Active1Node.jsstdioActive1Node.jsstdio - 517rowstilerowstile
Check, test, prove and review a rowstile policy: access rules for Postgres row-level security
Active1Node.jsstdioActive1Node.jsstdio - 518Gostanosgostanos
Query the Small Print record: versioned, diffed tool descriptions and schemas of MCP servers, skills and plugins, with graded changes and public advisories.
Active0Node.jsstdioActive0Node.jsstdio - 519Lazarettojamesdfinance-dev
Check lockfiles against malicious-package advisories and scan artifacts for credential theft, exfiltration, obfuscation, prompt injection and droppers.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 520Ssiddrumworks
MAC address (OUI) vendor lookup with randomized-address detection, plus router default login IPs and admin credentials cited to manufacturer documentation.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 5214da4da-systems
Dependency intelligence for coding agents: live CVE scanning, dependency health, upgrade planning, ecosystem news and decision memory.
Active0Node.jsstdioActive0Node.jsstdio - 522AI Supplyai-supply-store
MCP server for ai-supply.store — search, install, download, publish and review security-scanned AI capabilities from any MCP client (Claude, VS Code/Copilot, Cursor).
Slowing0Node.jsstdioSlowing0Node.jsstdio - 523AIMarket Oracle Gatewayalexar76
Verifiable oracle tools via AIMarket Hub: Platon VRF randomness, Chronos VDF computation and verification, and LUMEN reputation scores.
Active0PythonstdioActive0Pythonstdio - 524Agent Securitymdfifty50-boop
MCP server providing security scanning, prompt injection detection, secret leak detection, and agent permission auditing for AI agent workflows
Slowing0Node.jsstdioSlowing0Node.jsstdio - 525Agent Toolkitwhite-hat-lab
MCP server exposing pay-per-call developer and npm supply-chain security tools for coding agents, over x402.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 526Algentathyn-ai
Algenta decision engine: dataset discovery, exact queries, utility models, decision memory and governed agent runs with approvals and execution receipts.
Active0PythonstdioremoteActive0Pythonstdioremote - 527Alienvault Otxpipeworx-io
AlienVault OTX MCP — Open Threat Exchange (free with key)
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 528Blackwallbluetieroperations-create
Risk gate that agents call before irreversible actions, returning a risk score, reversibility class, red flags and a proceed/confirm/human-required decision.
Active0Node.jsstdioActive0Node.jsstdio