Security MCP servers
851 security servers from the official MCP Registry. The 100 most starred are below, 25 per page; open a server for install commands. Search all 40,104 servers →
| # | Server | Category | GitHub stars | Runs as |
|---|---|---|---|---|
| 1 |
OpenWork MCP Gateway Your OpenWork org's skills, plugins, workflows, and connections through one OAuth MCP URL.
|
Security | 23.9K | remote |
| 2 |
Attestix AI agent identity, W3C credentials, EU AI Act compliance. 47 MCP tools.
|
Security | 874 | pypi |
| 3 |
skylos Dead code, security, secrets detection and code quality for Python, TypeScript, Go.
|
Security | 843 | pypi |
| 4 |
HOL Guard Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.
|
Security | 807 | pypi |
| 5 |
SonarQube MCP Server Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants.
|
Security | 658 | oci |
| 6 |
mcp-ssh-manager SSH server management for agents, with per-server read-only and allowlist security modes
|
Security | 499 | npm |
| 7 |
MCPProxy Local-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savings
|
Security | 387 | |
| 8 |
wireshark-mcp Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
|
Security | 287 | pypi |
| 9 |
squirrelscan Website QA for your coding agent: audit SEO, performance, security, accessibility over MCP.
|
Security | 272 | remote |
| 10 |
mcp-niubiz MCP server for Niubiz — Peru card acquirer: security token, session, authorize, reverse
|
Security | 272 | npm |
| 11 |
CrowdStrike Falcon MCP Server Connects AI agents with CrowdStrike Falcon for security analysis and automation.
|
Security | 265 | pypi |
| 12 |
Reversecore MCP Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
|
Security | 207 | pypi oci |
| 13 |
OpenClaw MCP Server MCP server bridging Claude.ai/Desktop with self-hosted OpenClaw via OAuth 2.1.
|
Security | 185 | npm oci |
| 14 |
Taskade MCP Hosted OAuth MCP at https://www.taskade.com/mcp, or local @taskade/mcp-server.
|
Security | 164 | remote npm |
| 15 |
virustotal MCP server for querying VirusTotal API with comprehensive security analysis tools.
|
Security | 150 | npm |
| 16 |
mcp-observatory MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
|
Security | 140 | npm |
| 17 |
shellward AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
|
Security | 140 | npm |
| 18 |
agent-security-scanner-mcp Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
|
Security | 122 | npm |
| 19 |
dvalincode Deterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.
|
Security | 120 | npm |
| 20 |
lockbox Encrypted secrets for Next.js. AES-256-GCM with no vault needed.
|
Security | 107 | npm |
| 21 |
notebooklm-mcp-secure Security-hardened NotebookLM MCP with post-quantum encryption
|
Security | 85 | npm |
| 22 |
ssh MCP server for SSH remote server management with SSH agent authentication support.
|
Security | 81 | npm |
| 23 |
dependency-management-mcp-server Sonatype component intelligence: versions, security analysis, and Trust Score recommendations
|
Security | 74 | remote |
| 24 |
agentos Build and manage policy-compliant AI agents with safety enforcement and compliance checking
|
Security | 74 | npm |
| 25 |
cybersec-toolkit Authorization-gated MCP server to discover and run 670+ security tools for CTF, pentest, and DFIR.
|
Security | 68 | oci |
| 26 |
MCP ZAP Server Safe, self-hosted ZAP operator for guided AI security scans and reports.
|
Security | 67 | oci |
| 27 |
depwire Dependency graph + 24 MCP tools. Impact analysis, simulation, security, agent coordination
|
Security | 64 | npm |
| 28 |
SAS Viya Execute SAS code and query Compute, CAS, and model APIs on SAS Viya via OAuth 2.0.
|
Security | 63 | oci |
| 29 |
kastell Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.
|
Security | 60 | npm |
| 30 |
mcp Easily find and fix security issues in your applications leveraging Snyk platform capabilities.
|
Security | 55 | npm |
| 31 |
MCP Server for OSCAL AI agent tools for Open Security Controls Assessment Language (OSCAL)
|
Security | 53 | pypi |
| 32 |
Action1 MCP Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations.
|
Security | 52 | mcpb |
| 33 |
Proofpoint MCP Proofpoint TAP threats, VAPs, clickers, and IOCs from your terminal, with a local threat store.
|
Security | 52 | mcpb |
| 34 |
ThreatLocker MCP Every ThreatLocker Portal API feature, plus the write operations the read-only tools lack and a
|
Security | 52 | mcpb |
| 35 |
CodeInspectus Local-first MCP security scanner and CLI for AI-generated applications.
|
Security | 47 | npm |
| 36 |
mythos-agent Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
|
Security | 44 | npm |
| 37 |
appstore-connect-mcp MCP server for Apple Store Connect API integration with OAuth authentication support
|
Security | 41 | npm |
| 38 |
grantex OAuth 2.0 for AI agents — scoped delegation tokens, audit trails, and revocation.
|
Security | 34 | npm |
| 39 |
MCP Evernote Evernote note management with OAuth and ENML conversion
|
Security | 33 | npm |
| 40 |
Expense Budget Tracker Track expenses, budgets, balances, transfers, and multi-currency reports with OAuth-secured tools.
|
Security | 32 | remote |
| 41 |
codacy Analyze code quality, security issues, and coverage across repositories
|
Security | 32 | pypi oci |
| 42 |
iso27001-mcp ISO 27001 compliance workspace for Claude. Risks, policies, SoA, evidence, and audit workflows.
|
Security | 32 | npm |
| 43 |
janee Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.
|
Security | 30 | npm |
| 44 |
Repository Intelligence Analyze repos of any size - security scanning code analysis monorepo support
|
Security | 28 | |
| 45 |
Prism Scanner Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
|
Security | 27 | pypi |
| 46 |
mcp-cinema4d MCP server for Cinema 4D — entity CRUD, parameter-level access, batched undo, security controls.
|
Security | 25 | npm |
| 47 |
operant-mcp Security testing MCP server for penetration testing, forensics, and vulnerability assessment
|
Security | 25 | npm |
| 48 |
hush A secret store for AI agents: the agent never sees the plaintext.
|
Security | 20 | remote |
| 49 |
mastyf.ai Runtime proxy for MCP security, cost governance & audit
|
Security | 20 | npm |
| 50 |
Clipboard History MCP Your clipboard, but Claude can read it. Type-classified, secret-encrypted. macOS + Linux.
|
Security | 19 | mcpb |
| 51 |
Nekzus-npm-sentinel-mcp Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
|
Security | 18 | remote |
| 52 |
npm-sentinel-mcp Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.
|
Security | 18 | npm |
| 53 |
Phantom Secrets Value-blind secret metadata and gated workflows for AI coding agents through Phantom's local proxy.
|
Security | 16 | npm |
| 54 |
NeuroDock (hosted) Hosted NeuroDock — stateless communication and planning tools over OAuth-secured Streamable HTTP.
|
Security | 16 | remote |
| 55 |
prodcheck 4,372 pre-production checks: security, performance, scale, integrations, post-launch.
|
Security | 15 | npm |
| 56 |
prodlint Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.
|
Security | 15 | npm |
| 57 |
aegis Credential isolation for AI agents. Inject secrets at the network boundary.
|
Security | 14 | npm |
| 58 |
WHOOP — MissingMCP WHOOP recovery, strain, sleep and workouts in Claude via official WHOOP OAuth. Free, open source.
|
Security | 13 | remote |
| 59 |
MobiLoop Guarded AI mobile Appium testing, security scanning, verification, and fix-retest MCP tools.
|
Security | 12 | oci |
| 60 |
cortex-gateway Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.
|
Security | 12 | remote oci |
| 61 |
IdentArk Gateway Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
|
Security | 12 | remote |
| 62 |
TAP Credential isolation for AI agents: placeholder secrets, policy checks, optional human approval.
|
Security | 12 | remote |
| 63 |
ProductClank Boost posts and launch community growth campaigns from your AI assistant. OAuth, credit-billed.
|
Security | 11 | remote |
| 64 |
Klarion Secret scanning for AI agents: rules and entropy find candidates, a model decides which are real.
|
Security | 11 | mcpb |
| 65 |
pkgxray Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.
|
Security | 11 | npm |
| 66 |
vulnicheck HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.
|
Security | 11 | oci |
| 67 |
mcp-eu-ai-act EU AI Act + GDPR compliance scanner. One call, no arguments, 10 seconds. 22 AI frameworks detected.
|
Security | 11 | remote |
| 68 |
Niro AI pentester for PRs — finds exploitable bugs and hands your developer agent the fix.
|
Security | 10 | mcpb |
| 69 |
Trent Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
|
Security | 9 | remote |
| 70 |
royal-mcp Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.
|
Security | 9 | remote |
| 71 |
stackhawk An MCP server that provides interaction with StackHawk's security scanning platform.
|
Security | 9 | pypi |
| 72 |
skgate OAuth MCP gateway. SI proxy with model aliases. Grok subscription as OpenAI-compatible API, no key.
|
Security | 9 | oci |
| 73 |
mcp-threatintel Unified threat intel - OTX, AbuseIPDB, GreyNoise, abuse.ch, Feodo Tracker
|
Security | 8 | npm |
| 74 |
MCP Safety Warden MCP proxy adding security scanning, behavioral profiling, risk gating, and safe tool call execution.
|
Security | 8 | pypi |
| 75 |
Snyk API & Web MCP Server MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage
|
Security | 8 | pypi |
| 76 |
wass-mcp MCP server for web application security scanning
|
Security | 8 | |
| 77 |
SPARDA AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
|
Security | 8 | npm |
| 78 |
SPARDA AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
|
Security | 8 | npm |
| 79 |
Draugr Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
|
Security | 7 | mcpb |
| 80 |
Judges Panel 45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
|
Security | 7 | npm |
| 81 |
PreClick — An MCP-native URL preflight scanning service for autonomous agents. PreClick scans links for threats and confirms intent match with high accuracy before agents click.
|
Security | 6 | remote |
| 82 |
SkillTotal Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
|
Security | 6 | pypi |
| 83 |
PreClick — An MCP-native URL preflight scanning service for autonomous agents (formerly URLCheck). PreClick scans links for threats and confirms intent match with high accuracy before agents click.
|
Security | 6 | remote |
| 84 |
mcp-bastion Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.
|
Security | 6 | npm |
| 85 |
FedRAMP 20x Requirements An MCP server that provides access to FedRAMP 20x security requirements and controls.
|
Security | 6 | pypi |
| 86 |
pincer Secure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture
|
Security | 6 | npm |
| 87 |
skill-audit-mcp MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
|
Security | 6 | remote oci |
| 88 |
supply-chain-guard Supply-chain malware scanner and MCP server: vet packages in 15 ecosystems before install, offline.
|
Security | 6 | npm |
| 89 |
Husk Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs
|
Security | 6 | npm cargo |
| 90 |
Cybersecurity Vulnerability Intel CVE lookup via NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK. 7 tools.
|
Security | 6 | remote |
| 91 |
Regulatory Monitor Federal Register monitoring and regulations.gov tracking. 4 MCP tools for regulatory compliance.
|
Security | 6 | remote |
| 92 |
MCP-Bastion Security middleware for MCP. Blocks prompt injection, PII leakage, and resource exhaustion.
|
Security | 6 | pypi |
| 93 |
Aident Loadout Connect any AI agent to 1,000+ apps and 27,000+ actions through one remote MCP server (OAuth).
|
Security | 5 | remote |
| 94 |
nucleus Sovereign Agent OS — Persistent Memory, Governance & Compliance for AI Agents.
|
Security | 5 | remote pypi |
| 95 |
guardvibe Deterministic security layer your AI can't be. 553 rules, 39 tools, CLI + doctor + host audit.
|
Security | 5 | npm |
| 96 |
leakferret Context-aware secret scanner: lets an AI agent scan, verify, and rewrite secrets before committing.
|
Security | 5 | npm |
| 97 |
zerosmtp A free SMTP relay that still takes a username and password, for devices that cannot do OAuth 2.0.
|
Security | 5 | npm |
| 98 |
onelogin-mcp MCP server for OneLogin API - manage users, apps, roles, and authentication
|
Security | 5 | npm |
| 99 |
siteaudit-mcp SEO, performance, and security audits for any URL — no API keys required
|
Security | 5 | pypi |
| 100 |
kdbx Read-only access to secrets in a local KeePassXC vault. Runs commands with them injected.
|
Security | 5 | oci |
Other categories
Databases 921Browser and web scraping 1,206Finance and crypto 3,789Commerce and payments 1,990Git, GitHub and code review 454Cloud and DevOps 1,053Productivity and workspace 1,197Messaging and social 1,774Files and documents 1,416Design, images and media 1,621Search and knowledge 3,695Data and analytics 2,971Memory and agent tools 3,357Developer tools 1,860AI models and prompts 665Other 11,284
Newest in the registry
Most recently published in security.
skgateOct 7, 2026 · Security
OAuth MCP gateway. SI proxy with model aliases. Grok subscription as OpenAI-compatible API, no key.
SkillTotalOct 7, 2026 · Security
Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
mcp-hubOct 7, 2026 · Security
Many stdio MCP servers from one container, published over HTTPS with OAuth 2.1 for any MCP client
Electron MCP ServerOct 7, 2026 · Security
Electron.js MCP server — IPC scaffolding, security auditing, build tooling for AI assistants
MCP ComplianceOct 7, 2026 · Security
CLI tool and MCP server that tests MCP servers for spec compliance
DeepsleuthOct 7, 2026 · Security
Deterministic, no-LLM security scanner for MCP servers, plus an inline proxy gate.
LovedOne Family MCPOct 7, 2026 · Security
Family inbox: read records; invite, reply, mint codes. API key or OAuth care_circle:write.
FEDLIN ScannersOct 7, 2026 · Security
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
vulnrableOct 7, 2026 · Security
Security grades for MCP servers and npm/PyPI packages, ranked by CISA KEV and EPSS.
AI agents that can use MCP servers
From each product's documentation; see the feature matrix.