Security
Everything here was classified as security by keyword match against the maintainer's own description, so treat the grouping as a starting point rather than a verdict.
The list is ordered by the most recent commit, not by stars. A popular project that stopped in 2024 is not a better answer than a smaller one shipped last week.
Listed, not yet verified by us (60)
Published to the registry, but we have not yet checked its repository. Treat the entry as the maintainer’s claim only.
-
io.github.visus-mcp/visus-mcp
— v0.13.0
Security-first web access. Sanitizes pages, blocks injection, redacts PII. Now with PDF/JSON/SVG.
-
io.github.vmoranv/jshookmcp
— v0.3.0
MCP server for JavaScript analysis, security auditing, browser automation and hooks
-
VMware Harden
— v1.8.9
VMware compliance scanning (CIS, vSphere SCG, GB/T 22239, PCI-DSS) with drift detection.
-
VMware NSX Security
— v1.8.9
VMware NSX security: DFW policies, security groups, tags, Traceflow, IDPS — 21 MCP tools.
-
io.github.vola-trebla/env-secret-exposure-analyzer-mcp
— v0.2.0
Scans projects for secret exposure: leaked API keys, unprotected .env files, and secrets in logs.
-
io.github.VouchlyAI/pincer
— v0.1.5
Secure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture
-
io.github.vpatser1/legal-doc-analyzer
— v1.1.4
Contract analysis, risk assessment, version diffs, compliance checks (GDPR, CCPA, SOC2)
-
io.github.vpatser1/mcp-server-security-scanner
— v1.1.4
Scan MCP configs for 30+ CVEs, prompt injection, tool poisoning; validate OAuth configs
-
VulnCheck
— v0.1.2
VulnCheck exploit intelligence — CVE research, exploit data, advisories, and threat analysis.
-
cve-cache
— v0.1.1
Recent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).
-
MCP Gateway Scan
— v0.1.1
Read-only MCP/agent-gateway readiness scanner — scores a repo across 7 security dimensions.
-
io.github.wiserautomation/suprawall-mcp
— v0.1.0
SupraWall security gateway for AI agents. Provides deterministic guardrails for MCP agents.
-
io.github.wkoverfield/switchboard
— v0.2.2
One firewall and password manager for all your AI coding agents' MCP servers and secrets.
-
io.github.wundervault/wundervault-mcp
— v1.6.9
Zero-knowledge MCP secrets vault for AI agents: secrets injected at runtime, never seen by the model
-
Abnormal Security
— v1.2.0
MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation.
-
Avanan
— v2.2.1
MCP server for Check Point Harmony Email & Collaboration (Avanan) email security.
-
KnowBe4
— v1.1.1
MCP server for KnowBe4 security awareness training — users, groups, training, phishing campaigns.
-
Mimecast
— v1.3.0
MCP server for Mimecast email security: message queue, held messages, domains, and threats.
-
Proofpoint
— v1.1.2
MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.
-
SaaS Alerts
— v1.2.0
MCP server for Kaseya SaaS Alerts — SaaS security monitoring for M365 & Google Workspace.
-
SpamTitan
— v1.3.1
MCP server for SpamTitan email security — quarantine, allow/block lists, and policy management.
-
HIPAA Agent
— v2.0.0
HIPAA compliance AI agent — scan, grade, SRA, and generate compliance docs.
-
io.github.xiaoxuzhu303-prog/harmony-mcp
— v0.4.2
AI copilot for WeChat Mini Program - compile-fix, size analysis, compliance. 20 tools.
-
io.github.xmpuspus/cloudwright
— v1.9.0
Natural-language cloud architecture: deployable Terraform/Pulumi, cost, compliance control mapping.
-
io.github.xu-c0/cybersec-mcp
— v0.1.2
Cybersecurity MCP server: 323 prompts + 7 workflows for red team, blue team, SOC, cloud, OSINT.
-
kdbx
— v0.3.1
Read-only access to secrets in a local KeePassXC vault. Runs commands with them injected.
-
io.github.YawLabs/electron-mcp
— v1.2.15
Electron.js MCP server — IPC scaffolding, security auditing, build tooling for AI assistants
-
io.github.YawLabs/mcp-compliance
— v0.16.4
CLI tool and MCP server that tests MCP servers for spec compliance
-
io.github.YawLabs/npmjs-mcp
— v0.12.2
npm registry MCP server — package intelligence, security audits, dependency analysis
-
PkgSeek Linux Intelligence
— v0.1.19
Linux package, file, command, vulnerability, lifecycle, migration, and repository intelligence.
-
io.github.yifanyifan897645/webcheck
— v0.1.3
Website health analysis: SEO, accessibility, performance, security, and broken links
-
lavela
— v1.0.0
Launch and operate a SaaS from one conversation — domain, hosting, email, Stripe, ads, security.
-
io.github.your-ko/mcp-k8s-ro
— v1.2.0
Read-only Kubernetes MCP server: inspect resources, logs, events, and metrics. Secrets are masked.
-
io.github.yourtablecloth/tablecloth-mcp
— v0.3.0
Open Korean e-Gov and finance sites in a clean, disposable Windows Sandbox with security programs.
-
VMware Harden
— v1.8.7
VMware compliance scanning (CIS, vSphere SCG, GB/T 22239, PCI-DSS) with drift detection.
-
VMware NSX Security
— v1.8.8
VMware NSX security: DFW policies, security groups, tags, Traceflow, IDPS — 21 MCP tools.
-
SPARDA
— v0.71.3
AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
-
io.heronapp/heron
— v1.2.0
Signed security scores for what an AI agent runs and reads: skills, MCP servers, prompts, tokens.
-
KernelScan
— v1.0.0
Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs.
-
MCP Marketplace
— v1.0.0
Search and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client.
-
mytesla.io
— v1.0.0
Control your Tesla from your AI assistant - climate, charging, access, and security.
-
io.nip.5-9-107-124/token-risk
— v0.2.1
DeFi pool yield+security intelligence & token/contract risk scanner. USDC on Base via x402.
-
Seal Security
— v0.1.116
Vulnerability management: scan projects, search sealed packages, manage sealing rules and reports.
-
SimplyScan
— v1.0.0
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
-
io.snyk/mcp
— v1.1304.2
Easily find and fix security issues in your applications leveraging Snyk platform capabilities.
-
Stobox Intelligence & Tokenization
— v0.1.1
Verified RWA tokenization knowledge — security tokens, regulation, standards — for any AI.
-
mcp-armor
— v0.7.0
Security sidecar for MCP servers: prompt-injection scan, Ed25519 verify, tools/list drift. 10 tools.
-
systemprompt.io reports
— v1.0.0
Paid EU AI Act compliance reports for agents. $1.50 per call via x402 (USDC on Base) or Stripe.
-
io.tooloracle/agentguard
— v1.0.0
AgentGuard — 20-tool AI safety MCP: policy preflight, risk scoring, audit logging, rate limits.
-
io.tooloracle/ampel
— v1.0.0
AmpelOracle — 50-tool compliance traffic-light: Go/Caution/Stop signals for ESG, MiCA, AML.
-
io.tooloracle/cloudoracle
— v1.0.0
CloudOracle - 14-tool multi-cloud compliance MCP: AWS, Azure, GCP posture, IAM, configs.
-
io.tooloracle/conductor
— v1.0.0
DORA OS Conductor — 16-tool meta-orchestrator for DORA compliance workflow automation.
-
io.tooloracle/cybershield
— v1.0.0
CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.
-
io.tooloracle/doraeventfabric
— v1.0.0
DORA OS EventFabric - 14-tool event stream for DORA compliance signals and pub/sub fabric.
-
io.tooloracle/insuranceoracle
— v1.0.0
InsuranceOracle - 12 insurance compliance tools: GDV, BaFin VAG, Solvency II, IDD.
-
io.tooloracle/mica
— v1.0.0
MiCAOracle — 24 tools for EU MiCA stablecoin compliance: peg, reserves, attestations.
-
io.tooloracle/zkevidenceoracle
— v1.0.0
ZKEvidenceOracle - 14 zero-knowledge proof tools for compliance evidence: Groth16, PLONK.
-
it.elsas/security-intel
— v1.0.0
Daily Ed25519-signed security intelligence for AI-agent stacks; CVEs & advisories, paid via x402.
-
kr.ai.vdb/vdb
— v0.1.2
Check packages for CVEs, slopsquatting, and CISA KEV before your AI agent installs them.
-
net.agentutil/think-mcp
— v1.0.0
Intent security pre-flight checks for autonomous AI agents.
Page 12 of 13
How this page is ordered
Entries are grouped by whether anyone is still working on them, using the date of the most recent push to the repository. They are not ordered by stars, because a star is a bookmark somebody left once and never took back.
Where we have not checked an entry yet, it says so rather than being mixed in with the verified ones.