Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 12 of 24.
  1. CertScoreergoveritas1-alt

    Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.

    Active0Node.jsstdioremote
  2. Checkeroksigeniasl

    Local-first domain security and privacy checker: live SPF, DMARC, DKIM, DNSSEC, TLS, CAA and security header checks, scored with remediation advice.

    Maintained0Node.jsstdio
  3. CIRCL Vulnerability-Lookup — aggregated vulnerability records

    Active0Node.jsstdioremote
  4. Codebase Doctorsubhajitlucky

    Read-only codebase audits for coding agents: secrets, RLS, deps, review verdicts. No writes.

    Active0Node.jsstdio
  5. Compliance AIopsaiops-tools

    Turn other AIops tools' audit trails into tamper-evident, hash-chained evidence bundles mapped to HIPAA, PCI-DSS, SOC 2 and GDPR. Offline and deterministic.

    Active0Pythonstdio
  6. DDG Agent Servicesdaedalusdevelopmentgroup

    Pay-per-call x402 tools (utilities, DNS/WHOIS, blockchain RPC, market and DEX data, prediction markets, security audits) plus an OpenAI-compatible LLM gateway.

    Active0Pythonstdioremote
  7. Eleion Scannerhernaninverso

    Register and verify domains, queue security scans (headers, TLS, DNS, ports, CVEs and AI-specific checks) and read findings.

    Slowing0Node.jsstdio
  8. Etchsaravananjaichandar

    Signed audit chain for AI agent decisions: events are signed, Merkle-chained per project, anchored to public transparency logs and verifiable offline.

    Maintained0Pythonremote
  9. EverThreadpb-digital-llc

    Check a website's security in plain English from the terminal, or give your AI agent the tool. Free, no key.

    Active0Node.jsstdio
  10. Feldspar free repository security scanproject-feldspar-resources

    Deterministic security scan of public git repositories: vulnerable dependencies via OSV, hard-coded secrets and risky config lint, as file:line findings.

    Active0Pythonremote
  11. Finishkitfinishkit

    MCP server for FinishKit. Production readiness scanner for AI-built apps. Enables AI agents in Claude, Cursor, Windsurf, and VS Code to check if code is ready to ship.

    Stale0Node.jsstdio
  12. Scan Google News and PR wires for a company's funding rounds, executive moves, launches and acquisitions as deduplicated, dated events in Clay-ready JSON.

    Active0Node.jsstdio
  13. Gatehousenickgeorgeseo

    Permission tiers, approval gates and secret-redacting audit logging enforced inside MCP servers at the tool boundary, with a demo order-desk server.

    Active0Pythonstdio
  14. Resolve a company domain to its GitHub organization with repository, language and activity signals.

    Active0Node.jsstdio
  15. Greynoisepipeworx-io

    GreyNoise Community MCP — internet scanner classification (free tier with key)

    Active0Node.jsstdioremote
  16. Halluccfredyee

    Claim-level hallucination detection with sources, agent trajectory verification, risk gating for computer-use actions and prompt-injection defense.

    Active0Node.jsremote
  17. Ledd MCP Auditjoepangallo

    MCP server interface for AI agent and MCP security auditing — config analysis, trust audits, prompt injection testing, tool probing, and data flow tracing

    Maintained0Node.jsstdio
  18. Malwarebazaarpipeworx-io

    MalwareBazaar MCP — abuse.ch malware sample database (free, key required)

    Active0Node.jsstdioremote
  19. Mandaremandarelabs

    Accountability for AI agent fleets: verify a signed, hash-chained ledger, check budgets, kill an agent, and issue passports and mandates, all through the local CLI.

    Active0Node.jsstdio
  20. Market Spreadpipeworx-io

    market-spread MCP — cross-venue prediction-market landscape scanner.

    Active0Node.jsstdioremote
  21. MarketNowalicelabs-llc

    68k+ security-audited MCP skills + free agent trust layer: signed ATC cards, tool gating, audits.

    Active0Node.jsstdioremote
  22. MDN HTTP Observatory — grade any website's HTTP security headers and get the specific fixes, from Mozilla's public scanner.

    Active0Node.jsstdioremote
  23. Negbitag3ntlab-ai

    MCP server for negbit — discover and read curated knowledge bundles (verified provenance, security-reviewed) agents can buy with their own x402 wallet. Read-only: never holds a wallet or moves money.

    Maintained0Node.jsstdio
  24. Nel Veilnelproinc

    Free passive security scanning for AI agents. Check any domain for email spoofing (DMARC/SPF/DKIM), TLS, security headers, exposed files, and subdomain takeover risk — using public information only, no intrusive probing.

    Maintained0Node.jsstdio
  25. Nvdpipeworx-io

    NVD MCP — wraps the NIST National Vulnerability Database API.

    Active0Node.jsstdioremote
  26. Off-Nadir Deltaoff-nadir-lab

    Live geolocated world-event intelligence and a daily world brief: event signals, hotspots, Sentinel satellite imagery and an OSINT/GEOINT analyst.

    Active0Node.jsremote
  27. Omnideckaapd-studio

    Privacy-first local MCP server: redact secrets, decode JWTs, estimate LLM costs, split long documents and check AI output for hallucinations — all on your own machine, with no network calls.

    Active0Node.jsstdio
  28. Pulsedivepipeworx-io

    Pulsedive MCP — threat-intelligence IOC enrichment (pulsedive.com)

    Active0Node.jsstdioremote
  29. Railsjaimenbell

    Self-hosted default-deny action registry, append-only spend-intent ledger and human sign-off audit trail for gating irreversible agent actions.

    Maintained0Pythonstdio
  30. Rqwstrkjopstad-it

    HTTP security testing toolkit (send, intruder, race, chain, out-of-band) with low-level HTTP/1.1 and HTTP/2 control: raw framing and connection pinning.

    Maintained0Gostdio
  31. SEOsparrow84001

    SEO, AEO, GEO, local SEO and CRO auditor with framework-aware code fixes, sitemap crawling and HTTP security header inspection.

    Active0Node.js
  32. Fail-closed policy proxy for MCP tool calls that denies, warns on or holds each call for human approval before forwarding, with client-side redaction.

    Maintained0Node.jsstdio
  33. ScreenVeritywilliamblakecunningham-max

    U.S. exclusion, debarment and license screening (OIG LEIE, SAM.gov, state boards) with an Ed25519-signed receipt of the exact list snapshots checked.

    Maintained0Node.jsstdio
  34. Sealaurumflux20

    Exactly-once payments for agents: prevents double settlement across processes and retries, confirms charges with the provider and reconciles out-of-band spend.

    Active0Pythonstdio
  35. Sec 13fpipeworx-io

    SEC 13F — institutional ownership, asked security-first.

    Active0Node.jsstdioremote
  36. Sec Nportpipeworx-io

    SEC Form N-PORT — fund and ETF holdings, asked security-first.

    Active0Node.jsstdioremote
  37. MCP server that lets an agent write secrets into .env without ever seeing the value — user pastes into a native Windows masked dialog; PowerShell writes the file.

    Slowing0Node.jsstdio
  38. SendGrid Securechoppaaahh

    Security-focused SendGrid email sending with recipient/domain allowlists, send caps, review mode, an audit log and no silent BCC.

    Maintained0Pythonstdio
  39. Shieldlyshieldly-io

    Analyze AWS IAM policies and CloudFormation templates with Shieldly to flag privilege-escalation paths, wildcards and over-permissive access.

    Maintained0Node.jsstdio
  40. Sonarigorolv

    Read-only access to self-hosted SonarQube Community Build: issues, security hotspots, rules and code snippets so an agent can fix findings locally.

    Active0Dockerstdio
  41. State of Web Vitalscorewebvitals

    Core Web Vitals metrics by CMS, CDN and framework, based on Chrome field data and a multi-site crawl.

    Maintained0remote
  42. Tamperlensharuodev

    Document forensics via the Tamperlens API: detect post-creation edits, failed redactions and embedded prompt injection in PDFs, Office files and images.

    Maintained0Node.jsstdio
  43. Tn Dmvpipeworx-io

    Tennessee DMV MCP — Department of Safety and Homeland Security: the 186 driver service

    Active0Node.jsstdioremote
  44. Trustscoreagenttrustscoreagent

    Check the reputation of AI microservices and public APIs before calling them and submit ratings afterward, via an open trust registry.

    Active0Node.jsstdio
  45. Ukhsapipeworx-io

    UK Health Security Agency (UKHSA) data dashboard MCP — keyless.

    Active0Node.jsstdioremote
  46. Umbraelberacasa

    Trust scores and guardrails for AI-generated code: static security rules, Docker-verified build/boot checks and receipts that catch agents lying about tests.

    Maintained0Node.jsstdio
  47. Urlhauspipeworx-io

    URLhaus MCP — wraps abuse.ch URLhaus malware URL database (free, no auth)

    Active0Node.jsstdioremote
  48. Veritymeloliva14

    Fail-closed trust gate for agents: fact-checking, prompt-injection detection, content moderation, PII and secret detection, and a pre-action guardrail.

    Maintained0Pythonstdio

Related categories