Skip to content

MCP servers for
Security

215 servers in the catalog, aggregated from the official MCP registry, the reference server repo, and the community. Showing 120.

01The servers

  • 123Ergo/unphurl-mcp

    123ergo/unphurl-mcp

    URL intelligence for AI agents. 13 tools for security signals and data quality: redirect behaviour, brand impersonation detection, domain age, SSL validation, parked detection, URL structural analysis, DNS enrichment.

  • 13bm/GhidraMCP

    13bm/ghidramcp

    MCP server for integrating Ghidra with AI assistants. This plugin enables binary analysis, providing tools for function inspection, decompilation, memory exploration, and import/export analysis via the Model Context Protocol.

  • 82ch/MCP-Dandan

    82ch/mcp-dandan

    Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across multiple threat detection engines.

  • 9hannahnine-jpg/arc-gate-mcp

    9hannahnine-jpg/arc-gate-mcp

    Runtime governance for MCP tool calls. Blocks prompt injection and capability abuse before tool results reach your agent.

  • Acacian/aegis

    acacian/aegis

    Policy-based governance for AI agent tool calls. YAML policies, approval gates, risk assessment, and audit logging. Cross-platform: LangChain, OpenAI, Anthropic, MCP.

  • adeptus-innovatio/solvitor-mcp

    adeptus-innovatio/solvitor-mcp
  • aeoess/agent-passport-mcp

    aeoess/agent-passport-mcp

    Agent identity, scoped delegation, and governance: issue passports, build and verify narrowing-only delegation chains, enforce policy at a gateway, and emit signed admission and outcome records. 150 tools. `npx -y agent-passport-system-mcp`

    npx -y agent-passport-system-mcpHomepage ↗
  • agentgraph-co/agentgraph

    agentgraph-co/agentgraph

    Trust verification and security scanning for AI agents. Checks security posture of third-party MCP servers and tools with signed attestations (Ed25519/JWS) before interaction.

  • AgentValet/AgentValet

    agentvalet/agentvalet

    Identity and credential governance broker for MCP servers. Issues scoped, short-lived credentials per agent to stop credential inheritance. Audit log, human approval gates, AIMS-aligned.

  • agentward-ai/agentward

    agentward-ai/agentward

    Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

  • agntor/mcp

    agntor/mcp

    MCP audit server for agent discovery and certification. Provides trust and payment rail for AI agents including identity verification, escrow, settlement, and reputation management.

  • AIM-Intelligence/AIM-Guard-MCP

    aim-intelligence/aim-mcp

    Security-focused MCP server that provides safety guidelines and content analysis for AI agents.

  • airblackbox/air-blackbox-mcp

    airblackbox/air-blackbox-mcp

    EU AI Act compliance scanner for Python AI agents. Scans, analyzes, and remediates LangChain/CrewAI/AutoGen/OpenAI code across 6 articles with 10 tools including prompt injection detection, risk classification, and trust layer integration. The only MCP compliance server that generates fix code, not just findings.

  • ajipurn/fida

    ajipurn/fida

    Local-first MCP gateway for coding agents that redacts detected secrets from file reads and command output before they reach model context.

  • alberthild/shieldapi-mcp

    alberthild/shieldapi-mcp

    Security intelligence for AI agents: password breach checks (900M+ HIBP hashes), email/domain/IP/URL reputation, prompt injection detection (200+ patterns), and skill supply chain scanning. Pay-per-request via x402 USDC micropayments or free demo mode, no API key needed.

  • alexar76/aimarket-mcp

    alexar76/aimarket-mcp

    **SSRF-hardened web gateway MCP** — `web_fetch`, `web_search`, `metis_verify`; one audited security core for Metis, ARGUS, and the ecosystem. stdio + optional HTTP · Python · [Glama](https://glama.ai/mcp/servers/alexar76/aimarket-mcp) · Registry `io.github.alexar76/aimarket-mcp`.

  • alexar76/aimarket-oracle-gateway

    alexar76/aimarket-oracle-gateway

    **Verifiable oracle MCP server**: Platon VRF (`get_random`), Chronos VDF (`compute_vdf` / `verify_vdf`), LUMEN reputation (`get_reputation_scores`) as agent tools. Pay-per-call over AIMarket Hub; every result independently verifiable. stdio · Python · [Glama](https://glama.ai/mcp/servers/alexar76/aimarket-oracle-gateway).

  • alexar76/argus

    alexar76/argus

    **ARGUS-3 as a stdio MCP server** (`argus mcp` → `argus_ask`, `argus_status`). **WARDEN** vets third-party MCP servers before any tool runs (LUMEN-scored firewall, tool-def pinning, drift sentinel). Distinct from `aimarket-oracle-gateway` (oracle tools) and `aimarket-plugins` (hub packager). npm `@alexar76/argus3` · [live](https://magic-ai-factory.com/argus/).

  • alexfleetcommander/agent-trust-stack-mcp

    alexfleetcommander/agent-trust-stack-mcp

    Cryptographic provenance, bilateral blind reputation scoring, and tamper-evident logging for AI agent interactions. 7 interlocking trust protocols (CoC, ARP, ASA, AJP, ALP, AMP, CWEP) available in Python (pip) and TypeScript (npm). 663 tests. Bitcoin-anchored provenance chains, anti-Goodhart reputation scoring, machine-readable contracts, dispute resolution, lifecycle management, trust-weighted matchmaking, and context-window cost allocation. Also on [Smithery](https://smithery.ai/server/@alexfleetcommander/agent-trust-stack-mcp) and [PyPI](https://pypi.org/project/agent-trust-stack-mcp/).

  • AperionAI/shield

    aperionai/shield

    Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or Streamable HTTP) and blocks destructive tool calls — DROP TABLE, rm -rf, force-push — before they execute. MCP supply-chain protection: TOFU tool-catalog pinning against rug pulls, plus tool-description and tool-result scanning for tool poisoning and prompt injection. 51 starter rules, approval gates, audit logging. Single binary, Apache-2.0.

  • arian-gogani/nobulex

    arian-gogani/nobulex

    Proof-of-behavior enforcement for AI agents. Define behavioral covenant rules (permit/forbid/require), enforce at runtime before execution, get SHA-256 hash-chained tamper-evident audit logs, and verify compliance independently. Cross-agent verification handshake — no proof, no transaction. MIT licensed, 4,244 tests.

  • ark-forge/arkforge-mcp

    ark-forge/arkforge-mcp

    Third-party certifying proxy — sign any HTTP call (AI agents, webhooks, microservices) with an independent Ed25519 signature, RFC 3161 timestamp, and Sigstore Rekor anchor. Works with Claude, GPT-4, Mistral, LangChain, AutoGen, or any HTTP client.

  • ARKALDA/hejdar-mcp

    arkalda/hejdar-mcp

    Runtime policy enforcement for AI agents. Evaluate actions against organization policies before execution, with observe and enforce modes.

  • arthurpanhku/DocSentinel

    arthurpanhku/docsentinel

    MCP server for AI agent for cybersecurity: automate assessment of documents, questionnaires & reports. Multi-format parsing, RAG knowledge base,Risks, compliance gaps, remediations.

  • askalf/truecopy

    askalf/truecopy

    Supply-chain gate for agent skills and MCP servers — scans tool definitions for poisoned instructions, pins vetted servers by content hash in a committed lock, and verifies drift in CI; the bundled truecopy-mcp proxy exposes only pinned, unmodified tools from a live server.

  • astafford8488/agentaegis-mcp

    astafford8488/agentaegis-mcp

    Security & trust layer for AI agents. Scan an MCP server or skill *before* you install it (`scan_mcp_plugin`, `scan_skill`) — flags exfiltration, prompt-injection sinks, dangerous capabilities, install hooks and obfuscation → PROCEED/CAUTION/BLOCK. Plus `vet_endpoint` (endpoint safety verdict before an agent calls or pays it) and 25 more tools: vuln scans, threat intel, compliance (SOC 2/ISO 27001/HIPAA), code security (SAST/secret/dependency), identity — 28 total. Per-call billing via API key or x402 USDC on Base; free discovery tier.

  • atomicchonk/roadrecon_mcp_server

    atomicchonk/roadrecon_mcp_server
  • aurumflux20/seal

    aurumflux20/seal

    Exactly-once execution for agents that move money: the same payment can't settle twice across processes or retries. World-confirmation asks the provider ("did this charge actually land?") and returns CONFIRMED_ONE / MULTIPLE / ABSENT / UNKNOWN; out-of-band reconcile catches spend that bypassed the gateway; earned-autonomy licensing (L0–L5) only raises an agent's unattended spend ceiling on proven-clean history. In the official MCP Registry as `io.github.aurumflux20/seal`. `pip install seal-kernel`

    pip install seal-kernelHomepage ↗
  • BeBraveBeKind/mcpskills-server

    bebravebekind/mcpskills-server

    Pre-install trust layer for MCP servers, AI skills, and npm packages. Scores any repo or package across 15 signals (incl. OSV/KEV/EPSS vulnerability intelligence) with safety scanning for prompt injection, credential theft, and supply-chain risk; the `auto_gate` tool returns a go/no-go install decision. Listed in the official MCP Registry as `io.mcpskills/server`. npm: `@mcpskillsio/server`. https://mcpskills.io

  • beeswaxpat/chronoverify-mcp

    beeswaxpat/chronoverify-mcp

    Verify a photo's capture time and provenance before an agent trusts it: cryptographic C2PA Content Credentials validation against the official trust lists, EXIF and XMP consistency checks, and classical pixel forensics fused into one typed verdict with a 0 to 100 confidence. Free keyless tier, opt-in shareable verdict permalinks, and key-gated signed PDF audit reports. Provenance validation, not a deepfake detector. `npx chronoverify-mcp`

  • behrensd/mcp-firewall

    behrensd/mcp-firewall

    Deterministic security proxy (iptables for MCP) that intercepts tool calls, enforces YAML policies, scans for secret leakage, and logs everything. No AI, no cloud.

  • Bichev/agentradar-mcp

    bichev/agentradar-mcp

    On-chain trust oracle for the ERC-8004 + x402 agent economy. 18 tools for verifying AI agents: 6-signal composite trust scoring (0-100), 272-wallet scam database, ERC-8004 identity lookup, EAS attestations on Base mainnet. x402-payable. Free `get_score` / `check_scam`. Live at [vvpro.ai](https://vvpro.ai) · npm [`@agentradar/mcp`](https://www.npmjs.com/package/@agentradar/mcp).

  • bluetieroperations-create/blackwall-mcp

    bluetieroperations-create/blackwall-mcp

    Pre-action risk gate for AI agents. One `forecast` tool the agent calls before any irreversible action (send money, run SQL, delete data); returns a risk score (0–100), reversibility class, named red flags from 28 failure modes, and a gate: proceed / confirm / human-required.

  • Buggy1111/anonymize-mcp

    buggy1111/anonymize-mcp

    Anonymize PII and redact text for GDPR across Czech and 35+ languages. Real NLP via ÚFAL/LINDAT (MasKIT + NameTag NER, not just regex), 80+ PII patterns, plus morphology, translation, and spellcheck. Czech-first, non-commercial. Install: `pip install anonymize-mcp`.

    pip install anonymize-mcpHomepage ↗
  • BurtTheCoder/mcp-dnstwist

    burtthecoder/mcp-dnstwist

    MCP server for dnstwist, a powerful DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage.

  • BurtTheCoder/mcp-maigret

    burtthecoder/mcp-maigret

    MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

  • BurtTheCoder/mcp-shodan

    burtthecoder/mcp-shodan

    MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.

  • BurtTheCoder/mcp-virustotal

    burtthecoder/mcp-virustotal

    MCP server for querying the VirusTotal API. This server provides tools for scanning URLs, analyzing file hashes, and retrieving IP address reports.

  • bx33661/Wireshark-MCP

    bx33661/wireshark-mcp

    Wireshark network packet analysis MCP Server with capture, protocol stats, field extraction, and security analysis capabilities.

  • calllint/calllint

    calllint/calllint

    Pre-flight security linter for MCP servers, agent tools, and skills. Scans a config *before* it runs — offline, deterministic, evidence-backed — and returns SAFE / REVIEW / BLOCK / UNKNOWN verdicts without executing the server it judges. CLI (`npx calllint scan`), MCP server (`npx calllint-mcp`), SARIF + CI gate. UNKNOWN is never SAFE.

  • chasdaddy/basescope

    chasdaddy/basescope

    The read-only safety layer for onchain AI agents. 13 read-only tools on Base + EVM: token/contract safety (honeypot & rug-pull checks cross-referenced across GoPlus + honeypot.is), risky-approval detection, verified-source lookup, balances, ENS + Basenames, gas, and prices. No private keys, no required API keys. `npx -y basescope`

    npx -y basescopeHomepage ↗
  • Chimera-Protocol/csl-core

    chimera-protocol/csl-core

    Deterministic AI safety policy engine with Z3 formal verification. Write, verify, and enforce machine-verifiable constraints for AI agents via MCP.

  • chrbailey/promptspeak-mcp-server

    chrbailey/promptspeak-mcp-server

    Pre-execution governance for AI agents. Intercepts and validates every agent tool call through an 8-stage pipeline before execution — risk classification, behavioral drift detection, hold queue for dangerous operations, and complete audit trail. 45 tools, 658 tests.

  • Chronolapse411/sicarius-guard

    chronolapse411/sicarius-guard

    Solana token safety oracle for AI agents and trading bots. Byte-level SPL mint analysis, honeypot detection, freeze/mint authority checks, Birdeye market enrichment, and composite risk scoring. Deployed on Google Cloud Run.

  • co-browser/attestable-mcp-server

    co-browser/attestable-mcp-server

    An MCP server running inside a trusted execution environment (TEE) via Gramine, showcasing remote attestation using [RA-TLS](https://gramine.readthedocs.io/en/stable/attestation.html). This allows an MCP client to verify the server before conencting.

  • corewebvitals/state-of-cwv-mcp

    corewebvitals/state-of-cwv-mcp

    Free remote MCP for Core Web Vitals metrics by CMS, CDN, and framework (Chrome field data + multi-site crawl). No auth. Endpoint: `https://www.corewebvitals.io/api/state-of-cwv/mcp`.

  • coreyhines/opnsense-mcp

    coreyhines/opnsense-mcp

    OPNsense firewall operations via API. Query ARP, DHCP, firewall rules, logs, interfaces, system status, and packet capture via STDIO or SSE.

  • creatorrmode-lead/avp-sdk

    creatorrmode-lead/avp-sdk

    Trust, identity (W3C DID), and EigenTrust reputation for AI agents. Attestations, disputes, sybil detection, IPFS audit anchoring.

  • CSOAI-ORG/councilof-ai

    csoai-org/councilof-ai

    Live GSPC measurement board over MCP (`https://councilof.ai/mcp`, `npx -y csoai-gspc-mcp@0.1.1`). Seven read-only tools. Measurement, never certification. Verify: https://councilof.ai/gspc-verify

    npx -y csoai-gspc-mcpHomepage ↗
  • Cubiczan/governed-mcp-gateway

    cubiczan/governed-mcp-gateway

    HTTP MCP gateway: principal on tools/call + SSE, allowlists, vault rotate. `npx -y @cubiczan/governed-mcp-gateway`

    npx -y @cubiczan/governed-mcp-gatewayHomepage ↗
  • Cubiczan/trust-ledger-os

    cubiczan/trust-ledger-os

    Trust/risk control plane for AI teams: phases, routes, package catalog over MCP. `node packages/mcp/dist/server.js` after build.

  • cuttalo/depscope

    cuttalo/depscope

    Package Intelligence for AI agents. 22 tools across 17 ecosystems (npm/pypi/cargo/go/maven/nuget/rubygems/composer/pub/hex/swift/cocoapods/cpan/hackage/cran/conda/homebrew) — check health, vulnerabilities (OSV + CISA KEV + EPSS), typosquats, malicious flags, alternatives, known bugs, breaking changes, stack compatibility and error-to-fix. 31k+ packages, 2.2k+ CVEs enriched. Zero auth, MIT. Remote URL https://mcp.depscope.dev/mcp or stdio `npx depscope-mcp`.

  • cyntrisec/cyntrisec-cli

    cyntrisec/cyntrisec-cli

    Local-first AWS security analyzer that discovers attack paths and generates remediations using graph theory.

  • datanexusmcp/mcp-server

    datanexusmcp/mcp-server

    55 tools for verified public data lookups — CVE/SBOM security audits, licence compliance, patents, federal contracts, NPI provider lookups, nonprofit 990 filings, and domain intelligence. No API key required.

  • Declade/lucairn-sdks

    declade/lucairn-sdks

    Privacy-preserving AI gateway. Sanitises PII (German + English; Microsoft Presidio + custom recognisers) before prompts reach Anthropic / OpenAI / your LLM, then emits a signed cryptographic certificate per call (Ed25519 + RFC 3161 timestamp + Sigstore Rekor anchoring). EU GDPR + AI Act ready. Free tier 500 calls/month, BYOK. Install: `npx -y @lucairn/mcp-server`. Docs: https://lucairn.eu/developer/mcp.

    npx -y @lucairn/mcp-serverHomepage ↗
  • dengyier/OpenWorkProof

    dengyier/openworkproof

    Verifiable execution protocol for AI agent tool calls. Ed25519-signed PolicyDecisions, causal evidence chains (RFC 8785 JCS), and offline verification from SQLite ledger. 2,281 tests, 2 real-world bugs demonstrated end-to-end. `pip install openworkproof`

    pip install openworkproofHomepage ↗
  • dkvdm/onepassword-mcp-server

    dkvdm/onepassword-mcp-server

    An MCP server that enables secure credential retrieval from 1Password to be used by Agentic AI.

  • dnsdoctor/claude-plugin

    dnsdoctor/claude-plugin

    Scan and fix a domain's email authentication — SPF, DMARC, DKIM, MX, blacklists, domain/SSL expiry. Deterministic, validated fix records (never LLM-generated); hosted server at dnsdoctor.dev/mcp with anonymous access.

  • duriantaco/skylos

    duriantaco/skylos

    Dead code detection, security scanning, and code quality analysis for Python, TypeScript, and Go. 98% recall with fewer false positives than Vulture. Includes AI-powered remediation.

  • eliottreich/taskbounty-check

    eliottreich/taskbounty-check

    Local-only GitHub Actions and CI maintenance scanner for AI-built apps. Exposes `scan_repo`, `explain_finding`, and `generate_fix_plan` to MCP clients; reads only allowlisted workflow and update configuration, modifies nothing, makes no outbound requests by default, and has zero runtime dependencies. Run with `npx -y taskbounty-check@0.1.6 mcp`.

    npx -y taskbounty-checkHomepage ↗
  • emiliaprotocol/emilia-protocol

    emiliaprotocol/emilia-protocol

    Human sign-off + trust receipts for AI agents: requires a named human's approval before an irreversible action (payment release, record change, deploy), then mints an offline-verifiable Ed25519 Trust Receipt. Also exposes trust profiles, receipt verification, disputes, and delegation. Apache-2.0; policy engine formally verified. Install: `npx -y @emilia-protocol/mcp-server`.

    npx -y @emilia-protocol/mcp-serverHomepage ↗
  • Erodenn/fetch-guard

    erodenn/fetch-guard

    URL fetcher and HTML-to-markdown converter with three-layer prompt injection defense: pre-extraction sanitization of hidden/off-screen elements and non-printing Unicode, 15-pattern risk scanning (HIGH/MEDIUM/OK), and per-request session-salt content boundary wrapping.

  • felixpg13-glitch/spendshield

    felixpg13-glitch/spendshield

    Payment guardrails for AI agents: spend-capped digital identity (KYA), dry-run / budget / amount-limit / approval gates, prompt-injection defense (new recipients & large amounts require human sign-off), AES-encrypted secret vault with audited access, full audit trail. Python library + stdio MCP server. `pip install spendshield`

    pip install spendshieldHomepage ↗
  • firstorderai/authenticator_mcp

    firstorderai/authenticator_mcp
  • forest6511/secretctl

    forest6511/secretctl

    AI agents never see plaintext secrets. Features output sanitization, AES-256-GCM encryption, and Argon2id key derivation.

  • forgemeshlabs/x402-notary-mcp

    forgemeshlabs/x402-notary-mcp

    Cryptographic receipts for AI outputs: notarize any model inference with a signed Ed25519 attestation, sha256 content hash, and Merkle chain-anchor on Base or Solana. $0.001 per call via x402 USDC micropayments; verification is free and needs no wallet. Notarizes the hash, never your prompts. `npx -y @forgemeshlabs/x402-notary-mcp`

    npx -y @forgemeshlabs/x402-notary-mcpHomepage ↗
  • fosdickio/binary_ninja_mcp

    fosdickio/binary_ninja_mcp

    A Binary Ninja plugin, MCP server, and bridge that seamlessly integrates [Binary Ninja](https://binary.ninja) with your favorite MCP client. It enables you to automate the process of performing binary analysis and reverse engineering.

  • FoundryNet/mint-mcp

    foundrynet/mint-mcp

    MINT Protocol — universal work attestation for autonomous agents. Cryptographically attest, verify, rate, and discover agent work to build portable, on-chain trust and reputation across the agent economy. 6 tools.

  • fr0gger/MCP_Security

    fr0gger/mcp_security

    MCP server for querying the ORKL API. This server provides tools for fetching threat reports, analyzing threat actors, and retrieving intelligence sources.

  • Fronesis-Labs/dcl-webhook

    fronesis-labs/dcl-webhook

    Deterministic AI audit layer: evaluates LLM/agent outputs against configurable policies (jailbreak, safety, quality, wallet, trade, MEV compliance) and writes every verdict to a tamper-evident SHA-256 hash chain — metadata only, never raw content. 17 tools including a full crypto-trading compliance suite. Pay-per-call via x402 (USDC on Base), from $0.01. `mcp.fronesislabs.com/mcp`

  • Gaffx/volatility-mcp

    gaffx/volatility-mcp

    MCP server for Volatility 3.x, allowing you to perform memory forensics analysis with AI assistant. Experience memory forensics without barriers as plugins like pslist and netscan become accessible through clean REST APIs and LLMs.

  • gaoharimran29-glitch/Cybersecurity-MCP-Server

    gaoharimran29-glitch/cybersecurity-mcp-server

    Cybersecurity reconnaissance server for Claude. WHOIS lookup, DNS enumeration with subdomain brute-forcing, Nmap port scanning with service detection, SSL/TLS certificate inspection, technology stack fingerprinting, CVE lookup, and IP reputation checking. Runs fully locally via FastMCP.

  • gautam-u/sieve-mcp

    gautam-u/sieve-mcp

    Local AI chat history secret scanner for macOS. Finds API keys and secrets leaked into Claude Code, Cursor, Copilot Chat, Cline, Codex, Gemini CLI, and other AI tool transcripts. 9 MCP tools: findings list with redacted previews, boolean secret detection (`sieve_check_text`), placeholder-only redaction (`sieve_redact_text` returns `sieve://project/key`, never raw values), vault-backed command execution, and scan health. Local-only stdio transport, macOS Keychain vault, no plaintext secrets in any tool response. [Mac App Store](https://apps.apple.com/app/sieve-ai-secret-scanner/id6747506504).

  • gbrigandi/mcp-server-cortex

    gbrigandi/mcp-server-cortex

    A Rust-based MCP server to integrate Cortex, enabling observable analysis and automated security responses through AI.

  • gbrigandi/mcp-server-thehive

    gbrigandi/mcp-server-thehive

    A Rust-based MCP server to integrate TheHive, facilitating collaborative security incident response and case management via AI.

  • gbrigandi/mcp-server-wazuh

    gbrigandi/mcp-server-wazuh

    A Rust-based MCP server bridging Wazuh SIEM with AI assistants, providing real-time security alerts and event data for enhanced contextual understanding.

  • gebalamariusz/cloud-audit

    gebalamariusz/cloud-audit

    Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.

  • getaegis/aegis

    getaegis/aegis

    Credential isolation proxy for AI agents. Injects secrets at the network boundary with domain restrictions, agent authentication, and audit logging. No SDK required — works as a transparent HTTP proxy or MCP server.

  • girste/mcp-cybersec-watchdog

    girste/mcp-cybersec-watchdog

    Comprehensive Linux server security audit with 89 CIS Benchmark controls, NIST 800-53, and PCI-DSS compliance checks. Real-time monitoring with anomaly detection across 23 analyzers: firewall, SSH, fail2ban, Docker, CVE, rootkit, SSL/TLS, filesystem, network, and more.

  • goklab/guardvibe

    goklab/guardvibe

    Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

    https://glama.ai/mcp/servers/goklab/guardvibe/badgeHomepage ↗
  • goldmembrane/cleaner-code

    goldmembrane/cleaner-code

    AI code security scanner MCP server. Detects 9 categories of threats in AI-generated code (invisible Unicode, Trojan Source, homoglyphs, Glassworm steganography, rules file backdoors, dependency typosquatting, obfuscation) using static analysis plus CodeBERT deep learning. Runs locally, free tier.

  • gridinsoft/mcp-inspector

    gridinsoft/mcp-inspector

    MCP server for domain and URL security analysis powered by GridinSoft Inspector, enabling AI agents to verify website and link safety.

  • GUCCI-atlasv/skillssafe-mcp

    gucci-atlasv/skillssafe-mcp

    Free AI agent skill security scanner. Scan SKILL.md, MCP configs, and system prompts for credential theft, prompt injection, zero-width character attacks, and ClawHavoc indicators. Supports OpenClaw, Claude Code, Cursor, and Codex. No signup required.

  • HaroldFinchIFT/vuln-nist-mcp-server

    haroldfinchift/vuln-nist-mcp-server

    A Model Context Protocol (MCP) server for querying NIST National Vulnerability Database (NVD) API endpoints.

  • haruodev/tamperlens-mcp

    haruodev/tamperlens-mcp

    Document forensics before an agent reads the file: whether a PDF, Office file or image was edited after it was written, whether its redactions actually removed the text, and whether it carries text addressed to a language model rather than to a reader — the recovered injection payload is elided rather than echoed back into the context. Thin client over the Tamperlens REST API; signals with evidence, never a verdict; nothing stored. 10 documents/hour with no key. `npx -y tamperlens-mcp`

    npx -y tamperlens-mcpHomepage ↗
  • hernaninverso/eleion-scanner-mcp

    hernaninverso/eleion-scanner-mcp

    Register/verify your domains, queue security scans (headers, TLS, DNS, ports, CVEs + AI-specific checks) and read findings, for AI agents. Install with `npx -y eleion-scanner-mcp`.

    npx -y eleion-scanner-mcpHomepage ↗
  • hieutran/entraid-mcp-server

    hieuttmmo/entraid-mcp-server

    A MCP server for Microsoft Entra ID (Azure AD) directory, user, group, device, sign-in, and security operations via Microsoft Graph Python SDK.

  • honeylabshq/honeylabs-mcp

    honeylabshq/honeylabs-mcp

    Honeypot threat intelligence for AI agents: 90 days of probe data from a sensor network for IP reputation, scanner classification, CVE probing trends, and JA4/JA4H/HASSH fingerprints. Remote MCP, free tier.

  • I4cTime/quantum_ring

    i4ctime/quantum_ring

    Quantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation.

  • iamredmh/volta-mcp-server

    iamredmh/volta-mcp-server

    Burn-after-read encrypted notes for AI agents. Create and read self-destructing notes via Volta Notes with AES-256-GCM E2E encryption — the decryption key never leaves the URL fragment. Secure credential handoff between users and agents without secrets appearing in chat history.

  • icoretech/warden-mcp

    icoretech/warden-mcp

    MCP server for Bitwarden and Vaultwarden vault management. Search, create, edit, and organize logins, notes, cards, identities, SSH keys, folders, collections, attachments, and Sends via the official `bw` CLI.

  • imran-siddique/agentos-mcp-server

    imran-siddique/agent-os

    Agent OS MCP server for AI agent governance with policy enforcement, code safety verification, multi-model hallucination detection, and immutable audit trails.

  • infai-tech/vulnfeed-mcp

    infai-tech/vulnfeed-mcp

    Dependency vulnerability scanner with EPSS exploit probability scoring. Scans lockfiles (npm, pip, Go, Cargo, Ruby, Composer, Gradle, NuGet, Mix), prioritizes by real-world exploit likelihood, recommends fix versions. 9 MCP tools for scanning, monitoring, and alerting. Free tier + x402 micropayments. `pip install vulnfeed-mcp`

    pip install vulnfeed-mcpHomepage ↗
  • inkog-io/inkog-mcp

    inkog-io/inkog-mcp

    AI agent security scanner. Audits MCP servers for vulnerabilities, detects prompt injection, infinite loops, token bombing, and missing human oversight across 20+ frameworks. Maps findings to EU AI Act, OWASP LLM Top 10.

  • IntoDNS.ai DNS & Email Security Scanner

    rosconl/intodns-mcp-server

    Free DNS and email security scanner for AI assistants. DNS, SPF, DKIM, DMARC, DNSSEC, MTA-STS, BIMI, TLS/STARTTLS, FCrDNS, CAA, TLSA/DANE, blacklist and full-deliverability checks, plus security-header/CSP analysis and bookmarkable report snapshots, via the IntoDNS.ai API. No signup or API key. `npx intodns-mcp`

    npx -y intodns-mcpHomepage ↗
  • intruder-io/intruder-mcp

    intruder-io/intruder-mcp

    MCP server to access [Intruder](https://www.intruder.io/), helping you identify, understand, and fix security vulnerabilities in your infrastructure.

  • itsalissonsilva/ModelSafetyMCP

    itsalissonsilva/modelsafetymcp

    MCP server for scanning machine learning model artifacts for unsafe serialization, malicious model patterns, risky packaging, URL-based artifact scanning, and directory-level triage using ModelScan, PickleScan, and heuristic inspection.

  • jagmarques/asqav-mcp

    jagmarques/asqav-mcp

    AI agent governance MCP server with policy enforcement, quantum-safe audit trails (ML-DSA), multi-party authorization, and compliance reporting. Check policies, sign actions, and verify signatures through MCP tools.

  • jamesdfinance-dev/lazaretto-mcp

    jamesdfinance-dev/lazaretto-mcp

    Check whether anything you depend on is known malware, before an agent installs it. `check_lockfile` takes a package-lock.json, yarn.lock or pnpm-lock.yaml and matches every pinned version against published malicious-package advisories in one call, free and with no API key, catching compromised releases like chalk@5.6.1 while leaving their clean releases alone. `scan_artifact` adds deterministic behavioral analysis (no LLM in the serving path) for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, with the file, line and evidence that triggered it; verdicts are SHA-256-bound so you can re-verify what landed on disk. Paid scans settle at $0.03 USDC on Base (x402) or prepaid credits. `npx lazaretto-mcp`

  • jamjet-labs/jamjet-policy

    jamjet-labs/jamjet-policy

    MCP stdio interceptor (`@jamjet/mcp-shim`) that applies one YAML policy file (block / require_approval / audit / budget cap) to `tools/call` requests before they reach the real MCP server. The same policy also runs in Claude Code PreToolUse hooks (`@jamjet/claude-code-hook`), OpenAI Agents SDK guardrails (`@jamjet/openai-guardrail`), and JamJet's Python/TS SDKs — `jamjet audit show` tails every decision across every adapter from `~/.jamjet/audit/`.

  • jaspertvdm/mcp-server-inject-bender

    jaspertvdm/mcp-server-inject-bender

    Security through absurdity: transforms SQL injection and XSS attempts into harmless comedy responses using AI-powered humor defense.

  • jimmyracheta/AI-Runtime-Guard

    runtimeguard/runtime-guard

    prevents accidental damage to your systems, unauthorized agent access and automates backup-before-write for any touched files.

  • jnMetaCode/shellward

    jnmetacode/shellward

    AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.

  • joergmichno/clawguard-mcp

    joergmichno/clawguard-mcp

    Security scanner for AI agents that detects prompt injections using 42+ regex patterns

  • JoeyBrar/agentseal-mcp

    joeybrar/agentseal-mcp

    Action logs for AI agents. Records every agent action in a SHA-256 hash chain, making an audit trail. Install via `npx agentseal-mcp`.

  • jonnybottles/patch-tuesday-mcp

    jonnybottles/patch-tuesday-mcp

    Microsoft Patch Tuesday triage from the official MSRC Security Update Guide. Monthly rollups, CVE/KB lookups, supersedence chains, product watchlists, and urgency-ranked results enriched with EPSS scores and the CISA KEV catalog. No API keys; also available as a free hosted remote endpoint. `uvx patch-tuesday-mcp`

  • jstibal/openterms-mcp

    jstibal/openterms-mcp

    Ed25519-signed consent receipts and programmable policy engine for AI agents. Spending caps, action whitelists, escalation thresholds, and JWKS-backed provider verification. Independently verifiable.

  • jtang613/GhidrAssistMCP

    jtang613/ghidrassistmcp

    A native Model Context Protocol server for Ghidra. Includes GUI configuration and logging, 31 powerful tools and no external dependencies.

  • juanisidoro/securecode-mcp

    juanisidoro/securecode-mcp

    Secrets vault for Claude Code with audit logs, MCP access rules, and AES-256 encryption. Secrets are injected to local files so the AI never sees raw values. Includes session lock, device approval, and per-model access policies.

  • jyjune/mcp_vms

    jyjune/mcp_vms

    A Model Context Protocol (MCP) server designed to connect to a CCTV recording program (VMS) to retrieve recorded and live video streams. It also provides tools to control the VMS software, such as showing live or playback dialogs for specific channels at specified times.

  • kakunin-ai/kakunin-mcp

    kakunin-ai/kakunin-mcp

    Compliance and identity for AI agents — verify an agent's certificate scope, read its behavioral risk score, and append to an immutable audit trail. X.509 identity issued via AWS KMS; MiCA / EU AI Act aligned. `npx -y @kakunin/mcp`

    npx -y @kakunin/mcpHomepage ↗
  • kastelldev/kastell

    kastelldev/kastell

    Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.

  • kent-tokyo/shohei

    kent-tokyo/shohei

    Rust infrastructure diagnostics MCP server for AI agents: DNS checks, TLS certificate chain inspection, email security, global DNS propagation, and DNS latency benchmarking.

  • Kjopstad-IT/rqwstr

    kjopstad-it/rqwstr-mcp

    AI-native HTTP security testing toolkit: 17 tools (send, intruder, race, chain, oob) with low-level control over HTTP/1.1 + HTTP/2 (raw framing, connection pinning).

  • knowledgepa3/gia-mcp-server

    knowledgepa3/gia-mcp-server

    Enterprise AI governance layer with 29 tools: MAI decision classification (Mandatory/Advisory/Informational), hash-chained forensic audit trails, human-in-the-loop gates, compliance mapping (NIST AI RMF, EU AI Act, ISO 42001), governed memory packs, and site reliability tools.

  • KOVY/agentforge-trust-mcp

    kovy/agentforge-trust-mcp

    Query the AgentForge Trust Score (0-100 across five dimensions: security, code health, behavioral audit, community trust, EU compliance) for any MCP server before connecting. Exposes `check_trust`, `evaluate_policy`, `list_trusted`, and `recommend` tools. 3,600+ servers audited, free public API.

  • Kzino/vorim-mcp-server

    kzino/vorim-mcp-server

    AI agent identity, trust, and audit trail infrastructure. 17 MCP tools: register agents with Ed25519 keypairs, check permissions (sub-5ms), emit tamper-evident audit events, verify trust scores (0-100), delegate credentials, and manage ephemeral agents. IETF Internet-Draft filed (draft-vorim-vaip-00). Works with LangChain, OpenAI, CrewAI, Stripe ACP, and 4 more frameworks. `npx @vorim/mcp-server`.

  • LaurieWired/GhidraMCP

    lauriewired/ghidramcp

    A Model Context Protocol server for Ghidra that enables LLMs to autonomously reverse engineer applications. Provides tools for decompiling binaries, renaming methods and data, and listing methods, classes, imports, and exports.

  • layervai/qurl-mcp

    layervai/qurl-mcp

    Mint, resolve, audit, and rotate expiring scope-limited access links (qURLs) for AI agents — secure URL gateway for the qURL API. 9 tools (create / resolve / list / get / delete / extend / update / mint-link / batch-create), 3 resources, 3 guided prompts. stdio transport, OIDC-attested npm provenance.

  • loglux/authmcp-gateway

    loglux/authmcp-gateway

    Auth proxy for MCP servers: OAuth2 + DCR, JWT, RBAC, rate limiting, multi-server aggregation, and monitoring dashboard.

    https://glama.ai/mcp/servers/@loglux/auth-mcp-gatewayHomepage ↗

02Other categories

6,000+ servers · one catalog · any agent

Give an agent new tools.
Add any MCP server in minutes.