Category
Security MCP servers
- 193
Draugrdraugr-devSecurity scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
Active7stdioActive7stdio - 194Minreestrvelvetway
Search the Russian software registry for import-substitution and FSTEC/FSB-certified products, with full-text search and manufacturer listings.
Slowing7PythonSlowing7Python - 195
Strac MCP Dlpstrac-ioDetect and redact PII, PHI, PCI and secrets in text and files before an AI agent sees them.
Maintained7PythonstdioMaintained7Pythonstdio - 196Supply Chain Guardhomeofe
Supply-chain malware scanner and MCP server: vet packages in 15 ecosystems before install, offline.
Active7Node.jsstdioActive7Node.jsstdio - 197Webmingjenkins20
Webmin Linux system administration: services, users, storage, security, databases and more.
Slowing7PythonSlowing7Python - 198Guardvibegoklab
Security scanner for vibe-coded apps (Next.js, Supabase, Stripe, Prisma and more): taint analysis, auto-fix, SARIF export, pre-commit hook and CVE detection.
Active6Node.jsstdioActive6Node.jsstdio - 199Anythink Clianythink-cloud
Build and run a backend on the Anythink platform: relational data with row-level security, search, RBAC, workflows, growth and retention tools, and payments.
Active6.NETstdioActive6.NETstdio - 200Apimeshmbeato
74 paid web-analysis APIs (SEO, security, TLS, DNS, email) as MCP tools. USDC via x402.
Slowing6Node.jsstdioSlowing6Node.jsstdio - 201Rad Securityrad-security
Interact with the RAD Security platform which provides AI-powered security insights for Kubernetes and cloud environments.
Active6Node.jsActive6Node.js - 202Scanjacksenechal
Minimal MCP server for scanner capture (ADF/duplex/page-size); typed tools; JSON Schema–validated I/O; multipage assembly; Node 22 + SANE.
Maintained6Node.jsstdioMaintained6Node.jsstdio - 203Authboxmarucie
Zero-knowledge password manager and MCP credential gateway: policy-gated agent access, deterministic passwords, BIP-39 recovery and a hash-chain audit trail.
Slowing6Node.jsSlowing6Node.js - 204FedRAMP 20x Requirementskevinrabun
An MCP server that provides access to FedRAMP 20x security requirements and controls.
Stale6PythonstdioStale6Pythonstdio - 205Huskhusk-security
Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs
Active6Node.jsstdioActive6Node.jsstdio - 206Pincervouchlyai
Secure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture
Stale6Node.jsstdioStale6Node.jsstdio - 207Service Public Franceonenicolas
French public services: tax, property, admin, education, healthcare, security, risks, legal texts
Stale6remoteStale6remote - 208Skill Auditeltociear
MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
Active6DockerstdioremoteActive6Dockerstdioremote - 209SkillTotalpezhik
Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
Active6PythonstdioActive6Pythonstdio - 210Verifyscopeblind
Offline verification of Ed25519/JCS-signed artifacts such as receipts, manifests and audit bundles.
Slowing6Node.jsSlowing6Node.js - 211Argusqa OSironclawdevs27
Argus — the QA layer for AI-assisted development. Claude-native (MCP) Chrome audits across 67 categories — errors, visual regressions, a11y, security, performance — no test files, secrets redacted by default (Aegis).
Maintained5Node.jsstdioMaintained5Node.jsstdio - 212Chrome Bridgefrsorrentino
Drive your logged-in Chrome via an extension: compact element refs, visual regression, accessibility, SEO and security audits, and network mocking.
Active5Node.jsstdioActive5Node.jsstdio - 213Czech PII Anonymizer & NLPbuggy1111
Anonymize PII for GDPR in Czech and many other languages using ÚFAL/LINDAT NLP (MasKIT, NameTag), plus morphology, translation and spellcheck.
Maintained5PythonstdioMaintained5Pythonstdio - 214Diffgate Reviewsrbsa
Deterministic guardrail for AI-written diffs: AST-based checks for SQLi, SSRF, XXE, hardcoded secrets and over-abstraction, scoped to the changed lines.
Maintained5Node.jsstdioMaintained5Node.jsstdio - 215Imprisekera-radim
Self-hostable human-in-the-loop approval inbox: humans approve, reject or edit proposed agent actions via web, mobile, Slack, Discord or Telegram.
Active5Node.jsstdioActive5Node.jsstdio - 216Kepiloleg-vdv
Accountability layer for AI agents: per-version passports, per-job mandates with spending limits, a fail-closed action gate and a hash-chained journal.
Active5PythonstdioActive5Pythonstdio - 217Lachesisunboundcompute
Code property graph for C, Python and TypeScript: callers/callees, data and taint flow with source-to-sink witnesses, points-to and guard/sink structure.
Maintained5PythonstdioMaintained5Pythonstdio - 218PCI DSS v4.0.1 Compliance Checkershyshlakov
PCI DSS static analysis for Go payment code: finds PAN/CVV exposure, weak crypto, missing audit logs and vulnerable deps, each mapped to a PCI requirement.
Maintained5DockerstdioMaintained5Dockerstdio - 219Siteauditvdalhambra
Website audits: SEO, security headers and SSL, Lighthouse performance, broken links, WCAG accessibility, Schema.org validation, competitor gaps and robots.txt.
Slowing5PythonstdioSlowing5Pythonstdio - 220cmdxrayaurelio-nakamura
Offline safety gate for agent shell commands: rates each command as danger, caution or none and explains every flag, pipe, redirect and subshell.
Active5Node.jsstdioActive5Node.jsstdio - 221mcpwallbehrensd
Deterministic security proxy for MCP that intercepts tool calls, enforces YAML policies, scans for secret leakage and logs everything.
Active5Node.jsstdioActive5Node.jsstdio - 222Agentavowagentavow
Signed, recomputable safety scores for MCP servers, packages and tools, with offline-verifiable attestations and a GitHub Action to gate CI merges.
Active5PythonActive5Python - 223Leakferretleakferrethq
Context-aware secret scanner: lets an AI agent scan, verify, and rewrite secrets before committing.
Slowing5Node.jsstdioSlowing5Node.jsstdio - 224Mariadbarifulislamat
MCP server for MariaDB. Read-only by default, row caps, timeouts, secrets never logged.
Maintained5Node.jsstdioMaintained5Node.jsstdio - 225MySQLarifulislamat
MCP server for MySQL. Read-only by default, row caps, statement timeouts, secrets never logged.
Maintained5Node.jsstdioMaintained5Node.jsstdio - 226Active5remote
- 227Postgresarifulislamat
MCP server for PostgreSQL. Read-only by default, row caps, timeouts, secrets never logged.
Maintained5Node.jsstdioMaintained5Node.jsstdio - 228Proofpointwyre-ai
MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.
Active5DockerstdioActive5Dockerstdio - 229Proofpointwyre-technology
MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.
Active5DockerstdioActive5Dockerstdio - 230Active5Node.js
- 231kdbxyarrasys
Read-only access to secrets in a local KeePassXC vault. Runs commands with them injected.
Maintained5DockerstdioMaintained5Dockerstdio - 232MCP Guardianrudraneel93
Security and governance proxy for MCP with YAML policies (blocklists, rate limits, token budgets), token cost tracking, health monitoring and RBAC.
Slowing4Node.jsstdioSlowing4Node.jsstdio - 233Cyntrisec CLI (Historical)cyntrisec
Local-first AWS security analyzer that discovers attack paths and generates remediations using graph theory.
Slowing4PythonstdioSlowing4Pythonstdio - 234
IPGeolocation.ioipgeolocationOfficial MCP server for IP geolocation, IP security, abuse contacts, ASN, timezone, astronomy, and user-agent parsing.
Active4Node.jsstdioActive4Node.jsstdio - 235Malcolmnagametw
Malcolm threat hunting: search and aggregate network traffic, query Suricata alerts, browse Arkime sessions and resolve NetBox assets. Read-only by default.
Active4PythonstdioActive4Pythonstdio - 236MolTrustmoltycel
Trust infrastructure for AI agents: register DIDs, verify identities, query reputation scores, rate agents and manage W3C Verifiable Credentials.
Active4PythonremoteActive4Pythonremote - 237Patch Tuesdayjonnybottles
Microsoft Patch Tuesday triage from the MSRC Security Update Guide: monthly rollups, CVE/KB lookups, supersedence chains and EPSS/CISA KEV urgency ranking.
Maintained4PythonstdioremoteMaintained4Pythonstdioremote - 238SASTskyrxin
SAST/DAST scanners (Bandit, Semgrep, Trivy, CodeQL, OWASP ZAP and more) with closed-loop remediation, SARIF/SBOM/VEX export and compliance reporting.
Slowing4PythonstdioSlowing4Pythonstdio - 239VMware Hardenvmware-skills
Read-only VMware vSphere compliance scanning and drift detection against CIS, vSphere SCG, China DJCP 2.0 and PCI-DSS, with remediation suggestions.
Active4PythonstdioActive4Pythonstdio - 240VMware NSX Securityvmware-skills
VMware NSX security: Distributed Firewall policies and rules, security groups, Traceflow troubleshooting and IDS/IPS profiles, with checks before deletion.
Active4PythonstdioActive4Pythonstdio