Security MCP Servers
Security category — 262 MCP servers, ranked by GitHub stars.
AgentAvow
Signed, independently-recomputable safety scores for the MCP servers, packages, and tools an agent connects to: a 0–100 score plus an…
cmdxray
Offline MCP server: explains shell commands token-by-token and flags destructive ones for AI agents.
mcpwall
iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything.
Czech PII Anonymizer & NLP
Anonymize PII & redact text (GDPR): Czech + 35-lang NER, morphology, translation, spellcheck
Cyntrisec CLI (Historical)
Historical AWS analysis CLI; not a current Cyntrisec product.
patch-tuesday-mcp
Query Microsoft Patch Tuesday security updates (MSRC) with EPSS and CISA KEV enrichment
qURL
Mint, resolve, audit, and rotate scope-limited expiring access links (qURLs) for AI agents.
MolTrust MCP Server
Give an agent a verifiable identity, and check another agent's before dealing with it.
osv-ui
Visual CVE audit dashboard for npm, Python, Go, and Rust. Scan from Claude/Cursor, opens a browser UI for human review…
solvitor-mcp
Solvitor MCP server provides tools to access reverse engineering tools that help developers extract IDL files from closed-source Solana…
mcp-server
55 tools for verified public data lookups — CVE/SBOM security audits, licence compliance, patents, federal contracts, NPI provider…
inkog-mcp
Security co-pilot for AI agents. Scan for vulnerabilities, audit MCP servers, verify governance.
shohei
Rust infrastructure diagnostics MCP server for AI agents: DNS checks, TLS certificate chain inspection, email security, global DNS…
mcp-server-malcolm
MCP server for Malcolm (Zeek/Suricata/Arkime/OpenSearch): threat-hunting access for AI agents
kepil
Passport, mandate, fail-closed action gate and tamper-evident journal for AI agents.
mcp-guardian
Security, cost, and health governance proxy for MCP infrastructure
thales-cdsp-cakm-mcp-server
MCP server for Thales CDSP CAKM integration, enabling secure key management, cryptographic operations, and compliance monitoring through…
thales-cdsp-crdp-mcp-server
MCP server for Thales CipherTrust Manager RestFul Data Protection service.
PCI DSS v4.0.1 Compliance Checker
PCI DSS v4.0.1 compliance scanner for Go payment services, delivered as an MCP server
SAST MCP Server
11-scanner SAST/DAST MCP server with closed-loop remediation, SBOM/SARIF, and CI integrations
Lachesis
Compiler-precise code property graph for C, Python, and TypeScript, navigable over MCP.
VMware Harden
VMware compliance scanning (CIS, vSphere SCG, GB/T 22239, PCI-DSS) with drift detection.
arc-gate-mcp
Runtime governance for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.
AgentValet
Identity and credential governance broker for MCP servers. Issues scoped, short-lived credentials per agent to stop credential…
air-blackbox-mcp
EU AI Act compliance scanner for Python AI agents. 14 tools across 6 articles.
arkforge-mcp
Third-party certifying proxy — sign any HTTP call (AI agents, webhooks, microservices) with an independent Ed25519 signature, RFC 3161…
chronoverify-mcp
Verify a photo's capture time and provenance: C2PA validation, EXIF/XMP, and pixel forensics.
calllint
Static preflight safety gate for MCP servers — scan configs before you run them. Never executes.
sicarius-guard
Solana token safety oracle for AI agents and trading bots. Byte-level SPL mint analysis, honeypot detection, freeze/mint authority checks,…
lucairn-sdks
Pseudonymizes PII before your LLM and returns a cryptographically signed receipt per response.
waxseal-sdk
Ed25519 identity for AI agents. Verify seals, sign documents, gate actions with approvals.
claude-plugin
Scan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.
taskbounty-check
Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit.
SpendShield
Authorization layer between AI agents and money: ALLOW/APPROVAL/DENY, budgets, audit.
MINT Protocol — Universal Work Attestation
Trust stack for AI agents: identity, attest, verify, rate, recommend, discover — on Solana.
HoneyLabs
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
jamjet-policy
MCP stdio interceptor (`@jamjet/mcp-shim`) that applies one YAML policy file (block / require_approval / audit / budget cap) to…
openterms-mcp
Ed25519-signed consent receipts and programmable policy engine for AI agents. Spending caps, action whitelists, escalation thresholds, and…
mcp-bytesmith
Local byte-wrangling toolbox: encoding (hex/Base64/Base32/Base58/Base45…), cryptographic + CRC hashing, base conversion, and CSPRNG…
M2M Sentinel
Base bytecode capability observations, proxy resolution, gas, DEX, and transfer telemetry.
agentdevx-sdk
Give your AI hands. Identity and credential vault gateway for autonomous agents. Ed25519 cryptographic identity (not OAuth), AES-256-GCM…
privacyscrubber-mcp
Zero-Trust PII & secrets sanitizer. Locally scrubs data in-memory before sending context to LLMs.
Keycloak Admin
Administer Keycloak via its Admin REST API: users, roles, clients, groups, IdP, events.
mcp-shield
Security scanner for MCP servers. Detects backdoors, exfiltration code, obfuscation, dangerous code execution, prompt injection, and…
misp-mcp-server
MISP (Malware Information Sharing Platform) MCP server with built-in prompt injection defense via…
IntoDNS.ai DNS & Email Security Scanner
DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.
trustboost-api
PII sanitization layer for autonomous AI agent pipelines. Detects and redacts emails, phone numbers, national IDs, private keys, and…
wrg-sigma-rules
Sigma detection rule writing, validation, and conversion (Splunk/Elastic/Kibana/Wazuh) via 3 MCP tools (`draft_rule`, `validate_rule`,…
ida-headless-mcp
Headless IDA Pro binary analysis via MCP. Multi-session concurrency with Go orchestration and Python workers. Supports Il2CppDumper and…
Unphurl
URL intelligence for AI agents and developers. 16 tools, 25 signal weights, 20 free checks.
aggrete
MCP policy proxy: enforces a code of conduct across connectors before the upstream is called.
mcp
Trust layer for AI agents: identity, guard, redact, escrow, and x402 payments.
shieldapi-mcp
Security intelligence for AI agents: password breach checks (900M+ HIBP hashes), email/domain/IP/URL reputation, prompt injection…
AIMarket MCP Gateway
Stdio + HTTP MCP gateway: SSRF-hardened web_fetch, web_search, metis_verify, market_search.
ARGUS-3 MCP Server
ARGUS-3 stdio MCP with WARDEN firewall: argus_ask, argus_status, argus_capabilities.
agent-trust-stack-mcp
Cryptographic provenance, bilateral blind reputation scoring, and tamper-evident logging for AI agent interactions. 7 interlocking trust…
hejdar-mcp
Runtime policy enforcement for AI agents. Evaluate actions against organization policies before execution, with observe and enforce modes.
truecopy
Supply-chain gate for agent skills and MCP servers — scans tool definitions for poisoned instructions, pins vetted servers by content hash…
AgentAegis
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
mcpskills-server
Trust scoring for MCP servers, AI skills & npm packages — 15 signals + safety scanning.