Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 3 of 24.
  1. Analyze repos of any size - security scanning code analysis monorepo support

    Active28
  2. Cybersecuritygaoharimran29-glitch

    Local security reconnaissance: WHOIS, DNS and subdomain enumeration, Nmap scanning, TLS inspection, tech fingerprinting, CVE and IP reputation lookups.

    Active27Python
  3. Prism Scanneraidongise-cell

    Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.

    Stale27Pythonstdio
  4. Execution safety for agent actions: a YAML-policy gateway that allows, holds or denies tool calls, plus an approval queue and hash-chained receipts.

    Active26Pythonremote
  5. Ashfordeouashfordeou

    Codebase analysis: dependency graphs, security scanning, and refactor plans for GitHub and GitLab.

    Maintained26Node.jsstdio
  6. Intruderintruder-io

    Access Intruder to identify, understand and fix security vulnerabilities in your infrastructure.

    Slowing26Python
  7. Operantoperantlabs

    Security testing tools for penetration testing, network forensics, memory analysis and vulnerability assessment.

    Stale25Node.jsstdio
  8. Cinema4dkumoproductions

    MCP server for Cinema 4D — entity CRUD, parameter-level access, batched undo, security controls.

    Active25Node.jsstdio
  9. Cyberchefdoublegate

    GCHQ CyberChef's encryption, encoding, compression and forensics operations, plus analysis tools such as hash identification, cipher solving and RSA attacks.

    Active23Node.jsstdio
  10. Aimaim-intelligence

    Security-focused safety guidelines and content analysis for AI agents.

    Stale23Node.js
  11. Mobsfpullkitsan

    Static and dynamic analysis of Android and iOS apps with MobSF.

    Active23Rust
  12. Infrawisesidd27

    Cloud infrastructure analysis: detect IaC drift, missing indexes, security gaps and performance anti-patterns across AWS services and databases.

    Active22Node.jsstdio
  13. Attestableco-browser

    Demonstrates remote attestation of an MCP server running in a Gramine TEE via RA-TLS, so clients can verify the server before connecting.

    Abandoned22Python
  14. Nslookup IOnslookup-io

    DNS lookups, health reports, SSL certs, security scans, GEO scoring, uptime checks

    Maintained22Node.jsstdioremote
  15. Mastyf AImastyf-ai

    Runtime security proxy for MCP that blocks prompt injection, SSRF, shell/SQL injection and credential exfiltration, plus trust scores for npm MCP packages.

    Active21Node.jsstdio
  16. Libsqlxexr

    MCP server for libSQL databases with comprehensive security and management tools. Supports file, local HTTP, and remote Turso databases with connection pooling, transaction support, and 6 specialized database tools.

    Active21Node.js
  17. Spotdbaliengiraffe

    Ephemeral data sandbox for AI workflows with guardrails and security

    Stale21Dockerstdio
  18. Csl Corechimera-protocol

    Deterministic AI safety policy engine with Z3 formal verification: write, verify and enforce machine-verifiable constraints for AI agents.

    Active20Python
  19. Agentwardagentward-ai

    MCP proxy that enforces least-privilege YAML policies on tool calls, classifies PII/PHI, detects dangerous skill chains and generates compliance audit trails.

    Slowing19Python
  20. ToolTrust Scanneragentsafe-ai

    Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.

    Maintained19Node.jsstdio
  21. Wardenicoretech

    Manage Bitwarden and Vaultwarden vaults via the bw CLI: search, create, edit and organize logins, notes, cards, identities, SSH keys, folders and Sends.

    Active19Node.js
  22. Policy-based governance for agent tool calls across LangChain, OpenAI, Anthropic and MCP: YAML policies, approval gates, risk assessment and audit logging.

    Maintained18Pythonstdio
  23. FAOSTATberba-q

    FAOSTAT data for 245 countries: crops, trade, food security, and emissions via 23 MCP tools.

    Active18Pythonstdio
  24. Fidaajipurn

    Local-first MCP gateway for coding agents that redacts detected secrets from file reads and command output before they reach model context.

    Slowing18Rust
  25. Nekzusnekzus

    Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…

    Maintained18Node.jsstdioremote
  26. Hangarmcp-hangar

    Self-hosted policy enforcement for MCP server fleets: deterministic admission and egress policies, attributable audit logs and SIEM export.

    Active17Pythonstdio
  27. Cortexgbrigandi

    Cortex integration for observable analysis and automated security responses.

    Stale17Rust
  28. Vmsjyjune

    Retrieve live and recorded video from a CCTV recording program (VMS) and control it, such as opening live or playback dialogs for specific channels and times.

    Maintained17Python
  29. Dros Vajraclaw Hackertop-celestial-company-ltd

    Deterministic execution governance gateway and W3C DID security guardrail for AI agent MCP tool calls.

    Active16Python
  30. NetsCLIfstubner

    Network scanner for AI agents: discover hosts, scan TCP and UDP ports, query DNS and mDNS.

    Active16Node.jsstdio
  31. Value-blind secret metadata and gated workflows for AI coding agents through Phantom's local proxy.

    Active16Node.jsstdio
  32. Thehivegbrigandi

    TheHive integration for collaborative security incident response and case management.

    Stale16Rust
  33. VirusTotalvirustotal

    Official VirusTotal MCP server: threat reports, file and URL submissions, and analysis recovery.

    Active16Pythonstdioremote
  34. s-gwsgateway

    Local credential gateway for coding agents: agents get handles instead of raw secrets, and one-time approvals inject credentials only into approved commands.

    Active15Node.jsstdio
  35. Sdksidclawhq

    Governance proxy that wraps MCP servers with policy evaluation, human approval workflows and hash-chain audit trails.

    Active15Node.jsstdio
  36. prodlintprodlint

    Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.

    Maintained15Node.jsstdio
  37. Avp Sdkcreatorrmode-lead

    Trust, W3C DID identity and EigenTrust reputation for AI agents, with attestations, disputes, sybil detection and IPFS audit anchoring.

    Active15Node.js
  38. Depguardmopanc

    Pre-install npm package checks: static analysis, supply-chain attack detection, vulnerability audits, AI hallucination guard and CycloneDX SBOM generation.

    Active15Node.js
  39. GitHub security posture audit tools for AI agents — organization, repository, Actions, secrets, supply chain analysis via MCP

    Stale15Node.jsstdio
  40. Prodcheckfarzamhabibi

    4,372 pre-production checks: security, performance, scale, integrations, post-launch.

    Active15Node.jsstdio
  41. Runtime Guardruntimeguard

    Runtime policy enforcement for AI agents that prevents accidental system damage and unauthorized access, with automatic backups before file writes.

    Slowing15Python
  42. MCP governance proxy with capability tokens, tiered approvals, fail-closed execution and tamper-evident audit receipts, plus preflight tool-risk scanning.

    Active15Node.js
  43. Cligetaegis

    Credential isolation proxy that injects secrets at the network boundary, with domain restrictions, agent authentication and audit logging.

    Maintained14Node.jsstdio
  44. Post-quantum readiness: scan code for quantum-vulnerable cryptography (RSA, ECDH, ECDSA, DH), get ML-KEM/ML-DSA/SLH-DSA migration guidance and verify fixes.

    Maintained14Node.jsstdioremote
  45. Vuln Nistharoldfinchift

    Query the NIST National Vulnerability Database (NVD) API.

    Abandoned14Python
  46. Aletheiavikasny30

    Deterministic pre-execution filter for agent tool calls that blocks scope creep (credential reads, SSRF, destructive shell/SQL) and prompt injection.

    Active12Node.jsstdio
  47. Assayrul1an

    Fail-closed policy-as-code proxy for MCP that denies risky tool calls, produces offline-verifiable evidence bundles and enforces egress via eBPF and Landlock.

    Deprecated12Ruststdio
  48. Koma Gateswnotmetal

    Classify input for prompt injection and out-of-scope content with Koma Gate's LLM-based classifier.

    Active12Node.jsstdio

Related categories