Category
Security MCP servers
- 529
CertScoreergoveritas1-altFree website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 530Checkeroksigeniasl
Local-first domain security and privacy checker: live SPF, DMARC, DKIM, DNSSEC, TLS, CAA and security header checks, scored with remediation advice.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 531Circl Vulnerability Lookuppipeworx-io
CIRCL Vulnerability-Lookup — aggregated vulnerability records
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 532Codebase Doctorsubhajitlucky
Read-only codebase audits for coding agents: secrets, RLS, deps, review verdicts. No writes.
Active0Node.jsstdioActive0Node.jsstdio - 533Compliance AIopsaiops-tools
Turn other AIops tools' audit trails into tamper-evident, hash-chained evidence bundles mapped to HIPAA, PCI-DSS, SOC 2 and GDPR. Offline and deterministic.
Active0PythonstdioActive0Pythonstdio - 534DDG Agent Servicesdaedalusdevelopmentgroup
Pay-per-call x402 tools (utilities, DNS/WHOIS, blockchain RPC, market and DEX data, prediction markets, security audits) plus an OpenAI-compatible LLM gateway.
Active0PythonstdioremoteActive0Pythonstdioremote - 535Eleion Scannerhernaninverso
Register and verify domains, queue security scans (headers, TLS, DNS, ports, CVEs and AI-specific checks) and read findings.
Slowing0Node.jsstdioSlowing0Node.jsstdio - 536Etchsaravananjaichandar
Signed audit chain for AI agent decisions: events are signed, Merkle-chained per project, anchored to public transparency logs and verifiable offline.
Maintained0PythonremoteMaintained0Pythonremote - 537EverThreadpb-digital-llc
Check a website's security in plain English from the terminal, or give your AI agent the tool. Free, no key.
Active0Node.jsstdioActive0Node.jsstdio - 538Feldspar free repository security scanproject-feldspar-resources
Deterministic security scan of public git repositories: vulnerable dependencies via OSV, hard-coded secrets and risky config lint, as file:line findings.
Active0PythonremoteActive0Pythonremote - 539Finishkitfinishkit
MCP server for FinishKit. Production readiness scanner for AI-built apps. Enables AI agents in Claude, Cursor, Windsurf, and VS Code to check if code is ready to ship.
Stale0Node.jsstdioStale0Node.jsstdio - 540Funding Press Signal Scannermambalabsdev
Scan Google News and PR wires for a company's funding rounds, executive moves, launches and acquisitions as deduplicated, dated events in Clay-ready JSON.
Active0Node.jsstdioActive0Node.jsstdio - 541Gatehousenickgeorgeseo
Permission tiers, approval gates and secret-redacting audit logging enforced inside MCP servers at the tool boundary, with a demo order-desk server.
Active0PythonstdioActive0Pythonstdio - 542GitHub Organization Signal Scannermambalabsdev
Resolve a company domain to its GitHub organization with repository, language and activity signals.
Active0Node.jsstdioActive0Node.jsstdio - 543Greynoisepipeworx-io
GreyNoise Community MCP — internet scanner classification (free tier with key)
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 544Halluccfredyee
Claim-level hallucination detection with sources, agent trajectory verification, risk gating for computer-use actions and prompt-injection defense.
Active0Node.jsremoteActive0Node.jsremote - 545Ledd MCP Auditjoepangallo
MCP server interface for AI agent and MCP security auditing — config analysis, trust audits, prompt injection testing, tool probing, and data flow tracing
Maintained0Node.jsstdioMaintained0Node.jsstdio - 546Malwarebazaarpipeworx-io
MalwareBazaar MCP — abuse.ch malware sample database (free, key required)
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 547Mandaremandarelabs
Accountability for AI agent fleets: verify a signed, hash-chained ledger, check budgets, kill an agent, and issue passports and mandates, all through the local CLI.
Active0Node.jsstdioActive0Node.jsstdio - 548Market Spreadpipeworx-io
market-spread MCP — cross-venue prediction-market landscape scanner.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 549MarketNowalicelabs-llc
68k+ security-audited MCP skills + free agent trust layer: signed ATC cards, tool gating, audits.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 550Mozilla Observatorypipeworx-io
MDN HTTP Observatory — grade any website's HTTP security headers and get the specific fixes, from Mozilla's public scanner.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 551Negbitag3ntlab-ai
MCP server for negbit — discover and read curated knowledge bundles (verified provenance, security-reviewed) agents can buy with their own x402 wallet. Read-only: never holds a wallet or moves money.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 552Nel Veilnelproinc
Free passive security scanning for AI agents. Check any domain for email spoofing (DMARC/SPF/DKIM), TLS, security headers, exposed files, and subdomain takeover risk — using public information only, no intrusive probing.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 553Nvdpipeworx-io
NVD MCP — wraps the NIST National Vulnerability Database API.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 554Off-Nadir Deltaoff-nadir-lab
Live geolocated world-event intelligence and a daily world brief: event signals, hotspots, Sentinel satellite imagery and an OSINT/GEOINT analyst.
Active0Node.jsremoteActive0Node.jsremote - 555Omnideckaapd-studio
Privacy-first local MCP server: redact secrets, decode JWTs, estimate LLM costs, split long documents and check AI output for hallucinations — all on your own machine, with no network calls.
Active0Node.jsstdioActive0Node.jsstdio - 556Pulsedivepipeworx-io
Pulsedive MCP — threat-intelligence IOC enrichment (pulsedive.com)
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 557Railsjaimenbell
Self-hosted default-deny action registry, append-only spend-intent ledger and human sign-off audit trail for gating irreversible agent actions.
Maintained0PythonstdioMaintained0Pythonstdio - 558Rqwstrkjopstad-it
HTTP security testing toolkit (send, intruder, race, chain, out-of-band) with low-level HTTP/1.1 and HTTP/2 control: raw framing and connection pinning.
Maintained0GostdioMaintained0Gostdio - 559SEOsparrow84001
SEO, AEO, GEO, local SEO and CRO auditor with framework-aware code fixes, sitemap crawling and HTTP security header inspection.
Active0Node.jsActive0Node.js - 560Safenode MCP Gatewaysp3ak
Fail-closed policy proxy for MCP tool calls that denies, warns on or holds each call for human approval before forwarding, with client-side redaction.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 561ScreenVeritywilliamblakecunningham-max
U.S. exclusion, debarment and license screening (OIG LEIE, SAM.gov, state boards) with an Ed25519-signed receipt of the exact list snapshots checked.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 562Sealaurumflux20
Exactly-once payments for agents: prevents double settlement across processes and retries, confirms charges with the provider and reconciles out-of-band spend.
Active0PythonstdioActive0Pythonstdio - 563Active0Node.jsstdioremote
- 564Sec Nportpipeworx-io
SEC Form N-PORT — fund and ETF holdings, asked security-first.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 565Secret Safe Envirrenwill
MCP server that lets an agent write secrets into .env without ever seeing the value — user pastes into a native Windows masked dialog; PowerShell writes the file.
Slowing0Node.jsstdioSlowing0Node.jsstdio - 566SendGrid Securechoppaaahh
Security-focused SendGrid email sending with recipient/domain allowlists, send caps, review mode, an audit log and no silent BCC.
Maintained0PythonstdioMaintained0Pythonstdio - 567Shieldlyshieldly-io
Analyze AWS IAM policies and CloudFormation templates with Shieldly to flag privilege-escalation paths, wildcards and over-permissive access.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 568Sonarigorolv
Read-only access to self-hosted SonarQube Community Build: issues, security hotspots, rules and code snippets so an agent can fix findings locally.
Active0DockerstdioActive0Dockerstdio - 569State of Web Vitalscorewebvitals
Core Web Vitals metrics by CMS, CDN and framework, based on Chrome field data and a multi-site crawl.
Maintained0remoteMaintained0remote - 570Tamperlensharuodev
Document forensics via the Tamperlens API: detect post-creation edits, failed redactions and embedded prompt injection in PDFs, Office files and images.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 571Tn Dmvpipeworx-io
Tennessee DMV MCP — Department of Safety and Homeland Security: the 186 driver service
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 572Trustscoreagenttrustscoreagent
Check the reputation of AI microservices and public APIs before calling them and submit ratings afterward, via an open trust registry.
Active0Node.jsstdioActive0Node.jsstdio - 573Ukhsapipeworx-io
UK Health Security Agency (UKHSA) data dashboard MCP — keyless.
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 574Umbraelberacasa
Trust scores and guardrails for AI-generated code: static security rules, Docker-verified build/boot checks and receipts that catch agents lying about tests.
Maintained0Node.jsstdioMaintained0Node.jsstdio - 575Urlhauspipeworx-io
URLhaus MCP — wraps abuse.ch URLhaus malware URL database (free, no auth)
Active0Node.jsstdioremoteActive0Node.jsstdioremote - 576Veritymeloliva14
Fail-closed trust gate for agents: fact-checking, prompt-injection detection, content moderation, PII and secret detection, and a pre-action guardrail.
Maintained0PythonstdioMaintained0Pythonstdio