Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 7 of 24.
  1. Tripwirealiboily

    MCP for Roblox Studio and Open Cloud: drive Studio, run headless tests, and review game security.

    Maintained3Node.jsstdio
  2. npmalisaitteke

    MCP server for npm package management, security analysis, and compatibility checking

    Stale3Node.jsstdio
  3. Chronoverifybeeswaxpat

    Verify a photo's capture time and provenance: C2PA Content Credentials validation, EXIF/XMP consistency checks and pixel forensics combined into one verdict.

    Maintained2Node.jsstdio
  4. CISO-Approved Zero-Trust PII & Secrets Redaction MCP Server for Cursor, Windsurf, and Claude Desktop. Prevent API leaks and comply with HIPAA/SOC 2 locally.

    Active2Node.jsstdio
  5. AIShield - OWASP MCP Top 10 aligned security scanner. Scan MCP servers, detect tool poisoning, prompt injection, and supply chain risks.

    Active2Node.jsstdio
  6. Agentsealjoeybrar

    Action logs for AI agents: records every action in a SHA-256 hash chain as an audit trail.

    Slowing2Node.jsstdio
  7. Agentstampvinaybhosle

    Trust intelligence for AI agents: identity stamps, reputation scoring, a registry, forensic audit trails and A2A passports via x402 micropayments.

    Stale2Node.jsremote
  8. Agent identity registry (reputation, capability search, task marketplace, messaging) plus a local encrypted vault that leases provider keys to agents.

    Active2Node.jsstdio
  9. Dnsdoctordnsdoctor

    Scan and fix a domain's email authentication (SPF, DMARC, DKIM, MX), blacklist status and domain/SSL expiry, with deterministic, validated fix records.

    Active2Node.jsstdioremote
  10. CVE, KEV, EPSS, SBOM and advisory lookups; per-CVE exposure from Shodan data (© Shodan). Keyless.

    Active2Node.jsstdioremote
  11. Flagrixflagrix-io

    Scan GitHub repos and profiles for malware before you clone — CLI and MCP server for the Flagrix scanner

    Maintained2Node.jsstdio
  12. Gateway Scanwillianpinho

    Read-only static scanner that scores MCP and agent-gateway repos on RBAC, fail-closed behavior, supply chain, observability, cost and secrets handling.

    Maintained2Node.jsstdio
  13. HoneyLabshoneylabshq

    Honeypot threat intelligence from a sensor network: IP reputation, scanner classification, CVE probing trends and JA4, JA4H and HASSH fingerprints.

    Active2Pythonremote
  14. DNS and email security scans via IntoDNS.ai: SPF, DKIM, DMARC, DNSSEC, MTA-STS, BIMI, TLS, blacklist and deliverability checks plus security header analysis.

    Maintained2Node.jsstdioremote
  15. Administer Keycloak via its Admin REST API: users, roles, clients, groups, identity providers, federation and events, with a read-only mode.

    Maintained2Node.jsstdio
  16. Lucairndeclade

    Privacy gateway that sanitizes German and English PII before prompts reach an LLM and issues a signed, timestamped certificate for each call.

    Active2Node.jsstdio
  17. M2M Sentinelm2m-sentinel

    EVM bytecode capability analysis, EIP-1967 proxy resolution, gas recommendations and preflight safety checks for agents on Base.

    Active2Node.jsstdioremote
  18. Mintfoundrynet

    MINT Protocol work attestation for agents: cryptographically attest, verify, rate and discover agent work to build portable on-chain reputation.

    Maintained2Pythonremote
  19. Prufaprufa-dev

    Real-browser QA audits of a URL: broken signup, login and checkout flows, console errors, missing analytics, security headers, tap targets and accessibility.

    Slowing2Pythonstdio
  20. Ratatoskgarlickim21

    CNCF release intelligence: security fixes, breaking changes and deprecations from graduated and incubating project release notes, with local version checks.

    Active2Dockerstdio
  21. Screenshotdigital-defiance

    MCP server providing screenshot capture capabilities for AI agents with multi-format support, PII masking, and security controls

    Stale2Node.jsstdio
  22. SpendShieldfelixpg13-glitch

    Payment guardrails for AI agents: spend caps, budget and approval gates, prompt-injection defense, an encrypted secret vault and an audit trail.

    Maintained2Pythonstdio
  23. Taskbounty Checkeliottreich

    Local, read-only scanner for GitHub Actions and CI maintenance issues in AI-built apps, with finding explanations and fix plans.

    Slowing2Node.jsstdio
  24. HSM-backed vault secrets for AI agents (JIT fetch) plus prompt-injection and threat scanning.

    Active2Node.jsstdio
  25. Agent Trust Stackalexfleetcommander

    Cryptographic provenance, blind reputation scoring and tamper-evident logging for agent interactions, with dispute resolution and trust-based matchmaking.

    Slowing2Node.js
  26. Agentdevx Sdkmirajmahmudul

    Identity and credential gateway for agents: Ed25519 identity, encrypted credential vault, OPA policies with audit logging, per-agent memory and web scraping.

    Maintained2Node.js
  27. Agentvaletagentvalet

    Identity and credential broker for MCP servers: issues scoped, short-lived credentials per agent, with audit logging and human approval gates.

    Active2Node.js
  28. Aicraft Code Reviewgoodjobwilliam

    Code review as an MCP server — structured reviews with OWASP security scanning.

    Active2Pythonstdio
  29. Alderpost8randonpickart5

    Intelligence endpoints for security, company, threat, compliance, sales, sports, property and health data, paid via x402 micropayments on Base.

    Slowing2Node.js
  30. MCP server for static security analysis of Android source code

    Stale2remote
  31. Ansvar: Dutch Lawansvar-systems

    Cited EU & global law, regulations & security frameworks via Ansvar Gateway. OAuth, free + paid.

    Maintained2remote
  32. 54 AI agent tools: OSINT, intel feeds, DeFi, crypto, weather, DNS, proxies. x402 micropayments.

    Active2Node.jsstdioremote
  33. Arc Gate9hannahnine-jpg

    Runtime governance for MCP tool calls that blocks prompt injection and capability abuse before tool results reach the agent.

    Slowing2Python
  34. Arkforgeark-forge

    Third-party certifying proxy that signs any HTTP call with an independent Ed25519 signature, RFC 3161 timestamp and Sigstore Rekor anchor.

    Active2Python
  35. Bajuzjefebajuzjefe

    Security analysis for Aiken smart contracts on Cardano. 75 vulnerability detectors.

    Stale2Node.jsstdio
  36. Scan MCP servers and skill files for AVE vulnerabilities. Conformance scoring and threat intel.

    Slowing2Pythonstdio
  37. Retirement planning for Canada & US. CPP/OAS, Social Security, RRSP/TFSA, 401k/IRA, Monte Carlo.

    Maintained2remote
  38. Compliance Trestleoscal-compass

    An MCP server that provides tools to author OSCAL security compliance documentation

    Maintained2Pythonstdio
  39. Customsmcpcustoms

    Inspect an MCP server for common security risks before you install it. Offline, zero telemetry.

    Maintained2Node.jsstdio
  40. Twelve tools: token, wallet, contract and site security. Two free, the rest $1 in USDC over x402.

    Maintained2remote
  41. Datanexusmcpdatanexusmcp

    Public data lookups: CVE/SBOM security audits, license compliance, patents, federal contracts, NPI providers, nonprofit 990 filings and domain intelligence.

    Active2
  42. Local STDIO MCP for DugganUSA threat intel. 1.13M IOCs. Read-only. npm: dugganusa-cli.

    Active2Node.jsstdio
  43. Electronyawlabs

    Electron.js MCP server — IPC scaffolding, security auditing, build tooling for AI assistants

    Active2Node.jsstdio
  44. Fireflyyakupemreyerli

    Security-first, self-hosted MCP server for Firefly III — 152 operations behind 5 scoped tools.

    Active2Node.jsstdio
  45. Gitleaks Cloud - GitHub API Key Hunter & Secret Scanner

    Active2remote
  46. Hacktrickszebbern

    Offline full-text search over the HackTricks security wiki, synced every 3 days.

    Active2Node.jsstdio
  47. Ida Headlesszboralski

    Headless IDA Pro binary analysis with concurrent sessions and Il2CppDumper and Blutter metadata import for Unity and Flutter reverse engineering.

    Stale2Python
  48. Scans Greenhouse, Lever, Ashby, Workday, Rippling for roles in any category. Clay-ready.

    Active2Node.jsstdio

Related categories