Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 4 of 24.
  1. Verify agent communication protocols with session types and Lean 4 proofs to catch deadlocks and role violations; includes a linter, formatter and LSP.

    Maintained12Pythonstdio
  2. Auth proxy for MCP servers: OAuth2 with DCR, JWT, RBAC, rate limiting, multi-server aggregation and a monitoring dashboard.

    Active12Python
  3. Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

    Slowing12Pythonstdio
  4. Irulescansimonkowallik

    :shield: MCP enabled code security analyzer for F5 iRules

    Abandoned12
  5. TAPholonym-foundation

    Credential isolation for AI agents: placeholder secrets, policy checks, optional human approval.

    Maintained12remote
  6. Local guardrail proxy for MCP servers: blocks destructive tool calls, pins tool catalogs against rug pulls and scans for tool poisoning and prompt injection.

    Active11Dockerstdio
  7. EU AI Actark-forge

    EU AI Act compliance scanner that detects regulatory violations in AI codebases, with risk classification and remediation guidance.

    Active11Node.jsremote
  8. Scopeblindtomjwxf

    Security gateway that wraps MCP servers with per-tool policies, approval gates and optional signed receipts, in shadow (log-only) or enforce mode.

    Slowing11Node.jsstdio
  9. Conanconan-io

    Conan C/C++ package manager: create projects, manage dependencies, check licenses and scan for security vulnerabilities.

    Stale11Python
  10. Dm8mzaxd

    MCP server for DM8 database operations with enhanced security. Provides read-only database access via Model Context Protocol.

    Active11Node.jsstdio
  11. MobiLoopenessubass

    Guarded AI mobile Appium testing, security scanning, verification, and fix-retest MCP tools.

    Active11Dockerstdio
  12. Opnsensecoreyhines

    OPNsense firewall operations via API: query ARP, DHCP, firewall rules, logs, interfaces, system status and packet captures.

    Maintained11Node.js
  13. Remote SSHfaizbawa

    SSH access with persistent sessions, SFTP and port forwarding, with secrets injected via stdin and redacted from output before reaching the LLM.

    Maintained11Python
  14. Secretctlforest6511

    Secrets manager that injects credentials into commands as environment variables so agents never see plaintext secrets, and sanitizes command output.

    Stale11Go
  15. Vulnicheckandrasfe

    HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.

    Stale11Dockerremote
  16. pkgxrayadamsjack711-ux

    Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.

    Active11Node.jsstdio
  17. AI Soc Sherakramiot

    Dynamic SOC security threat analysis for a Text2SQL AI agent.

    Abandoned10Node.js
  18. AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.

    Active10remote
  19. VulnCheckvulncheck-oss

    VulnCheck exploit intelligence — CVE research, exploit data, advisories, and threat analysis.

    Active10Dockerstdio
  20. Zitadeltakleb3rry

    Zitadel identity management: manage users, projects, OIDC apps, roles and service accounts in natural language.

    Active10Node.js
  21. PerspectiveGraphluiacuaniello

    Attack-path engine for cloud and Kubernetes: list routes from internet exposure to sensitive assets, explain each hop, find choke points and simulate fixes.

    Active9Dockerstdio
  22. DNS and email security scanner with 81 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.

    Active9remote
  23. Thales CipherTrust Manager integration for key management, cryptographic operations and compliance monitoring.

    Maintained9Python
  24. Clearfrontscottmartinanderson

    OSINT sweep of a digital footprint: breaches, accounts, data brokers, domains and IPs

    Maintained9Pythonstdio
  25. PostgreSQL MCP server for schema, query, health, security, and performance analysis.

    Slowing9Dockerstdio
  26. Analyze GitHub repositories' tech stack, dependencies, architecture, health metrics and security indicators with deterministic JSON output.

    Slowing9Python
  27. Royalroyalplugins

    Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.

    Active9remote
  28. Stackhawkstackhawk

    An MCP server that provides interaction with StackHawk's security scanning platform.

    Slowing9Pythonstdio
  29. Trenttrnt-ai

    Security reviews, threat models over a repo or website, and remediation tracking, in your editor.

    Active9remote
  30. Fetch recent public X/Twitter posts by named handle for monitoring, comparison, OSINT, and research.

    Maintained9remote
  31. SPARDAzakariagharzouli

    Injects a live, reversible MCP server into a running Express, FastAPI or Next.js app, with safe reads by default and writes gated behind human confirmation.

    Active8Node.jsstdio
  32. Supply chain risk scoring for npm, PyPI, Cargo and Go packages from behavioral signals: publisher depth, release consistency and maintenance patterns.

    Active8Node.jsstdioremote
  33. Jobverifyyessglory17

    Check recruiters and job offers for scams: cross-checks company registration, domain age, look-alike domains, blocklists and crypto-scam databases.

    Slowing8Pythonstdio
  34. OPAorygnscode

    OPA and Rego policy toolkit wrapping the OPA CLI and Regal: format, lint, evaluate, test and benchmark policies, manage the OPA REST API and explain decisions.

    Active8Node.jsstdio
  35. Threatintelaplaceforallmystuff

    MCP server for unified threat intelligence - AlienVault OTX, AbuseIPDB, GreyNoise, and abuse.ch feeds

    Maintained8Node.jsstdio
  36. Acidtestchuckyatsuk

    Security scanner for MCP servers and AI agent skills. Scan before you install.

    Maintained8Node.jsstdio
  37. Auditp4st4s

    Transparent proxy that intercepts, signs, rate-limits, redacts and audits MCP tool calls without modifying client or server.

    Slowing8Go
  38. Chrome MCP Securepantheon-security

    Security-hardened Chrome automation and logins with post-quantum encryption, a credential vault, memory scrubbing and audit logging.

    Stale8Node.js
  39. Hexforge Gatewayboy-offi9-inc

    APK reverse engineering workspace that orchestrates jadx, apktool, adb and Frida through a workflow engine, on Termux (Android) or PC.

    Active8Node.js
  40. Mcpsafetywardengautamvarmadatla

    MCP proxy adding security scanning, behavioral profiling, risk gating, and safe tool call execution.

    Active8Pythonstdio
  41. MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage

    Active8Pythonstdio
  42. Wasstb0hdan

    MCP server for web application security scanning

    Stale8
  43. Bastiongowthaman90

    Security proxy for MCP servers: tool-definition pinning, tool-poisoning and exfiltration detection, injection blocking, secret redaction and audit trails.

    Active7Node.jsstdio
  44. Judges Panelkevinrabun

    45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.

    Stale7Node.jsstdio
  45. Stock Scanneryyordanov-tradu

    MCP server providing Claude Code with real-time stock and crypto market data, SEC filings, insider trades, and technical analysis

    Active7Node.jsstdio
  46. Urldnaurldna

    URL scanning and phishing triage: capture DOM snapshots, network requests and screenshots, and hunt historical scans with a custom query language.

    Maintained7Python
  47. Araitaniwhaai

    Enforces rules from existing agent instruction files (CLAUDE.md, .cursorrules) by blocking prohibited tool calls and logging per-rule compliance verdicts.

    Active7Rust
  48. Bastion Pythonvaquarkhan

    Security middleware for MCP. Blocks prompt injection, PII leakage, and resource exhaustion.

    Active7Pythonstdio

Related categories