Category
Security MCP servers
- 97Repository Intelligencenirholas
Analyze repos of any size - security scanning code analysis monorepo support
Active28Active28 - 98Cybersecuritygaoharimran29-glitch
Local security reconnaissance: WHOIS, DNS and subdomain enumeration, Nmap scanning, TLS inspection, tech fingerprinting, CVE and IP reputation lookups.
Active27PythonActive27Python - 99Prism Scanneraidongise-cell
Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
Stale27PythonstdioStale27Pythonstdio - 100CTRLRun Operatorctrlrun
Execution safety for agent actions: a YAML-policy gateway that allows, holds or denies tool calls, plus an approval queue and hash-chained receipts.
Active26PythonremoteActive26Pythonremote - 101Ashfordeouashfordeou
Codebase analysis: dependency graphs, security scanning, and refactor plans for GitHub and GitLab.
Maintained26Node.jsstdioMaintained26Node.jsstdio - 102Intruderintruder-io
Access Intruder to identify, understand and fix security vulnerabilities in your infrastructure.
Slowing26PythonSlowing26Python - 103Operantoperantlabs
Security testing tools for penetration testing, network forensics, memory analysis and vulnerability assessment.
Stale25Node.jsstdioStale25Node.jsstdio - 104Cinema4dkumoproductions
MCP server for Cinema 4D — entity CRUD, parameter-level access, batched undo, security controls.
Active25Node.jsstdioActive25Node.jsstdio - 105Cyberchefdoublegate
GCHQ CyberChef's encryption, encoding, compression and forensics operations, plus analysis tools such as hash identification, cipher solving and RSA attacks.
Active23Node.jsstdioActive23Node.jsstdio - 106Aimaim-intelligence
Security-focused safety guidelines and content analysis for AI agents.
Stale23Node.jsStale23Node.js - 107Active23Rust
- 108Infrawisesidd27
Cloud infrastructure analysis: detect IaC drift, missing indexes, security gaps and performance anti-patterns across AWS services and databases.
Active22Node.jsstdioActive22Node.jsstdio - 109Attestableco-browser
Demonstrates remote attestation of an MCP server running in a Gramine TEE via RA-TLS, so clients can verify the server before connecting.
Abandoned22PythonAbandoned22Python - 110Nslookup IOnslookup-io
DNS lookups, health reports, SSL certs, security scans, GEO scoring, uptime checks
Maintained22Node.jsstdioremoteMaintained22Node.jsstdioremote - 111Mastyf AImastyf-ai
Runtime security proxy for MCP that blocks prompt injection, SSRF, shell/SQL injection and credential exfiltration, plus trust scores for npm MCP packages.
Active21Node.jsstdioActive21Node.jsstdio - 112Libsqlxexr
MCP server for libSQL databases with comprehensive security and management tools. Supports file, local HTTP, and remote Turso databases with connection pooling, transaction support, and 6 specialized database tools.
Active21Node.jsActive21Node.js - 113Spotdbaliengiraffe
Ephemeral data sandbox for AI workflows with guardrails and security
Stale21DockerstdioStale21Dockerstdio - 114Csl Corechimera-protocol
Deterministic AI safety policy engine with Z3 formal verification: write, verify and enforce machine-verifiable constraints for AI agents.
Active20PythonActive20Python - 115Agentwardagentward-ai
MCP proxy that enforces least-privilege YAML policies on tool calls, classifies PII/PHI, detects dangerous skill chains and generates compliance audit trails.
Slowing19PythonSlowing19Python - 116ToolTrust Scanneragentsafe-ai
Scans MCP servers for prompt injection, data exfiltration, and privilege escalation.
Maintained19Node.jsstdioMaintained19Node.jsstdio - 117Wardenicoretech
Manage Bitwarden and Vaultwarden vaults via the bw CLI: search, create, edit and organize logins, notes, cards, identities, SSH keys, folders and Sends.
Active19Node.jsActive19Node.js - 118Aegis — AI Agent Governanceacacian
Policy-based governance for agent tool calls across LangChain, OpenAI, Anthropic and MCP: YAML policies, approval gates, risk assessment and audit logging.
Maintained18PythonstdioMaintained18Pythonstdio - 119FAOSTATberba-q
FAOSTAT data for 245 countries: crops, trade, food security, and emissions via 23 MCP tools.
Active18PythonstdioActive18Pythonstdio - 120Fidaajipurn
Local-first MCP gateway for coding agents that redacts detected secrets from file reads and command output before they reach model context.
Slowing18RustSlowing18Rust - 121Nekzusnekzus
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
Maintained18Node.jsstdioremoteMaintained18Node.jsstdioremote - 122Hangarmcp-hangar
Self-hosted policy enforcement for MCP server fleets: deterministic admission and egress policies, attributable audit logs and SIEM export.
Active17PythonstdioActive17Pythonstdio - 123Cortexgbrigandi
Cortex integration for observable analysis and automated security responses.
Stale17RustStale17Rust - 124Vmsjyjune
Retrieve live and recorded video from a CCTV recording program (VMS) and control it, such as opening live or playback dialogs for specific channels and times.
Maintained17PythonMaintained17Python - 125Dros Vajraclaw Hackertop-celestial-company-ltd
Deterministic execution governance gateway and W3C DID security guardrail for AI agent MCP tool calls.
Active16PythonActive16Python - 126NetsCLIfstubner
Network scanner for AI agents: discover hosts, scan TCP and UDP ports, query DNS and mDNS.
Active16Node.jsstdioActive16Node.jsstdio - 127Phantom Secretsashlrai
Value-blind secret metadata and gated workflows for AI coding agents through Phantom's local proxy.
Active16Node.jsstdioActive16Node.jsstdio - 128Thehivegbrigandi
TheHive integration for collaborative security incident response and case management.
Stale16RustStale16Rust - 129VirusTotalvirustotal
Official VirusTotal MCP server: threat reports, file and URL submissions, and analysis recovery.
Active16PythonstdioremoteActive16Pythonstdioremote - 130
s-gwsgatewayLocal credential gateway for coding agents: agents get handles instead of raw secrets, and one-time approvals inject credentials only into approved commands.
Active15Node.jsstdioActive15Node.jsstdio - 131Sdksidclawhq
Governance proxy that wraps MCP servers with policy evaluation, human approval workflows and hash-chain audit trails.
Active15Node.jsstdioActive15Node.jsstdio - 132prodlintprodlint
Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.
Maintained15Node.jsstdioMaintained15Node.jsstdio - 133Avp Sdkcreatorrmode-lead
Trust, W3C DID identity and EigenTrust reputation for AI agents, with attestations, disputes, sybil detection and IPFS audit anchoring.
Active15Node.jsActive15Node.js - 134Depguardmopanc
Pre-install npm package checks: static analysis, supply-chain attack detection, vulnerability audits, AI hallucination guard and CycloneDX SBOM generation.
Active15Node.jsActive15Node.js - 135GitHub Securitybadchars
GitHub security posture audit tools for AI agents — organization, repository, Actions, secrets, supply chain analysis via MCP
Stale15Node.jsstdioStale15Node.jsstdio - 136Prodcheckfarzamhabibi
4,372 pre-production checks: security, performance, scale, integrations, post-launch.
Active15Node.jsstdioActive15Node.jsstdio - 137Runtime Guardruntimeguard
Runtime policy enforcement for AI agents that prevents accidental system damage and unauthorized access, with automatic backups before file writes.
Slowing15PythonSlowing15Python - 138Sint Protocolsint-ai
MCP governance proxy with capability tokens, tiered approvals, fail-closed execution and tamper-evident audit receipts, plus preflight tool-risk scanning.
Active15Node.jsActive15Node.js - 139Cligetaegis
Credential isolation proxy that injects secrets at the network boundary, with domain restrictions, agent authentication and audit logging.
Maintained14Node.jsstdioMaintained14Node.jsstdio - 140quantakrypto pqc-toolsquantakrypto
Post-quantum readiness: scan code for quantum-vulnerable cryptography (RSA, ECDH, ECDSA, DH), get ML-KEM/ML-DSA/SLH-DSA migration guidance and verify fixes.
Maintained14Node.jsstdioremoteMaintained14Node.jsstdioremote - 141Abandoned14Python
- 142Aletheiavikasny30
Deterministic pre-execution filter for agent tool calls that blocks scope creep (credential reads, SSRF, destructive shell/SQL) and prompt injection.
Active12Node.jsstdioActive12Node.jsstdio - 143Assayrul1an
Fail-closed policy-as-code proxy for MCP that denies risky tool calls, produces offline-verifiable evidence bundles and enforces egress via eBPF and Landlock.
Deprecated12RuststdioDeprecated12Ruststdio - 144Koma Gateswnotmetal
Classify input for prompt injection and out-of-scope content with Koma Gate's LLM-based classifier.
Active12Node.jsstdioActive12Node.jsstdio