Security MCP Servers
Security topic — 243 MCP servers, ranked by GitHub stars.
csl-core
Deterministic AI safety policy engine with Z3 formal verification. Write, verify, and enforce machine-verifiable constraints for AI agents…
mcp-server-cortex
A Rust-based MCP server to integrate Cortex, enabling observable analysis and automated security responses through AI.
warden-mcp
MCP server for Bitwarden and Vaultwarden vault management. Search, create, edit, and organize logins, notes, cards, identities, SSH keys,…
mcp_vms
A Model Context Protocol (MCP) server designed to connect to a CCTV recording program (VMS) to retrieve recorded and live video streams.…
Aegis — AI Agent Governance
Policy-based governance for AI agent tool calls. YAML policy, approval gates, audit logging.
depguard
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory…
agentveil-sdk
Trust, identity (W3C DID), and EigenTrust reputation for AI agents. Attestations, disputes, sybil detection, IPFS audit anchoring.
mcp-server-thehive
A Rust-based MCP server to integrate TheHive, facilitating collaborative security incident response and case management via AI.
MCP Hangar
Policy enforcement plane for MCP: every tool call ends in a verdict. Self-hosted, MIT.
runtime-guard
Runtime policy enforcement for AI agents - prevents accidental damage to your systems, unauthorized agent access and automates…
s-gw
Keep credentials out of AI coding agents with local approvals, scoped injection, and audit trails.
aegis
Credential isolation for AI agents. Inject secrets at the network boundary.
vuln-nist-mcp-server
A Model Context Protocol (MCP) server for querying NIST National Vulnerability Database (NVD) API endpoints.
platform
Governance proxy for MCP servers — policy evaluation, human approval, audit trails.
sint-protocol
Security-first MCP governance proxy (`sint-mcp`) with capability tokens, T0-T3 approval tiers, fail-closed execution, and tamper-evident…
authmcp-gateway
[glama](https://glama.ai/mcp/servers/@loglux/auth-mcp-gateway) 🐍 ☁️ 🏠 🍎 🪟 🐧 - Auth proxy for MCP servers: OAuth2 + DCR, JWT, RBAC, rate…
quantakrypto pqc-tools
Scan code for quantum-vulnerable cryptography and get NIST post-quantum migration guidance.
Koma Core MCP
Protected RAG storage — agents discover public metadata, content only by access token.
Aperion Shield
Local guardrail proxy that blocks destructive MCP tool calls, rug pulls, and tool poisoning
Lingua Universale MCP Server
Verify AI agent communication with session types and formal proofs
opnsense-mcp
OPNsense firewall operations via API. Query ARP, DHCP, firewall rules, logs, interfaces, system status, and packet capture via STDIO or SSE.
secretctl
AI-safe secrets manager with MCP integration. Run commands with credentials injected as environment variables - AI agents never see…
assay
The firewall for MCP tool calls. Block, audit, replay with evidence bundles.
zitadel-mcp
MCP server for Zitadel identity management — manage users, projects, OIDC apps, roles, and service accounts through natural language.
scopeblind-gateway
Scan, protect, and monitor APIs from AI coding tools. Device-level rate limiting.
ciphertrust-manager-mcp-server
MCP server for Thales CipherTrust Manager integration, enabling secure key management, cryptographic operations, and compliance monitoring…
OPA MCP
Author, validate, debug, and explain OPA Rego policies through any MCP-compatible client.
job-verify
Detect fake-recruiter and job-offer scams using free OSINT. No API keys.
SPARDA
AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
hexforge-gateway
AI-assisted APK reverse-engineering workspace. Orchestrates jadx, apktool, adb, and frida as MCP agents through a Workflow engine, with a…
PerspectiveGraph
Read-only attack-path tools: reachable routes to sensitive assets, and what a fix would cut.
mcp-audit
Transparent Go proxy that intercepts, signs, rate-limits, redacts, and audits all MCP JSON-RPC tool calls without modifying client or…
Commit — Supply Chain Risk Scoring
Supply chain risk scoring for npm, PyPI, Cargo, and Go. 9 tools. Behavioral signals.
arai
Policy enforcement for AI coding agents derived from existing instruction files (CLAUDE.md, .cursorrules, .windsurfrules,…
mcp
MCP server for automated URL scanning and forensic phishing triage. Captures full DOM snapshots, network requests, and visual screenshots…
minreestr-mcp
Search каталогпо.рф (Russian software registry, 26k+ products) for import-substitution and ФСТЭК/ФСБ-certified software discovery. Three…
mcp-bastion
Reliability + security proxy for MCP: runtime tool-security and a compliance-mapped audit trail.
mcp-server
MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for…
guardvibe
Deterministic security layer your AI can't be. 472 rules, 39 tools, CLI + doctor + host audit.
q-ring
OS keychain secrets for AI coding agents, over MCP.
authbox
Zero-knowledge password manager with MCP credential gateway. BIP-39 seed phrase recovery, deterministic passwords, policy-gated AI agent…
scalekit-mcp-server
Hosted Scalekit MCP. Manage orgs, users, and SSO from the agent. https://mcp.scalekit.com
verify-mcp
Offline verification of signed artifacts -- receipts, manifests, audit bundles. Ed25519 + JCS. No accounts, no API calls. Apache-2.0.
Impri
Impri MCP server — human-in-the-loop approval inbox for AI agents
Agent Passport System — Cryptographic Identity for AI Agents
Cryptographic identity, delegation, governance, and commerce for AI agents. 152 tools.
AgentAvow
Signed, independently-recomputable safety scores for the MCP servers, packages, and tools an agent connects to: a 0–100 score plus an…
cmdxray
Offline MCP server: explains shell commands token-by-token and flags destructive ones for AI agents.
mcpwall
iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything.
Czech PII Anonymizer & NLP
Anonymize PII & redact text (GDPR): Czech + 35-lang NER, morphology, translation, spellcheck
Cyntrisec CLI (Historical)
Historical AWS analysis CLI; not a current Cyntrisec product.
patch-tuesday-mcp
Query Microsoft Patch Tuesday security updates (MSRC) with EPSS and CISA KEV enrichment
qURL
Mint, resolve, audit, and rotate scope-limited expiring access links (qURLs) for AI agents.
MolTrust MCP Server
Give an agent a verifiable identity, and check another agent's before dealing with it.
osv-ui
Visual CVE audit dashboard for npm, Python, Go, and Rust. Scan from Claude/Cursor, opens a browser UI for human review…
solvitor-mcp
Solvitor MCP server provides tools to access reverse engineering tools that help developers extract IDL files from closed-source Solana…
mcp-server
55 tools for verified public data lookups — CVE/SBOM security audits, licence compliance, patents, federal contracts, NPI provider…
inkog-mcp
Security co-pilot for AI agents. Scan for vulnerabilities, audit MCP servers, verify governance.
shohei
Rust infrastructure diagnostics MCP server for AI agents: DNS checks, TLS certificate chain inspection, email security, global DNS…
mcp-server-malcolm
MCP server for Malcolm (Zeek/Suricata/Arkime/OpenSearch): threat-hunting access for AI agents
kepil
Passport, mandate, fail-closed action gate and tamper-evident journal for AI agents.