Security
Everything here was classified as security by keyword match against the maintainer's own description, so treat the grouping as a starting point rather than a verdict.
The list is ordered by the most recent commit, not by stars. A popular project that stopped in 2024 is not a better answer than a smaller one shipped last week.
Listed, not yet verified by us (60)
Published to the registry, but we have not yet checked its repository. Treat the entry as the maintainer’s claim only.
-
io.github.kastelldev/kastell
— v1.14.0
Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.
-
io.github.kayembahamid/cybersim-pro
— v1.0.1
Cybersecurity training, simulation, and incident response MCP server
-
Kody
— v1.0.0
Personal assistant MCP server with search, execute, packages, jobs, secrets, and integrations.
-
FedRAMP 20x Requirements
— v1.3.0
An MCP server that provides access to FedRAMP 20x security requirements and controls.
-
GDPR Shift-Left Compliance
— v0.4.0
GDPR compliance MCP server - article lookup, DPIA, ROPA, DSR, IaC analysis, Bicep templates.
-
Judges Panel
— v3.129.9
45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
-
io.github.Kevthetech143/chain-signer
— v0.5.31
Security suite for AI agents: flag drains, permit-phishing & risky actions before signing.
-
io.github.kjgueye/netintel-mcp
— v1.1.38
MCP server for NetIntel — DNS, SSL, WHOIS, email security, OSINT via x402 micropayments
-
io.github.Kjopstad-IT/rqwstr
— v1.1.0
AI-native HTTP security testing MCP server — 17 tools with raw HTTP/1.1 + HTTP/2 control
-
io.github.klmlfl/case-doha-record
— v1.0.0
Search 30,000+ decided U.S. DOHA security-clearance decisions, cited to the public record.
-
Kloudle Cloud Security Scanner
— v0.1.1
AWS cloud security scanners for AI agents — S3, IAM, EC2, EKS, RDS, CloudTrail, CloudWatch Logs
-
io.github.KN0WBOT/clavis
— v0.1.3
Encrypted credential vault for AI agents — auto OAuth refresh, rate limiting, audit logging.
-
io.github.KNambiarDJsc/meridian-mcp
— v0.3.3
Local-first compliance scanner for DPDPA 2023/2025, RBI FREE-AI, SEBI AI/ML & EU AI Act.
-
GIA — Governed Intelligence Architecture
— v0.4.4
Runtime AI governance: decision gates, human approval, hash-chained audit, compliance mapping.
-
io.github.kota1026/bridgeguard-mcp
— v1.0.0
BridgeGuard MCP Server - Cross-chain bridge security audit tools for AI coding agents. Scan bri...
-
io.github.kota1026/quantumguard-mcp
— v1.0.0
Post-quantum cryptography security scanner. Detect ECDSA/RSA vulnerabilities, NIST compliance.
-
io.github.kota1026/smartguard-mcp
— v1.0.0
SmartGuard MCP Server - AI-powered smart contract security audit tools for Claude Code, Cursor,...
-
io.github.kota1026/vaultguard-mcp
— v1.0.0
VaultGuard MCP Server - Yearn V3 / DeFi vault security and analysis tools for AI coding agents....
-
io.github.kridaydave/file-organizer
— v2.1.0
Security-hardened file organizer with smart categorization and duplicate detection
-
io.github.KryptosAI/mcp-observatory
— v1.36.1
MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
-
io.github.KryptosAI/mcp-seatbelt
— v0.7.0
MCP runtime security proxy. Blocks dangerous AI agent tool calls with a policy engine.
-
io.github.kumoproductions/mcp-cinema4d
— v0.3.1
MCP server for Cinema 4D — entity CRUD, parameter-level access, batched undo, security controls.
-
MySQL (security-first)
— v1.3.1
Security-first MySQL MCP server with AST validation, table whitelist, schema resources, and audit.
-
NORMA MCP Server
— v1.0.0
EU compliance corpus across 8 frameworks (NIS2, DORA, AI Act, ISO 27001 + more) via MCP.
-
Warden
— v1.0.0
Register every AI agent, log every action, prove it. EU AI Act compliance built in.
-
AXIS Toolbox — Agentic Commerce Codebase Intelligence
— v0.4.0
Generate AGENTS.md, AP2 compliance docs, checkout rules, debug playbook & MCP configs from any repo.
-
io.github.leakferrethq/leakferret
— v0.1.13
Context-aware secret scanner: lets an AI agent scan, verify, and rewrite secrets before committing.
-
io.github.legalithm/legalithm-mcp-server
— v0.1.2
EU AI Act compliance in your editor: classify risk, cite obligations, draft Article 50 text.
-
io.github.leochong/visus-mcp
— v0.6.1
Security-first web access for Claude. Sanitizes pages, blocks injection, redacts PII.
-
ComplianceCN 跨境电商出海合规预检
— v0.3.1
出海合规预检 · Source-cited EU/US/UK/AU market-access checks for cross-border sellers
-
io.github.littleblakew/msds-chain
— v1.5.5
Chemical safety intelligence — 23 tools: compatibility, hazards, PPE, compliance, SDS lookup
-
Veragent
— v0.1.1
Check the trust/security score of MCP servers, agents, skills & CLIs before you install them.
-
io.github.llmops-pro/nostr-ops-mcp
— v0.2.3
Nostr publishing, queries, and DMs for AI agents, with allowlists, rate limits, and an audit log.
-
io.github.llmops-pro/nwc-mcp
— v0.2.3
Lightning wallet for AI agents via Nostr Wallet Connect (NIP-47): budget caps, confirm, audit log.
-
AIShield Security Scanner
— v4.2.1
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
-
io.github.loaditoutadmin/loaditout
— v0.2.4
Search and install 20,000+ security-graded MCP servers and agent skills.
-
io.github.Lokeshwaranramu/quantaseal
— v1.1.3
Quantum-safe vault, encryption & compliance for AI agents. NIST FIPS 203/204 ML-KEM-768 + ML-DSA-65.
-
Overdrive Intel
— v0.9.1
AI coding ecosystem intelligence — breaking changes, tools, security alerts from 900+ sources
-
io.github.lordbasilaiassistant-sudo/contract-scanner
— v1.0.2
Smart contract security scanner — vulnerabilities, risk scores, and calldata decoding
-
Bug Detector
— v1.0.0
Analyzes code for bugs, security vulnerabilities, and code smells
-
io.github.manumarri-sudo/quill
— v0.2.0a5
Pre-execution gate for AI-agent tool calls. Touch ID approval. Tamper-evident audit log.
-
Contazz AutoPilot
— v1.0.0
Brazilian AI-powered accounting & tax automation: NFS-e invoicing, CBS/IBS tax reform, compliance.
-
io.github.marcosnovo/lexvibe
— v1.0.3
One-step legal compliance for vibe-coded apps: privacy, terms, cookie banner and EU AI Act check.
-
Cordon for MCP
— v0.3.0
Cordon for MCP. Security gateway with policy enforcement, audit log, and HITL approvals.
-
Cybersecurity Vulnerability Intel
— v1.0.0
CVE lookup via NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK. 7 tools.
-
Environmental Compliance
— v1.0.0
EPA air quality monitoring and HUD foreclosure data. 3 MCP tools for environmental and housing data.
-
Regulatory Monitor
— v1.0.0
Federal Register monitoring and regulations.gov tracking. 4 MCP tools for regulatory compliance.
-
io.github.mastrophot/contract-security-scanner
— v0.1.1
MCP smart contract scanner with NEAR-focused security context.
-
io.github.mastyf-ai/mastyf.ai
— v4.1.12
Runtime proxy for MCP security, cost governance & audit
-
NYC Property & Venue API
— v0.1.2
NYC property intelligence, building violations, and restaurant/venue compliance via MCP.
-
io.github.matematicsolutions/mcp-eu-compliance
— v0.4.0
Offline MCP server: EU digital/data/cyber compliance full text (14 regs), verbatim + citations.
-
Sentrik
— v1.2.0
Governance runtime for AI-generated code. Enforce compliance and security standards.
-
dotrepo
— v1.0.1
Trust-aware repository facts for agents: build, test, docs, license, and security, no scraping.
-
io.github.mbeato/apimesh
— v1.8.2
74 paid web-analysis APIs (SEO, security, TLS, DNS, email) as MCP tools. USDC via x402.
-
DNS MCP Server
— v1.3.4
Real-time DNS security analysis — DNSSEC, email auth, and RDAP. Built for SOC investigations.
-
MCP Fortress
— v0.3.6
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
-
io.github.mcp-protocol/node-runtime
— v1.0.2
This package is intended for demonstration only. Maintained by JFrog Security.
-
MCP Customs
— v0.1.1
Inspect an MCP server for common security risks before you install it. Offline, zero telemetry.
-
MCPower Security Proxy
— v0.0.91
Security proxy that automatically wraps MCP servers with real-time monitoring and policy enforcement
-
SBOMApp - SBOM Generator & Vulnerability Scanner
— v1.1.0
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Page 8 of 13
How this page is ordered
Entries are grouped by whether anyone is still working on them, using the date of the most recent push to the repository. They are not ordered by stars, because a star is a bookmark somebody left once and never took back.
Where we have not checked an entry yet, it says so rather than being mixed in with the verified ones.