Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 15 of 24.
  1. Guarded WhatsApppeter-tnc-453

    Security gate for agent-driven WhatsApp: allowlist, secret scan, rate limit, audit log.

    Slowing0Pythonstdio
  2. HTTP header analysis — security headers, cache, server detection. x402 micropayment.

    Maintained0remote
  3. Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.

    Active0remote
  4. Encrypted secret store and rotation for autonomous agent credentials

    Slowing0remote
  5. Holehe Email Osintanshumanatrey

    Email OSINT Tool - Find Registered Accounts on 120+ Sites

    Active0remote
  6. Intelthreadlinqsthreadlinqs-cmd

    Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs

    Maintained0Node.jsstdio
  7. Ismalicioushexablob

    Reputation of IPs, domains, URLs, hashes, emails and phones; CVE lookups; prompt-injection scans

    Active0Node.jsstdio
  8. Keeper Secrets Managerwyre-technology

    Read-only multitenant Streamable HTTP bridge over Keeper Secrets Manager's MCP server.

    Active0Dockerstdio
  9. Read-only multitenant Streamable HTTP bridge over Keeper Secrets Manager's MCP server.

    Active0Dockerstdio
  10. Keysnagsheldon-desouza

    Cybersecurity for AI founders and vibe coders. A pre-push security gate for apps built with Claude Code, Cursor, Codex, Lovable and Bolt: 12 offline checks for leaked keys, Supabase RLS, cross-account (IDOR) access, injection, Stripe webhooks, known CVEs

    Active0Node.jsstdio
  11. KnowBe4wyre-technology

    MCP server for KnowBe4 security awareness training — users, groups, training, phishing campaigns.

    Active0Dockerstdio
  12. KnowBe4wyre-ai

    MCP server for KnowBe4 security awareness training — users, groups, training, phishing campaigns.

    Active0Dockerstdio
  13. kube-linter audit for Kubernetes manifests — 63 checks: security, availability, RBAC, network.

    Slowing0remote
  14. Australian ingredient scanner MCP — 21k+ AU products, 237 chemical rules, 17 condition tags.

    Slowing0remote
  15. MCPLookupmcplookupdev

    Look up independent trust ratings and security, maintenance, and adoption evidence for MCP servers.

    Maintained0Node.jsstdioremote
  16. Username Search & Lookup - Maigret OSINT Tool

    Active0remote
  17. Make Auditarose26

    Audit Make.com blueprints before importing: hardcoded secrets, dangling refs, risky settings.

    Maintained0Node.jsstdio
  18. Mcpcheckfpetitit

    Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.

    Slowing0remote
  19. Mcpindexmcpindex-ai

    Find MCP servers by describing a task and get advisory trust screens before connecting, using the mcpindex directory.

    Maintained0Node.js
  20. Mcpshield Climcpshield-dev

    Security scanner for MCP servers - detects tool poisoning and injection

    Slowing0Node.jsstdio
  21. MEOK CRA Article 14 Reporter MCP — actively-exploited-vulnerability notification with 24h/72h/14d

    Deprecated0Pythonstdioremote
  22. MEOK MCP Hardening MCP — automated security red-team for any MCP server. Maps OWASP LLM Top 10

    Deprecated0Pythonstdioremote
  23. MCP injection / prompt-poisoning / SSRF scanner. 30+ canonical rules covering the April 2026

    Maintained0Pythonstdio
  24. Middlebrickmiddlebrick

    Scan APIs for OWASP Top 10, LLM, and GraphQL security vulnerabilities.

    Stale0Node.jsstdio
  25. Mitre Atlascsoai-org

    MITRE ATLAS — Adversarial Threat Landscape for AI Systems. Tactics + techniques for attacking AI...

    Maintained0Pythonstdio
  26. Mudkolmno100

    Agent-readiness scanner (0-5 score), robots.txt + llms.txt generators, managed agent enablement.

    Maintained0remote
  27. Mundtyox-all

    Scan for prompt injection, secrets, PII, and vet MCP servers before installation

    Maintained0Node.jsstdio
  28. Score any website's AI-agent readiness. Open Agent Registry scanner + platform tools.

    Slowing0remote
  29. Positive-security for apps, APIs, LLMs and edge, plus fraud scoring and identity/AML screening.

    Maintained0Node.jsstdio
  30. Netintelkjgueye

    MCP server for NetIntel — DNS, SSL, WHOIS, email security, OSINT via x402 micropayments

    Active0Node.jsstdio
  31. 177 tools for AI agents. Turn Chrome into an MCP server — inspect DOM, automate clicks, audit security, mock APIs, extract data, download videos, schedule agents, monitor pages, self-improving recipes, full API collection management, business intelligence

    Maintained0Node.jsstdio
  32. Nexusnexus-api-lab

    Japanese LLM security — prompt injection detection (jpi-guard) + PII masking (PII Guard). Free.

    Slowing0remote
  33. Nmap Scanneranshumanatrey

    nmap - Network Port Scanner & Service Detection

    Active0remote
  34. Real-time threat intel for AI agents: 890K+ IOCs incl. prompt-injection & AI-skill threats

    Slowing0remote
  35. OSINTrobyroro

    Domain and website investigations: batch recon, shared infrastructure, CT history and public lookups

    Active0Pythonstdio
  36. Run Sherlock, Maigret, Holehe, GHunt, theHarvester, SpiderFoot and more OSINT tools locally

    Active0Pythonstdio
  37. Local MCP access to approved 1Password fields without exposing plaintext secrets to AI agents.

    Active0Node.jsstdio
  38. Openclaw Extensionsromainsantoli-web

    138-tool MCP server for AI agent firms: security, A2A, Hebbian memory, fleet mgmt

    Stale0Pythonstdio
  39. AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.

    Stale0remote
  40. Owasp MCP Scancodingselim

    Passive security scanner: audits MCP servers against the OWASP MCP Top 10, graded A-F.

    Maintained0Node.jsstdio
  41. Threat intel for AI agents: IOCs, CVEs (EPSS/KEV), wallet sanctions and age, domain and URL checks.

    Active0remote
  42. PII & Secret Redactortylerscomic-lab

    Detect and redact PII and secrets before text reaches an LLM, with reversible placeholders.

    Active0remote
  43. AI code security audits via x402 USDC: $0.01 scans, $0.50 audits, $5 auto-fixes. SAST/SCA.

    Active0remote
  44. Packet Chefnoor202401938-netizen

    Zero-native-dependency pure-JavaScript PCAP/PCAPng forensics MCP server for AI agents: packet inspection, conversation tracking, DNS, HTTP, TLS JA3/JA4, WebSocket, QUIC/HTTP3, and threat detection.

    Active0Node.jsstdio
  45. Free web tools for AI agents: HTML to Markdown, compliance scan, page profile, security headers.

    Maintained0
  46. Phishcleanchidhu07

    MCP server for PhishClean security analysis tools — check URLs, passwords, emails, headers, JWTs, and source code for security issues

    Active0Node.jsstdio
  47. TCP port scanning — check open ports on any host. x402 micropayment.

    Maintained0remote
  48. PostgreSQL security for AI agents: CVEs, yanked releases, exploits, and upgrade paths

    Maintained0Pythonstdio

Related categories