Security
Everything here was classified as security by keyword match against the maintainer's own description, so treat the grouping as a starting point rather than a verdict.
The list is ordered by the most recent commit, not by stars. A popular project that stopped in 2024 is not a better answer than a smaller one shipped last week.
Listed, not yet verified by us (60)
Published to the registry, but we have not yet checked its repository. Treat the entry as the maintainer’s claim only.
-
io.github.MCPShield-Dev/mcpshield
— v2.0.2
Security scanner for MCP servers - detects tool poisoning and injection
-
io.github.mdfifty50-boop/agent-security
— v0.1.3
Security scanning and threat detection for AI agents
-
io.github.mdfifty50-boop/compliance-shield
— v0.1.3
ZATCA, UAE CT, EU AI Act regulatory compliance for AI agents
-
io.github.mdfifty50-boop/secure-vault
— v0.1.1
Encrypted secrets and credential management for agents
-
io.github.megabrainee/sectora
— v1.1.0
Threat intel + your scans/findings/Shield posture. CVE, EPSS, KEV, package vuln lookup, DAST.
-
PostgreSQL CVE & Release Intelligence
— v1.0.2
PostgreSQL security for AI agents: CVEs, yanked releases, exploits, and upgrade paths
-
Parse-DMARC MCP Server
— v1.4.7
Lightweight DMARC parser: auto-fetch email reports, visualize compliance in a single all-in-one app
-
io.github.mgthompo1/anchorr-mcp
— v0.2.0
Agent-native CRM. 25 tools — contacts, deals, sequences, enrichment waterfall, audit log.
-
io.github.Mickdownunder/safeinstall
— v0.12.0
Local-first supply-chain security gate for npm/pnpm/bun: typosquat, release age, provenance checks
-
io.github.microqueryhq/microquery-mcp
— v1.0.3
SQL over real-world data — FDA, SEC, blockchain, genomics, CVEs, and more. No config.
-
io.github.middleBrick/mcp-server
— v0.1.2
Scan APIs for OWASP Top 10, LLM, and GraphQL security vulnerabilities.
-
Agent Security Scanner
— v0.4.2
Scan AI agents for tool-calling vulnerabilities: prompt leaks, hijacking, injections, and more.
-
Vanta
— v0.2.0
Vanta compliance MCP server: vulnerabilities, tests, controls, evidence, people, vendors, docs
-
io.github.minjikim89/fde-agent
— v1.0.0
Diagnose AI workflows for failure, security, and handoff risks — RED/AMBER/GREEN per node.
-
io.github.mintmas/oracle42-intelligence
— v1.0.0
AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.
-
ClauseKeeper Compliance Scanner
— v0.1.1
Scan website legal docs for missing or stale compliance clauses. Rule-based, no LLM.
-
io.github.mlawsonking/agent-firewall-mcp
— v1.2.0
Input/output safety for AI agents: known-pattern injection and obfuscation scan, URL/IP, secrets.
-
io.github.mlawsonking/code-guard-mcp
— v1.2.0
Security scan for AI-generated code: injection, SSRF, secrets, weak crypto, unsafe deserialization.
-
io.github.moxno/privacyscrubber-mcp
— v1.0.2
Zero-Trust PII & secrets sanitizer. Locally scrubs data in-memory before sending context to LLMs.
-
agent-bom
— v0.82.3
Security scanner and graph for agentic infrastructure — agents, MCP, runtime, and blast radius.
-
io.github.mythos-agent/mythos-agent
— v4.0.1
Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
-
Frigolog HACCP — French Food Safety Compliance
— v3.0.1
French HACCP for restaurants: temperatures, DLC, allergens, DDPP controls, live recalls. Sourced.
-
io.github.nan786521/recon-kit-mcp
— v0.13.0
Read-only network & security recon tools (DNS, TLS, headers, CORS) for AI agents, each graded.
-
io.github.Nekzus/npm-sentinel-mcp
— v1.26.0
Advanced NPM analysis: Recursive security scanning, ecosystem awareness, and deep insights.
-
Signal Oracle
— v1.0.0
Pay-per-call change-intelligence feeds for AI agents over x402 (deps, security, regs, tariffs)
-
Bright Security
— v1.0.1
AI-powered application security testing — scan APIs, discover endpoints, and find vulnerabilities.
-
NEUS MCP
— v1.3.8
Portable identity, authority, trust receipts, and Vault secrets before sensitive AI actions.
-
io.github.nexus-api-lab/nexus-mcp
— v1.0.0
Japanese LLM security — prompt injection detection (jpi-guard) + PII masking (PII Guard). Free.
-
io.github.NexusFeed/nexusfeed-abc
— v1.1.1
US liquor license compliance records (CA, TX, NY, FL, IL) with verifiable provenance.
-
mcp-gatehouse
— v0.1.0
Permission tiers, approval gates, and audit logging for MCP servers - the server is the gatekeeper
-
io.github.NikitaDatar/vectordecisions-mcp-server
— v1.0.3
AI Governance MCP Server - GATRI trust scoring, kill-switch, EU AI Act compliance for Claude
-
Repository Intelligence
— v1.0.0
Analyze repos of any size - security scanning code analysis monorepo support
-
io.github.node-man/dechonet-mcp
— v1.0.1
13 security recon tools for AI agents — DNS, SSL, HTTP, email, ports, ASN. Health Score 0-100.
-
Secrets-LE
— v2.2.2
Detect hardcoded secrets in source and config. Reports masked previews, never the values.
-
InsAIts - AI Communication Security Monitor
— v3.1.1
Runtime AI-to-AI security monitor. 23 anomaly types, OWASP MCP Top 10 coverage.
-
io.github.NOTTIBOY137/open-registry-poc
— v1.0.0
PoC: Open Registry supply chain — unvetted server listing (security research)
-
io.github.NOTTIBOY137/update-hijack-poc
— v1.0.1
PoC benign MCP server for update-hijack security research
-
PQC-Khepra MCP — CMMC Autopilot & AI Security Recorder
— v1.0.0
Post-quantum CMMC compliance scanner & AI agent attestation. FIPS 140-3, ML-DSA-65, 36K+ mappings.
-
VulnFeed
— v0.3.7
Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402.
-
io.github.nqzai/kakunin
— v0.2.3
X.509 identity, risk scoring, and audit logging for AI agents. MiCA + EU AI Act compliant.
-
bouncer
— v0.2.0
Static compliance-controls checker for UK Online Safety Act & ICO Children's Code. CLI + MCP.
-
RelayShield Security Intelligence
— v0.2.7
Breach, SIM swap, infostealer, domain lookalikes, MCP registry risk, prompt-injection detection.
-
MCP Sentinel
— v1.0.0
Zero-trust MCP security proxy with policy enforcement, PII scrubbing, approvals, and audit trails.
-
io.github.ogSINGH/contrast-checker-mcp
— v1.0.1
MCP - WCAG 2.1 color contrast checker - contrast ratios, compliance and accessible color suggestions
-
Data Compliance Classifier MCP
— v1.0.25
Classify data safety before storing or sharing. GDPR, HIPAA, PCI-DSS, CCPA. AI-powered.
-
VAT Validator MCP
— v2.0.30
Validate EU, UK, AU VAT numbers for AI agents. EU ViDA e-invoicing compliance.
-
io.github.oktopeak/clio-mcp
— v2.0.1
Connect Claude to Clio: 26 tools for matters, contacts, documents, tasks, billing, audit logs.
-
IntakeQ MCP
— v1.0.1
IntakeQ/PracticeQ MCP connector with HIPAA §164.312(b) audit logging on every PHI read/write
-
io.github.Olum289/agentlock
— v0.2.0
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
-
io.github.onefreeman1337/osf-data-marketplace
— v2.0.8
8.1M+ US gov and science data via x402 USDC. 21 tools, $0.001 sample tier, sanctions, SEC, CVEs.
-
Service Public France
— v1.14.8
French public services: tax, property, admin, education, healthcare, security, risks, legal texts
-
io.github.operantlabs/operant-mcp
— v1.0.1
Security testing MCP server for penetration testing, forensics, and vulnerability assessment
-
Gmail Postmaster Tools
— v1.0.1
Gmail Postmaster Tools v2 — domains, traffic metrics, and compliance via your own Google OAuth.
-
Agentic Security Shield
— v1.0.1
12-layer security configs for AI coding agents. Autonomous purchase via x402 (USDC on Base).
-
io.github.oscal-compass/compliance-trestle-mcp
— v0.1.2
An MCP server that provides tools to author OSCAL security compliance documentation
-
PageGuard MCP
— v1.0.1
Privacy compliance scanning for AI coding tools. Detects tracking tech, cookies, and data gaps.
-
PageLens AI
— v1.0.0
AI website audit: security, SEO, performance, UX and accessibility checks with actionable fixes.
-
MCP Gateway
— v1.0.0
Multi-tenant MCP platform with OAuth 2.1, Entra SSO, RBAC and audit logging.
-
io.github.Pantheon-Security/notebooklm-mcp-secure
— v2026.1.6
Security-hardened NotebookLM MCP with post-quantum encryption
-
io.github.parth-unjiya/odoo-mcp-gateway
— v0.1.1
Security-first MCP gateway for Odoo 17/18/19 — YAML-driven security, 27 tools
Page 9 of 13
How this page is ordered
Entries are grouped by whether anyone is still working on them, using the date of the most recent push to the repository. They are not ordered by stars, because a star is a bookmark somebody left once and never took back.
Where we have not checked an entry yet, it says so rather than being mixed in with the verified ones.