Security MCP Servers
Security category — 262 MCP servers, ranked by GitHub stars.
AIM-MCP
Security-focused MCP server that provides safety guidelines and content analysis for AI agents.
mobsf-mcp-server
A MCP server for MobSF which can be used for static and dynamic analysis of Android and iOS application.
attestable-mcp-server
An MCP server running inside a trusted execution environment (TEE) via Gramine, showcasing remote attestation using…
agentward
Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive…
CyberChef-MCP
CyberChef's 504 data-transformation operations as MCP tools: encryption, encoding, forensics.
mastyf.ai
Runtime proxy for MCP security, cost governance & audit
fida
Local-first MCP gateway for coding agents that redacts detected secrets from file reads and command output before they reach model context.
npm-sentinel-mcp
Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.
csl-core
Deterministic AI safety policy engine with Z3 formal verification. Write, verify, and enforce machine-verifiable constraints for AI agents…
mcp-server-cortex
A Rust-based MCP server to integrate Cortex, enabling observable analysis and automated security responses through AI.
warden-mcp
MCP server for Bitwarden and Vaultwarden vault management. Search, create, edit, and organize logins, notes, cards, identities, SSH keys,…
mcp_vms
A Model Context Protocol (MCP) server designed to connect to a CCTV recording program (VMS) to retrieve recorded and live video streams.…
Aegis — AI Agent Governance
Policy-based governance for AI agent tool calls. YAML policy, approval gates, audit logging.
depguard
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory…
agentveil-sdk
Trust, identity (W3C DID), and EigenTrust reputation for AI agents. Attestations, disputes, sybil detection, IPFS audit anchoring.
mcp-server-thehive
A Rust-based MCP server to integrate TheHive, facilitating collaborative security incident response and case management via AI.
MCP Hangar
Policy enforcement plane for MCP: every tool call ends in a verdict. Self-hosted, MIT.
runtime-guard
Runtime policy enforcement for AI agents - prevents accidental damage to your systems, unauthorized agent access and automates…
s-gw
Keep credentials out of AI coding agents with local approvals, scoped injection, and audit trails.
aegis
Credential isolation for AI agents. Inject secrets at the network boundary.
vuln-nist-mcp-server
A Model Context Protocol (MCP) server for querying NIST National Vulnerability Database (NVD) API endpoints.
platform
Governance proxy for MCP servers — policy evaluation, human approval, audit trails.
sint-protocol
Security-first MCP governance proxy (`sint-mcp`) with capability tokens, T0-T3 approval tiers, fail-closed execution, and tamper-evident…
MobiLoop
Guarded AI mobile Appium testing, security scanning, verification, and fix-retest MCP tools.
authmcp-gateway
[glama](https://glama.ai/mcp/servers/@loglux/auth-mcp-gateway) 🐍 ☁️ 🏠 🍎 🪟 🐧 - Auth proxy for MCP servers: OAuth2 + DCR, JWT, RBAC, rate…
quantakrypto pqc-tools
Scan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.
Koma Core MCP
Protected RAG storage — agents discover public metadata, content only by access token.
pkgxray
Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.
vulnicheck
HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.
Aperion Shield
Local guardrail proxy that blocks destructive MCP tool calls, rug pulls, and tool poisoning
Lingua Universale MCP Server
Verify AI agent communication with session types and formal proofs
Bawbel Scanner
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
opnsense-mcp
OPNsense firewall operations via API. Query ARP, DHCP, firewall rules, logs, interfaces, system status, and packet capture via STDIO or SSE.
secretctl
AI-safe secrets manager with MCP integration. Run commands with credentials injected as environment variables - AI agents never see…
Bug Bounty Intelligence
AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.
assay
The firewall for MCP tool calls. Block, audit, replay with evidence bundles.
stackhawk-mcp
An MCP server that provides interaction with StackHawk's security scanning platform.
zitadel-mcp
MCP server for Zitadel identity management — manage users, projects, OIDC apps, roles, and service accounts through natural language.
scopeblind-gateway
Scan, protect, and monitor APIs from AI coding tools. Device-level rate limiting.
ciphertrust-manager-mcp-server
MCP server for Thales CipherTrust Manager integration, enabling secure key management, cryptographic operations, and compliance monitoring…
OPA MCP
Author, validate, debug, and explain OPA Rego policies through any MCP-compatible client.
job-verify
Detect fake-recruiter and job-offer scams using free OSINT. No API keys.
SPARDA
AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
hexforge-gateway
AI-assisted APK reverse-engineering workspace. Orchestrates jadx, apktool, adb, and frida as MCP agents through a Workflow engine, with a…
PerspectiveGraph
Read-only attack-path tools: reachable routes to sensitive assets, and what a fix would cut.
mcp-audit
Transparent Go proxy that intercepts, signs, rate-limits, redacts, and audits all MCP JSON-RPC tool calls without modifying client or…
Commit — Supply Chain Risk Scoring
Supply chain risk scoring for npm, PyPI, Cargo, and Go. 9 tools. Behavioral signals.
arai
Policy enforcement for AI coding agents derived from existing instruction files (CLAUDE.md, .cursorrules, .windsurfrules,…
mcp
MCP server for automated URL scanning and forensic phishing triage. Captures full DOM snapshots, network requests, and visual screenshots…
minreestr-mcp
Search каталогпо.рф (Russian software registry, 26k+ products) for import-substitution and ФСТЭК/ФСБ-certified software discovery. Three…
mcp-bastion
Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.
mcp-server
MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for…
enigma-python-mcp
A Model Context Protocol server that brings the capabilities of [enigmapython](https://github.com/denismaggior8/enigma-python) library to…
guardvibe
Deterministic security layer your AI can't be. 472 rules, 39 tools, CLI + doctor + host audit.
q-ring
OS keychain secrets for AI coding agents, over MCP.
authbox
Zero-knowledge password manager with MCP credential gateway. BIP-39 seed phrase recovery, deterministic passwords, policy-gated AI agent…
scalekit-mcp-server
Hosted Scalekit MCP. Manage orgs, users, and SSO from the agent. https://mcp.scalekit.com
verify-mcp
Offline verification of signed artifacts -- receipts, manifests, audit bundles. Ed25519 + JCS. No accounts, no API calls. Apache-2.0.
Impri
Impri MCP server — human-in-the-loop approval inbox for AI agents
Agent Passport System — Cryptographic Identity for AI Agents
Cryptographic identity, delegation, governance, and commerce for AI agents. 152 tools.