Security
Published entries filed under “Security” in MCP, newest first by publication date on this site.
236 entries
- Security
123Ergo/unphurl-mcp
URL security signals: redirects, brand impersonation, domain age, SSL validation, parked-domain detection, structural analysis and DNS enrichment.
- Security
13bm/GhidraMCP
Ghidra plugin for binary analysis: function inspection, decompilation, memory exploration and import/export analysis.
- Security
26zl/cybersec-toolkit
Install a large security toolset and discover and run it through an authorization-gated server for CTF, pentesting, bug bounty and DFIR.
- Security
82ch/MCP-Dandan
Real-time security framework for MCP servers that detects and blocks malicious agent behavior by analyzing tool call patterns and intent.
- Security
9hannahnine-jpg/arc-gate-mcp
Runtime governance for MCP tool calls that blocks prompt injection and capability abuse before tool results reach the agent.
- Security
Acacian/aegis
Policy-based governance for agent tool calls across LangChain, OpenAI, Anthropic and MCP: YAML policies, approval gates, risk assessment and audit logging.
- Security
adeptus-innovatio/solvitor-mcp
Reverse engineering tools from Solvitor: extract IDL files from closed-source Solana smart contracts and decompile them.
- Security
aeoess/agent-passport-mcp
Agent identity, scoped delegation and governance: issue passports, verify narrowing-only delegation chains, enforce gateway policy and emit signed records.
- Security
AgentAvow/AgentAvow
Signed, recomputable safety scores for MCP servers, packages and tools, with offline-verifiable attestations and a GitHub Action to gate CI merges.
- Security
AgentValet/AgentValet
Identity and credential broker for MCP servers: issues scoped, short-lived credentials per agent, with audit logging and human approval gates.
- Security
agentward-ai/agentward
MCP proxy that enforces least-privilege YAML policies on tool calls, classifies PII/PHI, detects dangerous skill chains and generates compliance audit trails.
- Security
aggrete/aggrete
Policy proxy that refuses forbidden tool calls, stopping prompt-injection exfiltration and forbidden data combinations across Slack, Drive, GitHub and more.
- Security
agntor/mcp
Agent discovery and certification with a trust and payment rail: identity verification, escrow, settlement and reputation management.
- Security
AIM-Intelligence/AIM-Guard-MCP
Security-focused safety guidelines and content analysis for AI agents.
- Security
AIops-tools/Compliance-AIops
Turn other AIops tools' audit trails into tamper-evident, hash-chained evidence bundles mapped to HIPAA, PCI-DSS, SOC 2 and GDPR.
- Security
airblackbox/air-blackbox-mcp
EU AI Act compliance scanner for Python AI agents (LangChain, CrewAI, AutoGen, OpenAI) with prompt injection detection, risk classification and fix generation.
- Security
ajipurn/fida
Local-first MCP gateway for coding agents that redacts detected secrets from file reads and command output before they reach model context.
- Security
alberthild/shieldapi-mcp
Security intelligence: HIBP password breach checks, email/domain/IP/URL reputation, prompt injection detection and skill supply chain scanning.
- Security
alexar76/aimarket-mcp
SSRF-hardened web gateway with web fetch, web search and Metis verification, sharing an audited security core with Metis and ARGUS.
- Security
alexar76/aimarket-oracle-gateway
Verifiable oracle tools via AIMarket Hub: Platon VRF randomness, Chronos VDF computation and verification, and LUMEN reputation scores.
- Security
alexar76/argus
Query ARGUS-3 and check its status; WARDEN vets third-party MCP servers with a scored firewall, tool-definition pinning and drift detection.
- Security
alexfleetcommander/agent-trust-stack-mcp
Cryptographic provenance, blind reputation scoring and tamper-evident logging for agent interactions, with dispute resolution and trust-based matchmaking.
- Security
AperionAI/shield
Local guardrail proxy for MCP servers: blocks destructive tool calls, pins tool catalogs against rug pulls and scans for tool poisoning and prompt injection.
- Security
arian-gogani/nobulex
Proof-of-behavior enforcement for AI agents: define permit/forbid/require rules, enforce them at runtime and keep hash-chained, tamper-evident audit logs.
- Security
ark-forge/arkforge-mcp
Third-party certifying proxy that signs any HTTP call with an independent Ed25519 signature, RFC 3161 timestamp and Sigstore Rekor anchor.
- Security
ARKALDA/hejdar-mcp
Runtime policy enforcement for AI agents: evaluate actions against organization policies before execution, in observe or enforce mode.
- Security
arthurpanhku/DocSentinel
Automate cybersecurity assessment of documents, questionnaires and reports to surface risks, compliance gaps and remediations, using a RAG knowledge base.
- Security
askalf/truecopy
Supply-chain gate for agent skills and MCP servers: detects poisoned tool definitions, pins servers by hash, checks drift in CI and proxies only pinned tools.
- Security
astafford8488/agentaegis-mcp
Scan MCP servers and skills before install, vet endpoints before calling them, and run vulnerability scans, threat intel and compliance checks.
- Security
atomicchonk/roadrecon_mcp_server
Analyze ROADrecon gather results from Azure tenant enumeration.
- Security
aurelio-nakamura/cmdxray
Offline safety gate for agent shell commands: rates each command as danger, caution or none and explains every flag, pipe, redirect and subshell.
- Security
aurumflux20/seal
Exactly-once payments for agents: prevents double settlement across processes and retries, confirms charges with the provider and reconciles out-of-band spend.
- Security
BeBraveBeKind/mcpskills-server
Scores MCP servers, AI skills and npm packages before install, scanning for prompt injection, credential theft and supply-chain risk, with a go/no-go gate.
- Security
beeswaxpat/chronoverify-mcp
Verify a photo's capture time and provenance: C2PA Content Credentials validation, EXIF/XMP consistency checks and pixel forensics combined into one verdict.
- Security
behrensd/mcp-firewall
Deterministic security proxy for MCP that intercepts tool calls, enforces YAML policies, scans for secret leakage and logs everything.
- Security
Bichev/agentradar-mcp
On-chain trust oracle for ERC-8004 and x402 agents: composite trust scoring, a scam wallet database, ERC-8004 identity lookup and EAS attestations on Base.
- Security
bluetieroperations-create/blackwall-mcp
Risk gate that agents call before irreversible actions, returning a risk score, reversibility class, red flags and a proceed/confirm/human-required decision.
- Security
boy-offi9-inc/hexforge-gateway
APK reverse engineering workspace that orchestrates jadx, apktool, adb and Frida through a workflow engine, on Termux (Android) or PC.
- Security
Buggy1111/anonymize-mcp
Anonymize PII for GDPR in Czech and many other languages using ÚFAL/LINDAT NLP (MasKIT, NameTag), plus morphology, translation and spellcheck.
- Security
BurtTheCoder/mcp-dnstwist
Run dnstwist, a DNS fuzzing tool, to detect typosquatting, phishing and corporate espionage.
- Security
BurtTheCoder/mcp-maigret
Search usernames across social networks and analyze URLs with maigret, an OSINT tool that collects account information from public sources.
- Security
BurtTheCoder/mcp-shodan
Query the Shodan API and Shodan CVEDB: IP lookups, device searches, DNS lookups, vulnerability queries and CPE lookups.
- Security
BurtTheCoder/mcp-virustotal
Query the VirusTotal API: scan URLs, analyze file hashes and retrieve IP address reports.
- Security
bx33661/Wireshark-MCP
Wireshark packet analysis: capture, protocol statistics, field extraction and security analysis.
- Security
calllint/calllint
Offline pre-flight security linter for MCP servers, agent tools and skills that returns SAFE, REVIEW, BLOCK or UNKNOWN verdicts without executing them.
- Security
chasdaddy/basescope
Read-only safety checks for Base and EVM: honeypot and rug-pull detection, risky approvals, verified source, balances, ENS and Basenames, gas and prices.
- Security
Chimera-Protocol/csl-core
Deterministic AI safety policy engine with Z3 formal verification: write, verify and enforce machine-verifiable constraints for AI agents.
- Security
chrbailey/promptspeak-mcp-server
Pre-execution governance for agent tool calls: risk classification, behavioral drift detection, a hold queue for dangerous operations and an audit trail.
- Security
Chronolapse411/sicarius-guard
Solana token safety oracle: byte-level SPL mint analysis, honeypot detection, freeze/mint authority checks, Birdeye market data and composite risk scoring.
- Security
co-browser/attestable-mcp-server
Demonstrates remote attestation of an MCP server running in a Gramine TEE via RA-TLS, so clients can verify the server before connecting.
- Security
corewebvitals/state-of-cwv-mcp
Core Web Vitals metrics by CMS, CDN and framework, based on Chrome field data and a multi-site crawl.
- Security
coreyhines/opnsense-mcp
OPNsense firewall operations via API: query ARP, DHCP, firewall rules, logs, interfaces, system status and packet captures.
- Security
creatorrmode-lead/avp-sdk
Trust, W3C DID identity and EigenTrust reputation for AI agents, with attestations, disputes, sybil detection and IPFS audit anchoring.
- Security
CTRLRun/ctrlrun
Execution safety for agent actions: a YAML-policy gateway that allows, holds or denies tool calls, plus an approval queue and hash-chained receipts.
- Security
Cubiczan/governed-mcp-gateway
HTTP MCP gateway that attaches a principal to tool calls and SSE streams, with allowlists and vault rotation.
- Security
Cubiczan/trust-ledger-os
Trust and risk control plane for AI teams, with phases, routes and a package catalog.
- Security
cuttalo/depscope
Package intelligence across many ecosystems: health, vulnerabilities (OSV, CISA KEV, EPSS), typosquats, malicious packages, alternatives and breaking changes.
- Security
cyntrisec/cyntrisec-cli
Local-first AWS security analyzer that discovers attack paths and generates remediations using graph theory.
- Security
dambuchs/redact-pdf-mcp
Permanently redact PII (names, emails, phone numbers, addresses, IBANs, card numbers) from PDFs, scans and screenshots, with multilingual OCR.
- Security
datanexusmcp/mcp-server
Public data lookups: CVE/SBOM security audits, license compliance, patents, federal contracts, NPI providers, nonprofit 990 filings and domain intelligence.
- Security
Declade/lucairn-sdks
Privacy gateway that sanitizes German and English PII before prompts reach an LLM and issues a signed, timestamped certificate for each call.
- Security
dengyier/OpenWorkProof
Verifiable execution protocol for agent tool calls: signed policy decisions, causal evidence chains and offline verification from a SQLite ledger.
- Security
dnsdoctor/claude-plugin
Scan and fix a domain's email authentication (SPF, DMARC, DKIM, MX), blacklist status and domain/SSL expiry, with deterministic, validated fix records.
- Security
doublegate/CyberChef-MCP
GCHQ CyberChef's encryption, encoding, compression and forensics operations, plus analysis tools such as hash identification, cipher solving and RSA attacks.
- Security
Drumworks/ssid-mcp
MAC address (OUI) vendor lookup with randomized-address detection, plus router default login IPs and admin credentials cited to manufacturer documentation.
- Security
dtkmn/mcp-zap-server
Self-hosted OWASP ZAP integration with guided security scans, findings summaries and report generation.
- Security
duriantaco/skylos
Dead code detection, security scanning and code quality analysis for Python, TypeScript and Go, with AI-assisted remediation.
- Security
elang2/mcp-audit-gateway
Transparent MCP proxy that keeps a signed, hash-chained audit trail of agent tool calls, with YAML policy enforcement and OpenTelemetry export.
- Security
elberacasa/umbra
Trust scores and guardrails for AI-generated code: static security rules, Docker-verified build/boot checks and receipts that catch agents lying about tests.
- Security
eliottreich/taskbounty-check
Local, read-only scanner for GitHub Actions and CI maintenance issues in AI-built apps, with finding explanations and fix plans.
- Security
emiliaprotocol/emilia-protocol
Requires a named human's approval before irreversible agent actions such as payments or deploys, then issues an offline-verifiable Ed25519 trust receipt.
- Security
epistemedeus/skillguard
Static scanner that checks Claude Code skills, plugins and MCP servers for exfiltration, install hooks and prompt injection before you install them.
- Security
Erodenn/fetch-guard
URL fetcher and HTML-to-Markdown converter with layered prompt injection defense: hidden-element sanitization, risk scanning and content boundary wrapping.
- Security
felixpg13-glitch/spendshield
Payment guardrails for AI agents: spend caps, budget and approval gates, prompt-injection defense, an encrypted secret vault and an audit trail.
- Security
firstorderai/authenticator_mcp
Securely interact with the Authenticator App.
- Security
forest6511/secretctl
Secrets manager that injects credentials into commands as environment variables so agents never see plaintext secrets, and sanitizes command output.
- Security
forgemeshlabs/x402-notary-mcp
Notarize AI model outputs with signed Ed25519 attestations, SHA-256 content hashes and Merkle anchoring on Base or Solana, paid via x402.
- Security
fosdickio/binary_ninja_mcp
Binary Ninja plugin and bridge for automating binary analysis and reverse engineering.
- Security
FoundryNet/mint-mcp
MINT Protocol work attestation for agents: cryptographically attest, verify, rate and discover agent work to build portable on-chain reputation.
- Security
fr0gger/MCP_Security
Query the ORKL API to fetch threat reports, analyze threat actors and retrieve intelligence sources.
- Security
fredyee/hallucc-mcp
Claim-level hallucination detection with sources, agent trajectory verification, risk gating for computer-use actions and prompt-injection defense.
- Security
Fronesis-Labs/dcl-webhook
Deterministic audit layer that checks LLM and agent outputs against jailbreak, safety and trading compliance policies and logs verdicts to a hash chain.
- Security
Gaffx/volatility-mcp
Memory forensics with Volatility 3, exposing plugins such as pslist and netscan through REST APIs.
- Security
gaoharimran29-glitch/Cybersecurity-MCP-Server
Local security reconnaissance: WHOIS, DNS and subdomain enumeration, Nmap scanning, TLS inspection, tech fingerprinting, CVE and IP reputation lookups.
- Security
gautam-u/sieve-mcp
Local macOS scanner for secrets leaked into AI tool chat transcripts, with redacted findings, placeholder-only redaction and Keychain-backed command execution.
- Security
gbrigandi/mcp-server-cortex
Cortex integration for observable analysis and automated security responses.
- Security
gbrigandi/mcp-server-thehive
TheHive integration for collaborative security incident response and case management.
- Security
gbrigandi/mcp-server-wazuh
Access real-time security alerts and event data from Wazuh SIEM.
- Security
gebalamariusz/cloud-audit
AWS security scanner with attack chain detection, breach cost estimation and remediation snippets for CLI and Terraform.
- Security
getaegis/aegis
Credential isolation proxy that injects secrets at the network boundary, with domain restrictions, agent authentication and audit logging.
- Security
goklab/guardvibe
Security scanner for vibe-coded apps (Next.js, Supabase, Stripe, Prisma and more): taint analysis, auto-fix, SARIF export, pre-commit hook and CVE detection.
- Security
goldmembrane/cleaner-code
Locally scans AI-generated code for invisible Unicode, Trojan Source, homoglyphs, rules file backdoors and typosquatting using static analysis and CodeBERT.
- Security
gostanos/smallprint-action
Query the Small Print record: versioned, diffed tool descriptions and schemas of MCP servers, skills and plugins, with graded changes and public advisories.
- Security
Gowthaman90/mcp-bastion
Security proxy for MCP servers: tool-definition pinning, tool-poisoning and exfiltration detection, injection blocking, secret redaction and audit trails.
- Security
gridinsoft/mcp-inspector
Domain and URL security analysis with GridinSoft Inspector to verify website and link safety.
- Security
GUCCI-atlasv/skillssafe-mcp
Scan SKILL.md files, MCP configs and system prompts for credential theft, prompt injection, zero-width character attacks and ClawHavoc indicators.
- Security
HaroldFinchIFT/vuln-nist-mcp-server
Query the NIST National Vulnerability Database (NVD) API.
- Security
haruodev/tamperlens-mcp
Document forensics via the Tamperlens API: detect post-creation edits, failed redactions and embedded prompt injection in PDFs, Office files and images.
- Security
hernaninverso/eleion-scanner-mcp
Register and verify domains, queue security scans (headers, TLS, DNS, ports, CVEs and AI-specific checks) and read findings.
- Security
hieutran/entraid-mcp-server
Microsoft Entra ID (Azure AD) directory, user, group, device, sign-in and security operations via Microsoft Graph.
- Security
honeylabshq/honeylabs-mcp
Honeypot threat intelligence from a sensor network: IP reputation, scanner classification, CVE probing trends and JA4, JA4H and HASSH fingerprints.
- Security
I4cTime/quantum_ring
Quantum-inspired keyring for AI coding agents, securing secrets with superposition, entanglement, tunneling and teleportation.
- Security
iamredmh/volta-mcp-server
Burn-after-read encrypted Volta Notes for agents: hand off credentials between users and agents without secrets appearing in chat history.
- Security
icoretech/warden-mcp
Manage Bitwarden and Vaultwarden vaults via the bw CLI: search, create, edit and organize logins, notes, cards, identities, SSH keys, folders and Sends.
- Security
infai-tech/vulnfeed-mcp
Scans dependency lockfiles for vulnerabilities, prioritizes them by EPSS exploit probability and recommends fix versions, with monitoring and alerting.
- Security
inkog-io/inkog-mcp
Audits agents and MCP servers for prompt injection, infinite loops, token bombing and missing human oversight, with EU AI Act and OWASP mapping.
- Security
intruder-io/intruder-mcp
Access Intruder to identify, understand and fix security vulnerabilities in your infrastructure.
- Security
itsalissonsilva/ModelSafetyMCP
Scan ML model artifacts, URLs and directories for unsafe serialization, malicious patterns and risky packaging using ModelScan, PickleScan and heuristics.
- Security
jaimenbell/rails-mcp
Self-hosted default-deny action registry, append-only spend-intent ledger and human sign-off audit trail for gating irreversible agent actions.
- Security
jamesdfinance-dev/lazaretto-mcp
Check lockfiles against malicious-package advisories and scan artifacts for credential theft, exfiltration, obfuscation, prompt injection and droppers.
- Security
jamjet-labs/jamjet-policy
MCP interceptor that applies one YAML policy (block, require approval, audit, budget cap) to tool calls, also usable in Claude Code hooks and agent SDKs.
- Security
Jiangw2718i/frisk
Screen x402 payment counterparties before paying: address sanity, payTo swap, transport safety and spend policy checks with an allow, review or block verdict.
- Security
jimmyracheta/AI-Runtime-Guard
Runtime policy enforcement for AI agents that prevents accidental system damage and unauthorized access, with automatic backups before file writes.
- Security
jnMetaCode/shellward
Agent security middleware with layered defenses: prompt injection detection, DLP data flow tracking, command blocking and PII detection.
- Security
joergmichno/clawguard-mcp
Security scanner for AI agents that detects prompt injections using regex patterns.
- Security
JoeyBrar/agentseal-mcp
Action logs for AI agents: records every action in a SHA-256 hash chain as an audit trail.
- Security
jonnybottles/patch-tuesday-mcp
Microsoft Patch Tuesday triage from the MSRC Security Update Guide: monthly rollups, CVE/KB lookups, supersedence chains and EPSS/CISA KEV urgency ranking.
- Security
jstibal/openterms-mcp
Ed25519-signed consent receipts and a policy engine for agents: spending caps, action allowlists, escalation thresholds and JWKS-backed provider verification.
- Security
jtang613/GhidrAssistMCP
Native Ghidra integration with GUI configuration, logging and no external dependencies.
- Security
juanisidoro/securecode-mcp
Encrypted secrets vault for Claude Code that injects secrets into local files so the AI never sees raw values, with audit logs and per-model access rules.
- Security
jyjune/mcp_vms
Retrieve live and recorded video from a CCTV recording program (VMS) and control it, such as opening live or playback dialogs for specific channels and times.
- Security
kakunin-ai/kakunin-mcp
Agent compliance and identity: verify an agent's X.509 certificate scope, read its behavioral risk score and append to an immutable audit trail.
- Security
kastelldev/kastell
Server security auditing and hardening (SSH, firewall, Docker, TLS) with CIS/PCI-DSS/HIPAA mapping, fleet management and forensic evidence collection.
- Security
kent-tokyo/shohei
Infrastructure diagnostics: DNS checks, TLS certificate chain inspection, email security, global DNS propagation and DNS latency benchmarking.
- Security
Kjopstad-IT/rqwstr
HTTP security testing toolkit (send, intruder, race, chain, out-of-band) with low-level HTTP/1.1 and HTTP/2 control: raw framing and connection pinning.
- Security
KOVY/agentforge-trust-mcp
Query AgentForge Trust Scores for MCP servers before connecting, covering security, code health, behavioral audit, community trust and EU compliance.
- Security
Kzino/vorim-mcp-server
Agent identity, trust and audit trails: Ed25519 agent registration, permission checks, tamper-evident audit events, trust scores and credential delegation.
- Security
LaurieWired/GhidraMCP
Autonomous reverse engineering with Ghidra: decompile binaries, rename methods and data, and list methods, classes, imports and exports.
- Security
layervai/qurl-mcp
Mint, resolve, audit and rotate expiring, scope-limited access links (qURLs) via the qURL API.
- Security
loglux/authmcp-gateway
Auth proxy for MCP servers: OAuth2 with DCR, JWT, RBAC, rate limiting, multi-server aggregation and a monitoring dashboard.
- Security
luiacuaniello/perspectivegraph
Attack-path engine for cloud and Kubernetes: list routes from internet exposure to sensitive assets, explain each hop, find choke points and simulate fixes.
- Security
M2M-Sentinel/m2m-sentinel-sdk
EVM bytecode capability analysis, EIP-1967 proxy resolution, gas recommendations and preflight safety checks for agents on Base.
- Security
mariocandela/beelzebub
Honeypot framework for building decoy MCP tools that an agent would never use in normal work, to detect prompt injection and malicious agent behavior.
- Security
MARUCIE/authbox
Zero-knowledge password manager and MCP credential gateway: policy-gated agent access, deterministic passwords, BIP-39 recovery and a hash-chain audit trail.
- Security
mastyf-ai/mastyf.ai
Runtime security proxy for MCP that blocks prompt injection, SSRF, shell/SQL injection and credential exfiltration, plus trust scores for npm MCP packages.
- Security
maxfain/basedagents
Agent identity registry (reputation, capability search, task marketplace, messaging) plus a local encrypted vault that leases provider keys to agents.
- Security
mcp-hangar/mcp-hangar
Self-hosted policy enforcement for MCP server fleets: deterministic admission and egress policies, attributable audit logs and SIEM export.
- Security
mcpindex-ai/mcp-server-mcpindex
Find MCP servers by describing a task and get advisory trust screens before connecting, using the mcpindex directory.
- Security
meloliva14/verity-mcp
Fail-closed trust gate for agents: fact-checking, prompt-injection detection, content moderation, PII and secret detection, and a pre-action guardrail.
- Security
mirajmahmudul/agentdevx-sdk
Identity and credential gateway for agents: Ed25519 identity, encrypted credential vault, OPA policies with audit logging, per-agent memory and web scraping.
- Security
mobb-dev/mobb-vibe-shield-mcp
Mobb Vibe Shield identifies and remediates vulnerabilities in human and AI-written code.
- Security
MoltyCel/moltrust-mcp-server
Trust infrastructure for AI agents: register DIDs, verify identities, query reputation scores, rate agents and manage W3C Verifiable Credentials.
- Security
mopanc/depguard
Pre-install npm package checks: static analysis, supply-chain attack detection, vulnerability audits, AI hallucination guard and CycloneDX SBOM generation.
- Security
moxno/privacyscrubber-mcp
Local, zero-trust masking of PII and secrets.
- Security
mrexodia/ida-pro-mcp
IDA Pro plugin for binary analysis: decompilation, disassembly and automatic malware analysis reports.
- Security
mrz1880/mcp-keycloak-admin
Administer Keycloak via its Admin REST API: users, roles, clients, groups, identity providers, federation and events, with a read-only mode.
- Security
msaad00/agent-bom
AI supply chain security scanner: discovers MCP clients, scans dependencies for CVEs, maps blast radius to credentials and tools, and generates SBOMs.
- Security
muhannad-hash/mcp-shield
Pre-install security scanner for MCP servers: detects backdoors, exfiltration code, obfuscation, dangerous execution, prompt injection and supply chain risks.
- Security
nagameTW/mcp-server-malcolm
Malcolm threat hunting: search and aggregate network traffic, query Suricata alerts, browse Arkime sessions and resolve NetBox assets.
- Security
nh4ttruong/secobserve-mcp
SecObserve vulnerability and license management: triage observations, manage products and rules, import scan reports and SBOMs, run scans and generate VEX.
- Security
nickgeorgeseo/mcp-gatehouse
Permission tiers, approval gates and secret-redacting audit logging enforced inside MCP servers at the tool boundary, with a demo order-desk server.
- Security
nickpending/mcp-recon
Conversational recon with httpx and asnmap: domain analysis, security header inspection, certificate analysis and ASN lookups at multiple recon levels.
- Security
node-man/dechonet-mcp
Domain security checks: DNS, DNSSEC, TLS grading, HTTP security headers, SPF, DKIM and DMARC, port scans, ASN, RDAP and WHOIS, plus an overall health score.
- Security
OksigeniaSL/checker-mcp
Local-first domain security and privacy checker: live SPF, DMARC, DKIM, DNSSEC, TLS, CAA and security header checks, scored with remediation advice.
- Security
oleg-vdv/kepil
Accountability layer for AI agents: per-version passports, per-job mandates with spending limits, a fail-closed action gate and a hash-chained journal.
- Security
operantlabs/operant-mcp
Security testing tools for penetration testing, network forensics, memory analysis and vulnerability assessment.
- Security
OrygnsCode/opa-mcp-server
OPA and Rego policy toolkit wrapping the OPA CLI and Regal: format, lint, evaluate, test and benchmark policies, manage the OPA REST API and explain decisions.
- Security
P4ST4S/mcp-audit
Transparent proxy that intercepts, signs, rate-limits, redacts and audits MCP tool calls without modifying client or server.
- Security
panther-labs/mcp-panther
Use Panther's SIEM platform in natural language to write detections, query logs and manage alerts.
- Security
Pentagonal-ai/pentagonal
Generate, audit, fix and compile smart contracts on Ethereum, Solana, Base and other chains, with adversarial multi-agent pen testing and honeypot detection.
- Security
Perufitlife/web-exposure-mcp
Read-only check of a live URL for publicly exposed secret files: .git, .env, JS source maps, backup/SQL dumps, directory listings and dotfiles.
- Security
piiiico/proof-of-commitment
Supply chain risk scoring for npm, PyPI, Cargo and Go packages from behavioral signals: publisher depth, release consistency and maintenance patterns.
- Security
ppcvote/misp-mcp-server
Read-only MISP threat intelligence (events, attributes, search, tags, feeds, galaxies) with prompt injection scanning of every response.
- Security
project-feldspar-resources/feldspar-scan
Deterministic security scan of public git repositories: vulnerable dependencies via OSV, hard-coded secrets and risky config lint, as file:line findings.
- Security
pullkitsan/mobsf-mcp-server
Static and dynamic analysis of Android and iOS apps with MobSF.
- Security
qianniuspace/mcp-security-audit
Audit npm package dependencies for security vulnerabilities with real-time checks against the npm registry.
- Security
qinisolabs/qiniso
Verify IBAN, VAT, VIN, barcodes, national and tax IDs, crypto addresses, phone numbers, dates and holidays against checksums and curated data.
- Security
quantakrypto/pqc-tools
Post-quantum readiness: scan code for quantum-vulnerable cryptography (RSA, ECDH, ECDSA, DH), get ML-KEM/ML-DSA/SLH-DSA migration guidance and verify fixes.
- Security
rad-security/mcp-server
Query the RAD Security API for Kubernetes and cloud security findings, reports and runtime data.
- Security
radareorg/r2mcp
Disassemble and inspect binaries for reverse engineering with the Radare2 disassembler.
- Security
rafapra3008/cervellaswarm
Verify agent communication protocols with session types and Lean 4 proofs to catch deadlocks and role violations; includes a linter, formatter and LSP.
- Security
rev2ret/SecureAudit-MCP
Static C/C++ memory-safety scanning and PE/ELF binary protection audits (ASLR, DEP/NX, SafeSEH, PIE), with remediation via secure templates.
- Security
roadwy/cve-search_mcp
Query the CVE-Search API: browse vendors and products, get CVEs by ID and list the latest updated CVEs.
- Security
rob925/mcp-shield
Static security scanner for MCP servers and agent tools: detects secrets, shell execution, risky tool descriptions, environment access and prompt injection.
- Security
RoscoNL/intodns-mcp-server
DNS and email security scans via IntoDNS.ai: SPF, DKIM, DMARC, DNSSEC, MTA-STS, BIMI, TLS, blacklist and deliverability checks plus security header analysis.
- Security
rudimentall1/agentic-wallet-guardian-v3
Self-hosted security layer that evaluates AI agents' proposed blockchain transactions and returns an explainable allow, warn or block decision.
- Security
rudraneel93/mcp-guardian
Security and governance proxy for MCP with YAML policies (blocklists, rate limits, token budgets), token cost tracking, health monitoring and RBAC.
- Security
Rul1an/assay
Fail-closed policy-as-code proxy for MCP that denies risky tool calls, produces offline-verifiable evidence bundles and enforces egress via eBPF and Landlock.
- Security
sachio222/54ch10-mcp
JSON risk briefs for wallet addresses, tokens and URLs: scores, flags and sources from phishing, scam and URL-reputation heuristics, including OpenPhish.
- Security
safedep/vet
Locally check npm and PyPI packages, such as those suggested by AI coding tools, for vulnerabilities and malicious code.
- Security
samvas-codes/dawshund_mcp
Enumerate AWS IAM data, analyze effective permissions and visualize access relationships across users, roles and resources, based on dAWShund.
- Security
sanyambassi/ciphertrust-manager-mcp-server
Thales CipherTrust Manager integration for key management, cryptographic operations and compliance monitoring.
- Security
sanyambassi/thales-cdsp-cakm-mcp-server
Thales CDSP CAKM integration for key management, cryptographic operations and compliance monitoring for Microsoft SQL Server and Oracle databases.
- Security
sanyambassi/thales-cdsp-crdp-mcp-server
Integration with the Thales CipherTrust Manager RESTful Data Protection service.
- Security
SaravananJaichandar/etch-mcp
Signed audit chain for AI agent decisions: events are signed, Merkle-chained per project, anchored to public transparency logs and verifiable offline.
- Security
scalekit-inc/scalekit-mcp-server
Manage Scalekit organizations, users and SSO.
- Security
scamverifyai/scamverify-mcp
Scam and threat checks for phone numbers, URLs, texts, emails, documents and QR codes using FTC/FCC complaints, URLhaus and ThreatFox, with risk scores.
- Security
ScopeBlind/verify-mcp
Offline verification of Ed25519/JCS-signed artifacts such as receipts, manifests and audit bundles.
- Security
securityfortech/secops-mcp
Security testing toolbox that combines open source tools behind a single interface for pentesting, bug bounty hunting and threat hunting.
- Security
sekera-radim/impri
Self-hostable human-in-the-loop approval inbox: humans approve, reject or edit proposed agent actions via web, mobile, Slack, Discord or Telegram.
- Security
semgrep/semgrep
Scan code for security vulnerabilities using Semgrep.
- Security
sgateway/s-gw
Local credential gateway for coding agents: agents get handles instead of raw secrets, and one-time approvals inject credentials only into approved commands.
- Security
shieldly-io/mcp
Analyze AWS IAM policies and CloudFormation templates with Shieldly to flag privilege-escalation paths, wildcards and over-permissive access.
- Security
shyshlakov/pci-dss-mcp
PCI DSS static analysis for Go payment code: finds PAN/CVV exposure, weak crypto, missing audit logs and vulnerable deps, each mapped to a PCI requirement.
- Security
sidclawhq/platform
Governance proxy that wraps MCP servers with policy evaluation, human approval workflows and hash-chain audit trails.
- Security
sint-ai/sint-protocol
MCP governance proxy with capability tokens, tiered approvals, fail-closed execution and tamper-evident audit receipts, plus preflight tool-risk scanning.
- Security
Skyrxin/sast-mcp-server
SAST/DAST scanners (Bandit, Semgrep, Trivy, CodeQL, OWASP ZAP and more) with closed-loop remediation, SARIF/SBOM/VEX export and compliance reporting.
- Security
slouchd/cyberchef-api-mcp-server
Use CyberChef operations through the CyberChef server API.
- Security
snyk/studio-mcp
Embeds Snyk's security engines into agentic workflows to secure AI-generated code in real time and work through vulnerability backlogs faster.
- Security
sp3ak/safenode-mcp-gateway
Fail-closed policy proxy for MCP tool calls that denies, warns on or holds each call for human approval before forwarding, with client-side redaction.
- Security
srinivasan-sundaresan95/orihime
Cross-repository code knowledge graph for Java, Kotlin, JavaScript and TypeScript: call-flow tracing, taint analysis, reachability and license compliance.
- Security
StacklokLabs/osv-mcp
Query the OSV (Open Source Vulnerabilities) database by package version or commit, batch-query multiple packages and get vulnerability details by ID.
- Security
suhui-organization/pod
Least-privilege compiler for agents: record real tool calls, compile a minimal policy, enforce it at an MCP gateway and keep a hash-chained audit.
- Security
swnotmetal/Project-Koma
Classify input for prompt injection and out-of-scope content with Koma Gate's LLM-based classifier.
- Security
Synvoya/codeinspectus
Local security scanner for AI-generated JS/TS that combines Opengrep, Gitleaks and Trivy with checks for exposed secrets, Supabase RLS and prompt injection.
- Security
takleb3rry/zitadel-mcp
Zitadel identity management: manage users, projects, OIDC apps, roles and service accounts in natural language.
- Security
taniwhaai/arai
Enforces rules from existing agent instruction files (CLAUDE.md, .cursorrules) by blocking prohibited tool calls and logging per-rule compliance verdicts.
- Security
teodorofodocrispin-cmyk/trustboost-pii-sanitizer
Redacts emails, phone numbers, national IDs, private keys and financial data before text reaches LLMs, in English, Spanish, Portuguese, German and Japanese.
- Security
Thezenmonster/agentscore-mcp-server
Security trust layer that monitors MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift and publisher posture.
- Security
thyn-ai/algenta-sdk
Algenta decision engine: dataset discovery, exact queries, utility models, decision memory and governed agent runs with approvals and execution receipts.
- Security
timescale/rsigma
Author, lint, validate and convert Sigma detection rules with RSigma, evaluate and explain detections against log events, and inspect correlation state.
- Security
toan203/osv-ui
Visual CVE audit dashboard for npm, Python, Go and Rust using OSV data, with browser-based human review and fixes applied only after confirmation.
- Security
tomjwxf/scopeblind-gateway
Security gateway that wraps MCP servers with per-tool policies, approval gates and optional signed receipts, in shadow (log-only) or enforce mode.
- Security
Top-Celestial-Company-Ltd/DROS-VajraClaw-Hacker
Deterministic execution governance gateway and W3C DID security guardrail for AI agent MCP tool calls.
- Security
trustscoreagent/trustscoreagent
Check the reputation of AI microservices and public APIs before calling them and submit ratings afterward, via an open trust registry.
- Security
uchit/mcp-regulated-ai-compliance
Regulated-industry AI compliance knowledge: control lookup, use-case classification and crosswalks for EU AI Act, NIST AI RMF, ISO 42001, APRA, GDPR and more.
- Security
ucsandman/DashClaw
Fail-closed approval layer for unattended agent runs: checks actions against org policy, requests human approval and logs every decision to a causal ledger.
- Security
UnboundCompute/lachesis
Code property graph for C, Python and TypeScript: callers/callees, data and taint flow with source-to-sink witnesses, points-to and guard/sink structure.
- Security
UPinar/contrastapi
Security intelligence: CVE/EPSS/KEV lookups, domain recon (DNS, WHOIS, SSL, subdomains), IOC threat intel, OSINT and code scanning for secrets and injection.
- Security
urldna/mcp
URL scanning and phishing triage: capture DOM snapshots, network requests and screenshots, and hunt historical scans with a custom query language.
- Security
vaulted-fyi/vaulted-mcp-server
Share end-to-end encrypted, self-destructing secrets from an agent, reading them from env vars or files so they stay out of LLM context.
- Security
velvetway/minreestr-mcp
Search the Russian software registry for import-substitution and FSTEC/FSB-certified products, with full-text search and manufacturer listings.
- Security
vespo92/OPNSenseMCP
Manage and interact with the OPNsense open source firewall in natural language.
- Security
vikasny30/aletheia-mcp
Deterministic pre-execution filter for agent tool calls that blocks scope creep (credential reads, SSRF, destructive shell/SQL) and prompt injection.
- Security
vinaybhosle/agentstamp
Trust intelligence for AI agents: identity stamps, reputation scoring, a registry, forensic audit trails and A2A passports via x402 micropayments.
- Security
wei9072/aegis
Admission control for agent file edits: checks syntax, structural-cost regressions and workspace boundaries, returning BLOCK, WARN or PASS verdicts.
- Security
williamblakecunningham-max/screenverity-mcp
U.S. exclusion, debarment and license screening (OIG LEIE, SAM.gov, state boards) with an Ed25519-signed receipt of the exact list snapshots checked.
- Security
WRG-11/wrg-sigma-rules
Write, validate and convert Sigma detection rules for Splunk, Elastic, Kibana and Wazuh, backed by a rule corpus covering MITRE ATT&CK tactics.
- Security
yessGlory17/job-verify
Check recruiters and job offers for scams: cross-checks company registration, domain age, look-alike domains, blocklists and crypto-scam databases.
- Security
zboralski/ida-headless-mcp
Headless IDA Pro binary analysis with concurrent sessions and Il2CppDumper and Blutter metadata import for Unity and Flutter reverse engineering.
- Security
zekebuilds-lab/captcha-mcp
Middleware that gates MCP tool calls behind a Hashcash proof-of-work challenge or an L402 Lightning payment via self-hosted LNbits.
- Security
zinja-coder/apktool-mcp-server
Automate reverse engineering of Android APKs with Apktool.
- Security
zinja-coder/jadx-ai-mcp
JADX decompiler plugin providing live, LLM-assisted reverse engineering.
- Security
zkproofport/proofport-ai
Generate zero-knowledge proofs of identity claims (Coinbase KYC, country, Google OIDC, Microsoft 365) without revealing personal information.
- Security
zw008/VMware-Harden
Read-only VMware vSphere compliance scanning and drift detection against CIS, vSphere SCG, China DJCP 2.0 and PCI-DSS, with remediation suggestions.
- Security
zyx77550/sparda
Injects a live, reversible MCP server into a running Express, FastAPI or Next.js app, with safe reads by default and writes gated behind human confirmation.