Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 5 of 24.
  1. Draugrdraugr-dev

    Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.

    Active7stdio
  2. Minreestrvelvetway

    Search the Russian software registry for import-substitution and FSTEC/FSB-certified products, with full-text search and manufacturer listings.

    Slowing7Python
  3. Detect and redact PII, PHI, PCI and secrets in text and files before an AI agent sees them.

    Maintained7Pythonstdio
  4. Supply-chain malware scanner and MCP server: vet packages in 15 ecosystems before install, offline.

    Active7Node.jsstdio
  5. Webmingjenkins20

    Webmin Linux system administration: services, users, storage, security, databases and more.

    Slowing7Python
  6. Guardvibegoklab

    Security scanner for vibe-coded apps (Next.js, Supabase, Stripe, Prisma and more): taint analysis, auto-fix, SARIF export, pre-commit hook and CVE detection.

    Active6Node.jsstdio
  7. Anythink Clianythink-cloud

    Build and run a backend on the Anythink platform: relational data with row-level security, search, RBAC, workflows, growth and retention tools, and payments.

    Active6.NETstdio
  8. Apimeshmbeato

    74 paid web-analysis APIs (SEO, security, TLS, DNS, email) as MCP tools. USDC via x402.

    Slowing6Node.jsstdio
  9. Rad Securityrad-security

    Interact with the RAD Security platform which provides AI-powered security insights for Kubernetes and cloud environments.

    Active6Node.js
  10. Scanjacksenechal

    Minimal MCP server for scanner capture (ADF/duplex/page-size); typed tools; JSON Schema–validated I/O; multipage assembly; Node 22 + SANE.

    Maintained6Node.jsstdio
  11. Authboxmarucie

    Zero-knowledge password manager and MCP credential gateway: policy-gated agent access, deterministic passwords, BIP-39 recovery and a hash-chain audit trail.

    Slowing6Node.js
  12. An MCP server that provides access to FedRAMP 20x security requirements and controls.

    Stale6Pythonstdio
  13. Huskhusk-security

    Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs

    Active6Node.jsstdio
  14. Pincervouchlyai

    Secure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture

    Stale6Node.jsstdio
  15. French public services: tax, property, admin, education, healthcare, security, risks, legal texts

    Stale6remote
  16. Skill Auditeltociear

    MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.

    Active6Dockerstdioremote
  17. Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.

    Active6Pythonstdio
  18. Verifyscopeblind

    Offline verification of Ed25519/JCS-signed artifacts such as receipts, manifests and audit bundles.

    Slowing6Node.js
  19. Argusqa OSironclawdevs27

    Argus — the QA layer for AI-assisted development. Claude-native (MCP) Chrome audits across 67 categories — errors, visual regressions, a11y, security, performance — no test files, secrets redacted by default (Aegis).

    Maintained5Node.jsstdio
  20. Chrome Bridgefrsorrentino

    Drive your logged-in Chrome via an extension: compact element refs, visual regression, accessibility, SEO and security audits, and network mocking.

    Active5Node.jsstdio
  21. Anonymize PII for GDPR in Czech and many other languages using ÚFAL/LINDAT NLP (MasKIT, NameTag), plus morphology, translation and spellcheck.

    Maintained5Pythonstdio
  22. Deterministic guardrail for AI-written diffs: AST-based checks for SQLi, SSRF, XXE, hardcoded secrets and over-abstraction, scoped to the changed lines.

    Maintained5Node.jsstdio
  23. Imprisekera-radim

    Self-hostable human-in-the-loop approval inbox: humans approve, reject or edit proposed agent actions via web, mobile, Slack, Discord or Telegram.

    Active5Node.jsstdio
  24. Kepiloleg-vdv

    Accountability layer for AI agents: per-version passports, per-job mandates with spending limits, a fail-closed action gate and a hash-chained journal.

    Active5Pythonstdio
  25. Lachesisunboundcompute

    Code property graph for C, Python and TypeScript: callers/callees, data and taint flow with source-to-sink witnesses, points-to and guard/sink structure.

    Maintained5Pythonstdio
  26. PCI DSS static analysis for Go payment code: finds PAN/CVV exposure, weak crypto, missing audit logs and vulnerable deps, each mapped to a PCI requirement.

    Maintained5Dockerstdio
  27. Siteauditvdalhambra

    Website audits: SEO, security headers and SSL, Lighthouse performance, broken links, WCAG accessibility, Schema.org validation, competitor gaps and robots.txt.

    Slowing5Pythonstdio
  28. cmdxrayaurelio-nakamura

    Offline safety gate for agent shell commands: rates each command as danger, caution or none and explains every flag, pipe, redirect and subshell.

    Active5Node.jsstdio
  29. mcpwallbehrensd

    Deterministic security proxy for MCP that intercepts tool calls, enforces YAML policies, scans for secret leakage and logs everything.

    Active5Node.jsstdio
  30. Agentavowagentavow

    Signed, recomputable safety scores for MCP servers, packages and tools, with offline-verifiable attestations and a GitHub Action to gate CI merges.

    Active5Python
  31. Leakferretleakferrethq

    Context-aware secret scanner: lets an AI agent scan, verify, and rewrite secrets before committing.

    Slowing5Node.jsstdio
  32. Mariadbarifulislamat

    MCP server for MariaDB. Read-only by default, row caps, timeouts, secrets never logged.

    Maintained5Node.jsstdio
  33. MySQLarifulislamat

    MCP server for MySQL. Read-only by default, row caps, statement timeouts, secrets never logged.

    Maintained5Node.jsstdio
  34. PhoneInfoga - International Phone Number OSINT

    Active5remote
  35. Postgresarifulislamat

    MCP server for PostgreSQL. Read-only by default, row caps, timeouts, secrets never logged.

    Maintained5Node.jsstdio
  36. Proofpointwyre-ai

    MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.

    Active5Dockerstdio
  37. Proofpointwyre-technology

    MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.

    Active5Dockerstdio
  38. Scalekitscalekit-inc

    Manage Scalekit organizations, users and SSO.

    Active5Node.js
  39. kdbxyarrasys

    Read-only access to secrets in a local KeePassXC vault. Runs commands with them injected.

    Maintained5Dockerstdio
  40. MCP Guardianrudraneel93

    Security and governance proxy for MCP with YAML policies (blocklists, rate limits, token budgets), token cost tracking, health monitoring and RBAC.

    Slowing4Node.jsstdio
  41. Local-first AWS security analyzer that discovers attack paths and generates remediations using graph theory.

    Slowing4Pythonstdio
  42. IPGeolocation.ioipgeolocation

    Official MCP server for IP geolocation, IP security, abuse contacts, ASN, timezone, astronomy, and user-agent parsing.

    Active4Node.jsstdio
  43. Malcolmnagametw

    Malcolm threat hunting: search and aggregate network traffic, query Suricata alerts, browse Arkime sessions and resolve NetBox assets. Read-only by default.

    Active4Pythonstdio
  44. MolTrustmoltycel

    Trust infrastructure for AI agents: register DIDs, verify identities, query reputation scores, rate agents and manage W3C Verifiable Credentials.

    Active4Pythonremote
  45. Patch Tuesdayjonnybottles

    Microsoft Patch Tuesday triage from the MSRC Security Update Guide: monthly rollups, CVE/KB lookups, supersedence chains and EPSS/CISA KEV urgency ranking.

    Maintained4Pythonstdioremote
  46. SASTskyrxin

    SAST/DAST scanners (Bandit, Semgrep, Trivy, CodeQL, OWASP ZAP and more) with closed-loop remediation, SARIF/SBOM/VEX export and compliance reporting.

    Slowing4Pythonstdio
  47. VMware Hardenvmware-skills

    Read-only VMware vSphere compliance scanning and drift detection against CIS, vSphere SCG, China DJCP 2.0 and PCI-DSS, with remediation suggestions.

    Active4Pythonstdio
  48. VMware NSX Securityvmware-skills

    VMware NSX security: Distributed Firewall policies and rules, security groups, Traceflow troubleshooting and IDS/IPS profiles, with checks before deletion.

    Active4Pythonstdio

Related categories