Skip to content
mcp/skillhub

Category

Security MCP servers

1,107 security MCP servers, ranked by popularity. Each listing has copy-paste install for Claude Code, Cursor, VS Code, Claude Desktop and Windsurf. Page 8 of 24.
  1. Keellutfizp

    Control plane MCP that dedups scanner output, rate-limits hosts, and runs non-destructive proofs.

    Maintained2Pythonstdio
  2. KubeStellarkubestellar

    AI-powered Kubernetes diagnostics, RBAC analysis, security checks, and app deployment via MCP

    Active2Dockerstdio
  3. Mcpampelmcpampel

    Scan installed MCP servers for security vulnerabilities with 16 detection engines.

    Stale2Pythonstdio
  4. Mispppcvote

    Read-only MISP threat intelligence (events, attributes, search, tags, feeds, galaxies) with prompt injection scanning of every response.

    Slowing2Node.js
  5. Security-first MySQL MCP server with AST validation, table whitelist, schema resources, and audit.

    Active2Dockerstdio
  6. Opentermsjstibal

    Ed25519-signed consent receipts and a policy engine for agents: spending caps, action allowlists, escalation thresholds and JWKS-backed provider verification.

    Slowing2Python
  7. Pluginwiserautomation

    SupraWall security gateway for AI agents. Provides deterministic guardrails for MCP agents.

    Slowing2Node.jsstdio
  8. Security gateway for AI agents: detects prompt injections, jailbreaks, and common vulnerabilities.

    Active2Node.jsstdio
  9. Raven Nesttidynest

    AI-driven penetration testing - 22 security tools behind safety-hardened MCP endpoints

    Active2Dockerstdio
  10. Razieltide-foundation

    MCP server teaching AI agents to implement TideCloak: auth, E2EE, IGA, security analysis

    Active2Node.jsstdioremote
  11. Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.

    Active2remote
  12. Sentineloaslananka

    Zero-trust MCP security proxy with policy enforcement, PII scrubbing, approvals, and audit trails.

    Active2Node.jsstdio
  13. Shieldbuildwithabid

    Security scanner for MCP servers. Find vulnerabilities before your AI agent does.

    Active2Node.jsstdio
  14. Shieldmuhannad-hash

    Pre-install security scanner for MCP servers: detects backdoors, exfiltration code, obfuscation, dangerous execution, prompt injection and supply chain risks.

    Slowing2Node.js
  15. Shimjamjet-labs

    MCP interceptor that applies one YAML policy (block, require approval, audit, budget cap) to tool calls, also usable in Claude Code hooks and agent SDKs.

    Maintained2Node.js
  16. Sicarius Guardchronolapse411

    Solana token safety oracle: byte-level SPL mint analysis, honeypot detection, freeze/mint authority checks, Birdeye market data and composite risk scoring.

    Slowing2Node.js
  17. Starter Seriesstarter-series

    Scaffold Starter Series projects and check release, deployment, security, and agent instructions.

    Active2Node.jsstdio
  18. Generate API test cases from Swagger/OpenAPI specs (auth, validation, boundary, security and more) and export them to Gherkin, Postman, k6, pytest or TestRail.

    Slowing2Node.js
  19. Tableclothyourtablecloth

    Open Korean e-Gov and finance sites in a clean, disposable Windows Sandbox with security programs.

    Maintained2Node.jsstdio
  20. Trestletoro-guapo

    Detects leaked secrets (API keys, tokens, private keys) in source code.

    Slowing2Node.jsstdio
  21. Trustboost APIteodorofodocrispin-cmyk

    Redacts emails, phone numbers, national IDs, private keys and financial data before text reaches LLMs, in English, Spanish, Portuguese, German and Japanese.

    Active2Python
  22. Valcapranlabs

    Scans code, IaC and AI-agent config for security problems. Read-only — nothing can be edited.

    Active2Pythonstdio
  23. Write, validate and convert Sigma detection rules for Splunk, Elastic, Kibana and Wazuh, backed by a rule corpus covering MITRE ATT&CK tactics.

    Active2Python
  24. mlab.shmlab-sh

    Threat intelligence: enrich IOCs (IP, domain, URL, hash), search CVEs and actors, scan SBOMs.

    Maintained2remote
  25. npm registry MCP server — package intelligence, security audits, dependency analysis

    Active2Node.jsstdio
  26. Agentscore Xyzthezenmonster

    Security trust layer that monitors MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift and publisher posture.

    Slowing1Node.jsstdio
  27. Cleaner Codegoldmembrane

    Locally scans AI-generated code for invisible Unicode, Trojan Source, homoglyphs, rules file backdoors and typosquatting using static analysis and CodeBERT.

    Slowing1Node.jsstdio
  28. Mcpskillsiobebravebekind

    Scores MCP servers, AI skills and npm packages before install, scanning for prompt injection, credential theft and supply-chain risk, with a go/no-go gate.

    Slowing1Node.jsstdio
  29. Pre-execution governance for agent tool calls: risk classification, behavioral drift detection, a hold queue for dangerous operations and an audit trail.

    Active1Node.jsstdio
  30. RankCLIintegrallis

    SEO and GEO (AI search) analysis: Core Web Vitals, structured data, security headers, mobile SEO, image audits, internal linking and AI crawler access.

    Active1Node.jsstdio
  31. Redact PDFdambuchs

    Permanently redact PII (names, emails, phone numbers, addresses, IBANs, card numbers) from PDFs, scans and screenshots, with multilingual OCR.

    Active1Node.jsstdio
  32. ARGUS-3alexar76

    Query ARGUS-3 and check its status; WARDEN vets third-party MCP servers with a scored firewall, tool-definition pinning and drift detection.

    Active1Node.jsstdio
  33. WCAG 2.1 AA accessibility scanner (Playwright + axe-core) with grounded, browser-verified fixes. MCP server for Claude Code and any MCP client; also a Claude Code plugin.

    Active1Node.jsstdio
  34. AgentAegisastafford8488

    Scan MCP servers and skills before install, vet endpoints before calling them, and run vulnerability scans, threat intel and compliance checks.

    Maintained1Node.jsremote
  35. Self-hosted security layer that evaluates AI agents' proposed blockchain transactions and returns an explainable allow, warn or block decision.

    Active1Pythonstdio
  36. On-chain trust oracle for ERC-8004 and x402 agents: composite trust scoring, a scam wallet database, ERC-8004 identity lookup and EAS attestations on Base.

    Slowing1Node.jsstdio
  37. Aggreteaggrete

    Policy proxy that refuses forbidden tool calls, stopping prompt-injection exfiltration and forbidden data combinations across Slack, Drive, GitHub and more.

    Active1Pythonstdio
  38. Agntoragntor

    Agent discovery and certification with a trust and payment rail: identity verification, escrow, settlement and reputation management.

    Stale1Node.jsstdio
  39. Aimarketalexar76

    SSRF-hardened web gateway with web fetch, web search and Metis verification, sharing an audited security core with Metis and ARGUS.

    Active1Pythonstdioremote
  40. Arcwallrom-baro

    Arcwall Security MCP server for Claude Code, Cursor, Windsurf and any MCP-compatible AI coding tool

    Slowing1Node.jsstdio
  41. BeVigil OSINTsanthosh-005

    MCP server for the BeVigil OSINT API — mobile app attack surface discovery (hosts, subdomains, S3 buckets, wordlists) for AI agents

    Maintained1Node.jsstdio
  42. Captchazekebuilds-lab

    Middleware that gates MCP tool calls behind a Hashcash proof-of-work challenge or an L402 Lightning payment via self-hosted LNbits.

    Maintained1Node.jsstdio
  43. Dcl Webhookfronesis-labs

    Deterministic audit layer that checks LLM and agent outputs against jailbreak, safety and trading compliance policies and logs verdicts to a hash chain.

    Active1Pythonremote
  44. Dechonetnode-man

    Domain security checks: DNS, DNSSEC, TLS grading, HTTP security headers, SPF, DKIM and DMARC, port scans, ASN, RDAP and WHOIS, plus an overall health score.

    Active1Node.jsstdioremote
  45. DemandScopebaobabcat

    Demand-signal scanner for validating product and dev-tool ideas using GitHub repo signals, Hacker News attention and npm/PyPI download counts.

    Maintained1Pythonstdio
  46. Derbenttunahanaliozturk

    One local gate for Claude Code, Codex, Copilot CLI and Antigravity: allow, deny and ask rules over MCP and built-in tool calls, approvals from a terminal UI, and hash-chained receipts.

    Active1Go
  47. Everstakeeverstake

    Everstake non-custodial staking data across many networks: live APY, uptime metrics, rewards calculator, integrations, security and compliance info.

    Maintained1remote
  48. Forcedreamforcedreamai

    Discover, invoke and verify agents on a paid marketplace: code generation, security scanning (OSV.dev, GitGuardian) and lead scoring, with signed results.

    Maintained1Node.jsstdioremote

Related categories