Skip to content
Agents tracked: 258 Downloads (7d): 219M up 6.1% GitHub stars: 5.5M VS Code installs: 148M Releases (7d): 327 Agent status: 1 with issues Updated Oct 7, 2026

Security MCP servers

851 security servers from the official MCP Registry. The 100 most starred are below, 25 per page; open a server for install commands. Search all 40,104 servers →

# Server Category GitHub stars Runs as
1
OpenWork MCP Gateway Your OpenWork org's skills, plugins, workflows, and connections through one OAuth MCP URL.
Security 23.9K remote
2
Attestix AI agent identity, W3C credentials, EU AI Act compliance. 47 MCP tools.
Security 874 pypi
3
skylos Dead code, security, secrets detection and code quality for Python, TypeScript, Go.
Security 843 pypi
4
HOL Guard Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.
Security 807 pypi
5
SonarQube MCP Server Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants.
Security 658 oci
6
mcp-ssh-manager SSH server management for agents, with per-server read-only and allowlist security modes
Security 499 npm
7
MCPProxy Local-first MCP proxy with BM25 tool discovery, security scanning, quarantine & ~99% token savings
Security 387
8
wireshark-mcp Professional network analysis with tshark. Security audits, deep-dives, and threat detection.
Security 287 pypi
9
squirrelscan Website QA for your coding agent: audit SEO, performance, security, accessibility over MCP.
Security 272 remote
10
mcp-niubiz MCP server for Niubiz — Peru card acquirer: security token, session, authorize, reverse
Security 272 npm
11
CrowdStrike Falcon MCP Server Connects AI agents with CrowdStrike Falcon for security analysis and automation.
Security 265 pypi
12
Reversecore MCP Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
Security 207 pypi oci
13
OpenClaw MCP Server MCP server bridging Claude.ai/Desktop with self-hosted OpenClaw via OAuth 2.1.
Security 185 npm oci
14
Taskade MCP Hosted OAuth MCP at https://www.taskade.com/mcp, or local @taskade/mcp-server.
Security 164 remote npm
15
virustotal MCP server for querying VirusTotal API with comprehensive security analysis tools.
Security 150 npm
16
mcp-observatory MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
Security 140 npm
17
shellward AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
Security 140 npm
18
agent-security-scanner-mcp Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Security 122 npm
19
dvalincode Deterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.
Security 120 npm
20
lockbox Encrypted secrets for Next.js. AES-256-GCM with no vault needed.
Security 107 npm
21
notebooklm-mcp-secure Security-hardened NotebookLM MCP with post-quantum encryption
Security 85 npm
22
ssh MCP server for SSH remote server management with SSH agent authentication support.
Security 81 npm
23
dependency-management-mcp-server Sonatype component intelligence: versions, security analysis, and Trust Score recommendations
Security 74 remote
24
agentos Build and manage policy-compliant AI agents with safety enforcement and compliance checking
Security 74 npm
25
cybersec-toolkit Authorization-gated MCP server to discover and run 670+ security tools for CTF, pentest, and DFIR.
Security 68 oci
26
MCP ZAP Server Safe, self-hosted ZAP operator for guided AI security scans and reports.
Security 67 oci
27
depwire Dependency graph + 24 MCP tools. Impact analysis, simulation, security, agent coordination
Security 64 npm
28
SAS Viya Execute SAS code and query Compute, CAS, and model APIs on SAS Viya via OAuth 2.0.
Security 63 oci
29
kastell Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.
Security 60 npm
30
mcp Easily find and fix security issues in your applications leveraging Snyk platform capabilities.
Security 55 npm
31
MCP Server for OSCAL AI agent tools for Open Security Controls Assessment Language (OSCAL)
Security 53 pypi
32
Action1 MCP Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations.
Security 52 mcpb
33
Proofpoint MCP Proofpoint TAP threats, VAPs, clickers, and IOCs from your terminal, with a local threat store.
Security 52 mcpb
34
ThreatLocker MCP Every ThreatLocker Portal API feature, plus the write operations the read-only tools lack and a
Security 52 mcpb
35
CodeInspectus Local-first MCP security scanner and CLI for AI-generated applications.
Security 47 npm
36
mythos-agent Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
Security 44 npm
37
appstore-connect-mcp MCP server for Apple Store Connect API integration with OAuth authentication support
Security 41 npm
38
grantex OAuth 2.0 for AI agents — scoped delegation tokens, audit trails, and revocation.
Security 34 npm
39
MCP Evernote Evernote note management with OAuth and ENML conversion
Security 33 npm
40
Expense Budget Tracker Track expenses, budgets, balances, transfers, and multi-currency reports with OAuth-secured tools.
Security 32 remote
41
codacy Analyze code quality, security issues, and coverage across repositories
Security 32 pypi oci
42
iso27001-mcp ISO 27001 compliance workspace for Claude. Risks, policies, SoA, evidence, and audit workflows.
Security 32 npm
43
janee Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.
Security 30 npm
44
Repository Intelligence Analyze repos of any size - security scanning code analysis monorepo support
Security 28
45
Prism Scanner Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
Security 27 pypi
46
mcp-cinema4d MCP server for Cinema 4D — entity CRUD, parameter-level access, batched undo, security controls.
Security 25 npm
47
operant-mcp Security testing MCP server for penetration testing, forensics, and vulnerability assessment
Security 25 npm
48
hush A secret store for AI agents: the agent never sees the plaintext.
Security 20 remote
49
mastyf.ai Runtime proxy for MCP security, cost governance & audit
Security 20 npm
50
Clipboard History MCP Your clipboard, but Claude can read it. Type-classified, secret-encrypted. macOS + Linux.
Security 19 mcpb
51
Nekzus-npm-sentinel-mcp Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
Security 18 remote
52
npm-sentinel-mcp Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.
Security 18 npm
53
Phantom Secrets Value-blind secret metadata and gated workflows for AI coding agents through Phantom's local proxy.
Security 16 npm
54
NeuroDock (hosted) Hosted NeuroDock — stateless communication and planning tools over OAuth-secured Streamable HTTP.
Security 16 remote
55
prodcheck 4,372 pre-production checks: security, performance, scale, integrations, post-launch.
Security 15 npm
56
prodlint Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.
Security 15 npm
57
aegis Credential isolation for AI agents. Inject secrets at the network boundary.
Security 14 npm
58
WHOOP — MissingMCP WHOOP recovery, strain, sleep and workouts in Claude via official WHOOP OAuth. Free, open source.
Security 13 remote
59
MobiLoop Guarded AI mobile Appium testing, security scanning, verification, and fix-retest MCP tools.
Security 12 oci
60
cortex-gateway Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.
Security 12 remote oci
61
IdentArk Gateway Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
Security 12 remote
62
TAP Credential isolation for AI agents: placeholder secrets, policy checks, optional human approval.
Security 12 remote
63
ProductClank Boost posts and launch community growth campaigns from your AI assistant. OAuth, credit-billed.
Security 11 remote
64
Klarion Secret scanning for AI agents: rules and entropy find candidates, a model decides which are real.
Security 11 mcpb
65
pkgxray Pre-install security scans for npm packages, MCP servers, and AI agents with cited verdict evidence.
Security 11 npm
66
vulnicheck HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.
Security 11 oci
67
mcp-eu-ai-act EU AI Act + GDPR compliance scanner. One call, no arguments, 10 seconds. 22 AI frameworks detected.
Security 11 remote
68
Niro AI pentester for PRs — finds exploitable bugs and hands your developer agent the fix.
Security 10 mcpb
69
Trent Security reviews, threat models over a repo or website, and remediation tracking, in your editor.
Security 9 remote
70
royal-mcp Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.
Security 9 remote
71
stackhawk An MCP server that provides interaction with StackHawk's security scanning platform.
Security 9 pypi
72
skgate OAuth MCP gateway. SI proxy with model aliases. Grok subscription as OpenAI-compatible API, no key.
Security 9 oci
73
mcp-threatintel Unified threat intel - OTX, AbuseIPDB, GreyNoise, abuse.ch, Feodo Tracker
Security 8 npm
74
MCP Safety Warden MCP proxy adding security scanning, behavioral profiling, risk gating, and safe tool call execution.
Security 8 pypi
75
Snyk API & Web MCP Server MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage
Security 8 pypi
76
wass-mcp MCP server for web application security scanning
Security 8
77
SPARDA AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
Security 8 npm
78
SPARDA AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
Security 8 npm
79
Draugr Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
Security 7 mcpb
80
Judges Panel 45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
Security 7 npm
81
PreClick — An MCP-native URL preflight scanning service for autonomous agents. PreClick scans links for threats and confirms intent match with high accuracy before agents click.
Security 6 remote
82
SkillTotal Deterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.
Security 6 pypi
83
PreClick — An MCP-native URL preflight scanning service for autonomous agents (formerly URLCheck). PreClick scans links for threats and confirms intent match with high accuracy before agents click.
Security 6 remote
84
mcp-bastion Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.
Security 6 npm
85
FedRAMP 20x Requirements An MCP server that provides access to FedRAMP 20x security requirements and controls.
Security 6 pypi
86
pincer Secure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture
Security 6 npm
87
skill-audit-mcp MCP server: static security scanner for MCP servers, agent skills & plugins. 17 attack patterns.
Security 6 remote oci
88
supply-chain-guard Supply-chain malware scanner and MCP server: vet packages in 15 ecosystems before install, offline.
Security 6 npm
89
Husk Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs
Security 6 npm cargo
90
Cybersecurity Vulnerability Intel CVE lookup via NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK. 7 tools.
Security 6 remote
91
Regulatory Monitor Federal Register monitoring and regulations.gov tracking. 4 MCP tools for regulatory compliance.
Security 6 remote
92
MCP-Bastion Security middleware for MCP. Blocks prompt injection, PII leakage, and resource exhaustion.
Security 6 pypi
93
Aident Loadout Connect any AI agent to 1,000+ apps and 27,000+ actions through one remote MCP server (OAuth).
Security 5 remote
94
nucleus Sovereign Agent OS — Persistent Memory, Governance & Compliance for AI Agents.
Security 5 remote pypi
95
guardvibe Deterministic security layer your AI can't be. 553 rules, 39 tools, CLI + doctor + host audit.
Security 5 npm
96
leakferret Context-aware secret scanner: lets an AI agent scan, verify, and rewrite secrets before committing.
Security 5 npm
97
zerosmtp A free SMTP relay that still takes a username and password, for devices that cannot do OAuth 2.0.
Security 5 npm
98
onelogin-mcp MCP server for OneLogin API - manage users, apps, roles, and authentication
Security 5 npm
99
siteaudit-mcp SEO, performance, and security audits for any URL — no API keys required
Security 5 pypi
100
kdbx Read-only access to secrets in a local KeePassXC vault. Runs commands with them injected.
Security 5 oci

Other categories

Newest in the registry

Most recently published in security.

AI agents that can use MCP servers

From each product's documentation; see the feature matrix.