Category
Security MCP servers
- 289Tripwirealiboily
MCP for Roblox Studio and Open Cloud: drive Studio, run headless tests, and review game security.
Maintained3Node.jsstdioMaintained3Node.jsstdio - 290npmalisaitteke
MCP server for npm package management, security analysis, and compatibility checking
Stale3Node.jsstdioStale3Node.jsstdio - 291Chronoverifybeeswaxpat
Verify a photo's capture time and provenance: C2PA Content Credentials validation, EXIF/XMP consistency checks and pixel forensics combined into one verdict.
Maintained2Node.jsstdioMaintained2Node.jsstdio - 292Privacyscrubbermoxno
CISO-Approved Zero-Trust PII & Secrets Redaction MCP Server for Cursor, Windsurf, and Claude Desktop. Prevent API leaks and comply with HIPAA/SOC 2 locally.
Active2Node.jsstdioActive2Node.jsstdio - 293AIShield Security Scannerlm203688
AIShield - OWASP MCP Top 10 aligned security scanner. Scan MCP servers, detect tool poisoning, prompt injection, and supply chain risks.
Active2Node.jsstdioActive2Node.jsstdio - 294Agentsealjoeybrar
Action logs for AI agents: records every action in a SHA-256 hash chain as an audit trail.
Slowing2Node.jsstdioSlowing2Node.jsstdio - 295Agentstampvinaybhosle
Trust intelligence for AI agents: identity stamps, reputation scoring, a registry, forensic audit trails and A2A passports via x402 micropayments.
Stale2Node.jsremoteStale2Node.jsremote - 296Basedagentsmaxfain
Agent identity registry (reputation, capability search, task marketplace, messaging) plus a local encrypted vault that leases provider keys to agents.
Active2Node.jsstdioActive2Node.jsstdio - 297Dnsdoctordnsdoctor
Scan and fix a domain's email authentication (SPF, DMARC, DKIM, MX), blacklist status and domain/SSL expiry, with deterministic, validated fix records.
Active2Node.jsstdioremoteActive2Node.jsstdioremote - 298
EchelonGraph CVE & ExposureechelongraphCVE, KEV, EPSS, SBOM and advisory lookups; per-CVE exposure from Shodan data (© Shodan). Keyless.
Active2Node.jsstdioremoteActive2Node.jsstdioremote - 299Flagrixflagrix-io
Scan GitHub repos and profiles for malware before you clone — CLI and MCP server for the Flagrix scanner
Maintained2Node.jsstdioMaintained2Node.jsstdio - 300Gateway Scanwillianpinho
Read-only static scanner that scores MCP and agent-gateway repos on RBAC, fail-closed behavior, supply chain, observability, cost and secrets handling.
Maintained2Node.jsstdioMaintained2Node.jsstdio - 301HoneyLabshoneylabshq
Honeypot threat intelligence from a sensor network: IP reputation, scanner classification, CVE probing trends and JA4, JA4H and HASSH fingerprints.
Active2PythonremoteActive2Pythonremote - 302
DNS and email security scans via IntoDNS.ai: SPF, DKIM, DMARC, DNSSEC, MTA-STS, BIMI, TLS, blacklist and deliverability checks plus security header analysis.
Maintained2Node.jsstdioremoteMaintained2Node.jsstdioremote - 303Keycloak Adminmrz1880
Administer Keycloak via its Admin REST API: users, roles, clients, groups, identity providers, federation and events, with a read-only mode.
Maintained2Node.jsstdioMaintained2Node.jsstdio - 304Lucairndeclade
Privacy gateway that sanitizes German and English PII before prompts reach an LLM and issues a signed, timestamped certificate for each call.
Active2Node.jsstdioActive2Node.jsstdio - 305M2M Sentinelm2m-sentinel
EVM bytecode capability analysis, EIP-1967 proxy resolution, gas recommendations and preflight safety checks for agents on Base.
Active2Node.jsstdioremoteActive2Node.jsstdioremote - 306Mintfoundrynet
MINT Protocol work attestation for agents: cryptographically attest, verify, rate and discover agent work to build portable on-chain reputation.
Maintained2PythonremoteMaintained2Pythonremote - 307Prufaprufa-dev
Real-browser QA audits of a URL: broken signup, login and checkout flows, console errors, missing analytics, security headers, tap targets and accessibility.
Slowing2PythonstdioSlowing2Pythonstdio - 308Ratatoskgarlickim21
CNCF release intelligence: security fixes, breaking changes and deprecations from graduated and incubating project release notes, with local version checks.
Active2DockerstdioActive2Dockerstdio - 309Screenshotdigital-defiance
MCP server providing screenshot capture capabilities for AI agents with multi-format support, PII masking, and security controls
Stale2Node.jsstdioStale2Node.jsstdio - 310SpendShieldfelixpg13-glitch
Payment guardrails for AI agents: spend caps, budget and approval gates, prompt-injection defense, an encrypted secret vault and an audit trail.
Maintained2PythonstdioMaintained2Pythonstdio - 311Taskbounty Checkeliottreich
Local, read-only scanner for GitHub Actions and CI maintenance issues in AI-built apps, with finding explanations and fix plans.
Slowing2Node.jsstdioSlowing2Node.jsstdio - 3121Claw Vault1clawai
HSM-backed vault secrets for AI agents (JIT fetch) plus prompt-injection and threat scanning.
Active2Node.jsstdioActive2Node.jsstdio - 313Agent Trust Stackalexfleetcommander
Cryptographic provenance, blind reputation scoring and tamper-evident logging for agent interactions, with dispute resolution and trust-based matchmaking.
Slowing2Node.jsSlowing2Node.js - 314Agentdevx Sdkmirajmahmudul
Identity and credential gateway for agents: Ed25519 identity, encrypted credential vault, OPA policies with audit logging, per-agent memory and web scraping.
Maintained2Node.jsMaintained2Node.js - 315Agentvaletagentvalet
Identity and credential broker for MCP servers: issues scoped, short-lived credentials per agent, with audit logging and human approval gates.
Active2Node.jsActive2Node.js - 316Aicraft Code Reviewgoodjobwilliam
Code review as an MCP server — structured reviews with OWASP security scanning.
Active2PythonstdioActive2Pythonstdio - 317Alderpost8randonpickart5
Intelligence endpoints for security, company, threat, compliance, sales, sports, property and health data, paid via x402 micropayments on Base.
Slowing2Node.jsSlowing2Node.js - 318Android Security Analyzerako2345
MCP server for static security analysis of Android source code
Stale2remoteStale2remote - 319Ansvar: Dutch Lawansvar-systems
Cited EU & global law, regulations & security frameworks via Ansvar Gateway. OAuth, free + paid.
Maintained2remoteMaintained2remote - 320Apollo Intelligence Networkbnmbnmai
54 AI agent tools: OSINT, intel feeds, DeFi, crypto, weather, DNS, proxies. x402 micropayments.
Active2Node.jsstdioremoteActive2Node.jsstdioremote - 321Arc Gate9hannahnine-jpg
Runtime governance for MCP tool calls that blocks prompt injection and capability abuse before tool results reach the agent.
Slowing2PythonSlowing2Python - 322Arkforgeark-forge
Third-party certifying proxy that signs any HTTP call with an independent Ed25519 signature, RFC 3161 timestamp and Sigstore Rekor anchor.
Active2PythonActive2Python - 323Bajuzjefebajuzjefe
Security analysis for Aiken smart contracts on Cardano. 75 vulnerability detectors.
Stale2Node.jsstdioStale2Node.jsstdio - 324Bawbel Scannerbawbel
Scan MCP servers and skill files for AVE vulnerabilities. Conformance scoring and threat intel.
Slowing2PythonstdioSlowing2Pythonstdio - 325Cinderfi — Retirement Planningcinderfi
Retirement planning for Canada & US. CPP/OAS, Social Security, RRSP/TFSA, 401k/IRA, Monte Carlo.
Maintained2remoteMaintained2remote - 326Compliance Trestleoscal-compass
An MCP server that provides tools to author OSCAL security compliance documentation
Maintained2PythonstdioMaintained2Pythonstdio - 327Customsmcpcustoms
Inspect an MCP server for common security risks before you install it. Offline, zero telemetry.
Maintained2Node.jsstdioMaintained2Node.jsstdio - 328
Cybercentry VerificationcybercentryTwelve tools: token, wallet, contract and site security. Two free, the rest $1 in USDC over x402.
Maintained2remoteMaintained2remote - 329Datanexusmcpdatanexusmcp
Public data lookups: CVE/SBOM security audits, license compliance, patents, federal contracts, NPI providers, nonprofit 990 filings and domain intelligence.
Active2Active2 - 330DugganUSA CLI — Local STDIOpduggusa
Local STDIO MCP for DugganUSA threat intel. 1.13M IOCs. Read-only. npm: dugganusa-cli.
Active2Node.jsstdioActive2Node.jsstdio - 331Electronyawlabs
Electron.js MCP server — IPC scaffolding, security auditing, build tooling for AI assistants
Active2Node.jsstdioActive2Node.jsstdio - 332Fireflyyakupemreyerli
Security-first, self-hosted MCP server for Firefly III — 152 operations behind 5 scoped tools.
Active2Node.jsstdioActive2Node.jsstdio - 333Gitleaks GitHub Secret Scanneranshumanatrey
Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner
Active2remoteActive2remote - 334Hacktrickszebbern
Offline full-text search over the HackTricks security wiki, synced every 3 days.
Active2Node.jsstdioActive2Node.jsstdio - 335Ida Headlesszboralski
Headless IDA Pro binary analysis with concurrent sessions and Il2CppDumper and Blutter metadata import for Unity and Flutter reverse engineering.
Stale2PythonStale2Python - 336Job Board Keyword Signal Scannermambalabsdev
Scans Greenhouse, Lever, Ashby, Workday, Rippling for roles in any category. Clay-ready.
Active2Node.jsstdioActive2Node.jsstdio