Back to All MCP Servers
Best Claude Code MCP Servers for Security
100 MCP servers tagged with “security”
E2B Code Sandbox
Secure cloud sandbox for executing code in isolated environments with full system access
sandboxcode-executionsecuritycloud+1
Semgrep
Scan code for security vulnerabilities, bugs, and anti-patterns using Semgrep static analysis rules
securitysemgrepstatic-analysissast+1
RNWY Trust Intelligence
Check if an AI agent is trustworthy before you hire it. Sybil detection, signed attestations, and reviewer wallet analysis across 150,000+ agents. Free, no key.
trustsecurityai-agentsblockchain+1
Profullstack Server
A comprehensive MCP server aggregating 20+ tools including SEO optimization, document conversion, domain lookup, email validation, QR generation, weather data, social media posting, security scanning, and more developer utilities.
aggregatorssecurityai
Chrome Mcp Secure
Security-hardened Chrome automation with post-quantum encryption (ML-KEM-768 + ChaCha20-Poly1305), secure credential vault, memory scrubbing, and audit logging. 22 tools for browser automation and secure logins.
browser-automationsecuritybrowserautomation
Infrawise
Cloud infrastructure analysis for AI coding assistants — detects IaC drift, missing indexes, security gaps, and performance anti-patterns across AWS services and databases. 13 tools, works with Claude Code and Cursor.
cloud-platformsawssecurityperformance+1
Cloudwright
Natural-language cloud architecture intelligence for AWS, GCP, Azure, and Databricks. 19 tools for architecture design, cost estimation, compliance validation (HIPAA, SOC 2, FedRAMP, GDPR, PCI-DSS, Well-Architected), security scanning, Terraform/CloudFormation export, and blast-…
cloud-platformsawsgcpazure+1
Cli
Command line interface with secure execution and customizable security policies
coding-agentssecurity
Multi
Parallel multi-model code review, security analysis, and AI debate with ChatGPT, Claude, and Gemini. Orchestrates multiple LLMs for compare, consensus, and OWASP Top 10 security checks.
coding-agentssecurityaillm
Mysql
MySQL database integration with configurable access controls, schema inspection, and comprehensive security guidelines
databasesmysqlsecurity
Postgres
PostgreSQL MCP server with 14 tools for querying, schema exploration, and table analysis. Features security-first design with SQL injection prevention and read-only by default.
databasespostgressecurity
Libsql
Production-ready MCP server for libSQL databases with comprehensive security and management tools.
databasessecurity
AI SOC Sher
MCP Server to do dynamic AI SOC Security Threat analysis for a Text2SQL AI Agent.
developer-toolssecurityaiagent
Conan
Official MCP server for Conan C/C++ package manager. Create projects, manage dependencies, check licenses, and scan for security vulnerabilities.
developer-toolssecurity
GoSQLX
7 SQL tools (validate, format, parse, lint, security scan, metadata extraction, full analysis) over Streamable HTTP. Public remote server at mcp.gosqlx.dev - no install needed. 1.25M+ ops/sec, 6 SQL dialects.
developer-toolsgosecurity
Droidmind
Control Android devices with AI through MCP, enabling device control, debugging, system analysis, and UI automation with a comprehensive security framework.
developer-toolssecurityautomationai
Adr Analysis
AI-powered architectural analysis server for software projects. Provides technology stack detection, ADR management, security checks, enhanced TDD workflow, and deployment readiness validation with support for multiple AI models.
developer-toolssecuritydeploymentai
Everstake Mcp
An MCP server for Everstake's non-custodial staking data across 130+ networks: live APY, uptime metrics, rewards calculator, integrations, security and compliance. Built for asset managers, custodians, and exchanges evaluating institutional staking.
finance-fintechsecurity
Heurist Mesh
Access specialized web3 AI agents for blockchain analysis, smart contract security auditing, token metrics evaluation, and on-chain interactions through the Heurist Mesh network. Provides comprehensive tools for DeFi analysis, NFT valuation, and transaction monitoring across mul…
finance-fintechsecuritymonitoringai+1
Notebooklm Mcp Secure
Security-hardened NotebookLM MCP with post-quantum encryption (ML-KEM-768), GDPR/SOC2/CSSF compliance, and 14 security layers. Query Google's Gemini-grounded research from Claude and AI agents.
knowledge-memorygosecurityai+1
Mureo
Framework for AI agents (Claude Code, Cursor, Codex, Gemini) to operate Google Ads, Meta Ads, and Search Console. Grounded in a local STRATEGY.md — not metric-chasing. Defense-in-depth security, local-first. Apache 2.0.
marketinggosecurityai+1
Dynatrace
Leverage AI-driven observability, security, and automation to analyze anomalies, logs, traces, events, metrics.
monitoringsecurityautomationai+1
Lucidity
Enhance AI-generated code quality through intelligent, prompt-based analysis across 10 critical dimensions from complexity to security vulnerabilities
monitoringsecurityai
Gopher
Modern, cross-platform MCP server enabling AI assistants to browse and interact with both Gopher protocol and Gemini protocol resources safely and efficiently. Features dual protocol support, TLS security, and structured content extraction.
search-data-extractiongosecurityai
GhidraMCP
MCP server for integrating Ghidra with AI assistants. This plugin enables binary analysis, providing tools for function inspection, decompilation, memory exploration, and import/export analysis via the Model Context Protocol.
securityai
Dandan
Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across multiple threat detection engines.
securityaiagent
Authbox
Zero-knowledge password manager with MCP credential gateway. BIP-39 seed phrase recovery, deterministic passwords, policy-gated AI agent access (scope, rate limits, time windows, step-up approval), 70+ API key providers, and hash-chain audit trail. Go + Next.js + TypeScript.
securitytypescriptgoapi+2
Aegis
Policy-based governance for AI agent tool calls. YAML policies, approval gates, risk assessment, and audit logging. Cross-platform: LangChain, OpenAI, Anthropic, MCP.
securitygoaiagent
Solvitor
Solvitor MCP server provides tools to access reverse engineering tools that help developers extract IDL files from closed-source Solana smart contracts and decompile them.
security
AgentValet
Identity and credential governance broker for MCP servers. Issues scoped, short-lived credentials per agent to stop credential inheritance. Audit log, human approval gates, AIMS-aligned.
securitygoaiagent
Agntor Mcp
MCP audit server for agent discovery and certification. Provides trust and payment rail for AI agents including identity verification, escrow, settlement, and reputation management.
securityrustaiagent
Agentstamp
Trust intelligence for AI agents — identity stamps, reputation scoring (0-100), registry, forensic audit trails, and A2A passports via x402 micropayments.
securityrustaiagent
AIM
Security-focused MCP server that provides safety guidelines and content analysis for AI agents.
securityaiagent
Kastell
Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalO…
securitygonodedocker
Arkforge
Third-party certifying proxy — sign any HTTP call (AI agents, webhooks, microservices) with an independent Ed25519 signature, RFC 3161 timestamp, and Sigstore Rekor anchor. Works with Claude, GPT-4, Mistral, LangChain, AutoGen, or any HTTP client.
securityaiagent
Firewall
Deterministic security proxy (iptables for MCP) that intercepts tool calls, enforces YAML policies, scans for secret leakage, and logs everything. No AI, no cloud.
securityai
Dnstwist
MCP server for dnstwist, a powerful DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage.
security
Maigret
MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.
securityai
Shodan
MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.
securityapi
Virustotal
MCP server for querying the VirusTotal API. This server provides tools for scanning URLs, analyzing file hashes, and retrieving IP address reports.
securityrustapi
Csl Core
Deterministic AI safety policy engine with Z3 formal verification. Write, verify, and enforce machine-verifiable constraints for AI agents via MCP.
securityaiagent
Attestable
An MCP server running inside a trusted execution environment (TEE) via Gramine, showcasing remote attestation using [RA-TLS](https://gramine.readthedocs.io/en/stable/attestation.html). This allows an MCP client to verify the server before conencting.
securityrust
Cyntrisec Cli
Local-first AWS security analyzer that discovers attack paths and generates remediations using graph theory.
securityaws
Onepassword
An MCP server that enables secure credential retrieval from 1Password to be used by Agentic AI.
securityaiagent
Authenticator
A secure MCP (Model Context Protocol) server that enables AI agents to interact with the Authenticator App.
securityaiagent
Secretctl
AI-safe secrets manager with MCP integration. Run commands with credentials injected as environment variables - AI agents never see plaintext secrets. Features output sanitization, AES-256-GCM encryption, and Argon2id key derivation.
securitygoaiagent
Binary Ninja
A Binary Ninja plugin, MCP server, and bridge that seamlessly integrates [Binary Ninja](https://binary.ninja) with your favorite MCP client. It enables you to automate the process of performing binary analysis and reverse engineering.
security
Security
MCP server for querying the ORKL API. This server provides tools for fetching threat reports, analyzing threat actors, and retrieving intelligence sources.
securityapi
Volatility
MCP server for Volatility 3.x, allowing you to perform memory forensics analysis with AI assistant. Experience memory forensics without barriers as plugins like pslist and netscan become accessible through clean REST APIs and LLMs.
securityapirestai+1
Server Cortex
A Rust-based MCP server to integrate Cortex, enabling observable analysis and automated security responses through AI.
securityrustai
Server Thehive
A Rust-based MCP server to integrate TheHive, facilitating collaborative security incident response and case management via AI.
securityrustai
Server Wazuh
A Rust-based MCP server bridging Wazuh SIEM with AI assistants, providing real-time security alerts and event data for enhanced contextual understanding.
securityrustai
Aegis
Credential isolation proxy for AI agents. Injects secrets at the network boundary with domain restrictions, agent authentication, and audit logging. No SDK required — works as a transparent HTTP proxy or MCP server.
securityrestaiagent
Gia
Enterprise AI governance layer with 29 tools: MAI decision classification (Mandatory/Advisory/Informational), hash-chained forensic audit trails, human-in-the-loop gates, compliance mapping (NIST AI RMF, EU AI Act, ISO 42001), governed memory packs, and site reliability tools.
securitygoai
Cybersec Watchdog
Comprehensive Linux server security audit with 89 CIS Benchmark controls, NIST 800-53, and PCI-DSS compliance checks. Real-time monitoring with anomaly detection across 23 analyzers: firewall, SSH, fail2ban, Docker, CVE, rootkit, SSL/TLS, filesystem, network, and more.
securitydockermonitoringai
Inspector
MCP server for domain and URL security analysis powered by GridinSoft Inspector, enabling AI agents to verify website and link safety.
securityaiagent
Guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE versio…
securitygraphqlai
Vuln Nist
A Model Context Protocol (MCP) server for querying NIST National Vulnerability Database (NVD) API endpoints.
securityapi
Entraid
A MCP server for Microsoft Entra ID (Azure AD) directory, user, group, device, sign-in, and security operations via Microsoft Graph Python SDK.
securitypythonazureai
Quantum Ring
Quantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation.
securityaiagent
Intruder
MCP server to access [Intruder](https://www.intruder.io/), helping you identify, understand, and fix security vulnerabilities in your infrastructure.
security
ModelSafetyMCP
MCP server for scanning machine learning model artifacts for unsafe serialization, malicious model patterns, risky packaging, URL-based artifact scanning, and directory-level triage using ModelScan, PickleScan, and heuristic inspection.
security
Server Inject Bender
Security through absurdity: transforms SQL injection and XSS attempts into harmless comedy responses using AI-powered humor defense.
securityai
Shellward
AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.
securityaiagent
GhidrAssistMCP
A native Model Context Protocol server for Ghidra. Includes GUI configuration and logging, 31 powerful tools and no external dependencies.
security
Vms
A Model Context Protocol (MCP) server designed to connect to a CCTV recording program (VMS) to retrieve recorded and live video streams. It also provides tools to control the VMS software, such as showing live or playback dialogs for specific channels at specified times.
security
GhidraMCP
A Model Context Protocol server for Ghidra that enables LLMs to autonomously reverse engineer applications. Provides tools for decompiling binaries, renaming methods and data, and listing methods, classes, imports, and exports.
securityllm
Beelzebub
Beelzebub is a honeypot framework that lets you build honeypot tools using MCP. Its purpose is to detect prompt injection or malicious agent behavior. The underlying idea is to provide the agent with tools it would never use in its normal work.
securityagent
Ida Pro
MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.
securityai
Recon
Conversational recon interface and MCP server powered by httpx and asnmap. Supports various reconnaissance levels for domain analysis, security header inspection, certificate analysis, and ASN lookup.
securityai
Panther
MCP server that enables security professionals to interact with Panther's SIEM platform using natural language for writing detections, querying logs, and managing alerts.
security
Mobsf
A MCP server for MobSF which can be used for static and dynamic analysis of Android and iOS application.
security
Cervellaswarm
Verify AI agent communication protocols using session types. Formal specification with Lean 4 proofs, linter, formatter, and LSP. Catches deadlocks and role violations before deployment.
securitydeploymentaiagent
Rad Security Server
MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for querying the Rad Security API and retrieving security findings, reports, runtime data and many more.
securitykubernetesapiai
Radare2
MCP server for Radare2 disassembler. Provides AI with capability to disassemble and look into binaries for reverse engineering.
securityai
Cve Search
A Model Context Protocol (MCP) server for querying the CVE-Search API. This server provides comprehensive access to CVE-Search, browse vendor and product、get CVE per CVE-ID、get the last updated CVEs.
securityapi
Assay
Policy-as-code gate for MCP. A fail-closed proxy that denies risky tool calls before they run, produces offline-verifiable evidence bundles of what executed, and enforces IPv4/TCP egress in-kernel via eBPF/LSM and Landlock on Linux. Deterministic and offline-first.
securityai
Vet
vet-mcp checks open source packages—like those suggested by AI coding tools—for vulnerabilities and malicious code. It supports npm and PyPI, and runs locally via Docker or as a standalone binary for fast, automated vetting.
securitydockerai
Dawshund
An MCP server based on dAWShund to enumerate AWS IAM data, analyze effective permissions, and visualize access relationships across users, roles, and resources. Built for cloud security engineers who want fast, easy and effective insights into AWS identity risk.
securityaws
Ciphertrust Manager
MCP server for Thales CipherTrust Manager integration, enabling secure key management, cryptographic operations, and compliance monitoring through AI assistants.
securityrustmonitoringai
Thales Cdsp Cakm
MCP server for Thales CDSP CAKM integration, enabling secure key management, cryptographic operations, and compliance monitoring through AI assistants for Ms SQL and Oracle Databases.
securitymonitoringai
Thales Cdsp Crdp
MCP server for Thales CipherTrust Manager RestFul Data Protection service.
securityrustrest
Secops
All-in-one security testing toolbox that brings together popular open source tools through a single MCP interface. Connected to an AI agent, it enables tasks like pentesting, bug bounty hunting, threat hunting, and more.
securitytestingaiagent
Skillssafe
Free AI agent skill security scanner. Scan SKILL.md, MCP configs, and system prompts for credential theft, prompt injection, zero-width character attacks, and ClawHavoc indicators. Supports OpenClaw, Claude Code, Cursor, and Codex. No signup required.
securityaiagent
Cyberchef Api
MCP server for interacting with the CyberChef server API which will allow an MCP client to utilise the CyberChef operations.
securityapi
Platform
Governance proxy for MCP servers. Wraps any upstream server with policy evaluation, human approval workflows, and hash-chain audit trails. 18+ framework integrations. Apache 2.0 SDK.
securitygoai
Studio
Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs.
securityaiagent
Osv
Access the OSV (Open Source Vulnerabilities) database for vulnerability information. Query vulnerabilities by package version or commit, batch query multiple packages, and get detailed vulnerability information by ID.
securityai
OPNSenseMCP
MCP Server for managing & interacting with Open Source NGFW OPNSense via Natural Language
security
Aegis
AI-agent admission-control MCP server: validates file edits against Ring 0 syntax + Ring 0.5 structural-cost regression + workspace boundary (path / glob / shell-redirect / symlink). Negative-space framing — emits BLOCK / WARN / PASS verdicts, never coaches the agent.
securityaiagent
Ida Headless
Headless IDA Pro binary analysis via MCP. Multi-session concurrency with Go orchestration and Python workers. Supports Il2CppDumper and Blutter metadata import for Unity and Flutter reverse engineering.
securitypythongo
Apktool
APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.
securityautomation
Zitadel
MCP server for Zitadel identity management — manage users, projects, OIDC apps, roles, and service accounts through natural language.
security
Arai
Policy enforcement for AI coding agents derived from existing instruction files (CLAUDE.md, .cursorrules, .windsurfrules, .github/copilot-instructions.md) — no separate YAML to maintain. Rules with prohibitive predicates (`never`, `forbids`, `must_not`) emit `permissionDecision:…
securitygithubaiagent
Jadx Ai
JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.
securityaillm
DocSentinel
MCP server for AI agent for cybersecurity: automate assessment of documents, questionnaires & reports. Multi-format parsing, RAG knowledge base,Risks, compliance gaps, remediations.
securityairagagent
Urldna Mcp
MCP server for automated URL scanning and forensic phishing triage. Captures full DOM snapshots, network requests, and visual screenshots to identify malicious redirects and infrastructure. Supports historical threat hunting using Custom Query Language (CQL) to map actor pattern…
security
Depscope
Package Intelligence for AI agents. 22 tools across 17 ecosystems (npm/pypi/cargo/go/maven/nuget/rubygems/composer/pub/hex/swift/cocoapods/cpan/hackage/cran/conda/homebrew) — check health, vulnerabilities (OSV + CISA KEV + EPSS), typosquats, malicious flags, alternatives, known …
securitygoswiftai+1
Contrastapi
Security intelligence API with 31 MCP tools for CVE/EPSS/KEV lookup, domain recon (DNS/WHOIS/SSL/subdomains/CT logs), IOC/threat intel, OSINT (email/phone/username), and code security scanning (secrets, injection). Free 100 req/hr.
securityapiai
Depguard
Pre-install guardian for npm packages with static code analysis, supply-chain attack detection, vulnerability audit (npm + GitHub Advisory Database), AI hallucination guard, and CycloneDX 1.6 SBOM generation with VEX. 28 MCP tools. Zero runtime dependencies — the SBOM serializer…
securitygithubai
Drill down: Security setups by use case
Browse more topics
aerospace-astrodynamicsagentaggregatorsagileaiai-agentsai-personaairtablealertingamplitudeanalyticsapiapidogapifyapmarchitecture-designart-cultureatlassianatprotoauthautomationawsaxiomazurebigquerybiology-medicine-and-bioinformaticsbitbucketblockchainblueskybravebrowserbrowser-automationcachechatchromadbcicdcircleciclickhousecloudcloud-platformscloudflarecode-executioncoding-agentscolabcommand-linecommunicationcommunicationscommunityconfluencecontainerscontextcrash-reportingcrawlingcrmcustomer-data-platformscypherdashboardsdatadata-engineeringdata-extractiondata-platformsdata-sciencedata-science-toolsdata-visualizationdata-warehousedatabasedatabasesdatadogdbtdebuggingdeliverydeploymentdesigndeveloper-toolsdevopsdigitaloceandirectionsdiscorddockerdocumentationdrivee-commerceecommerceedgeelasticsearchemailembedded-systemembeddingembeddingsend-to-end-rag-platformsenterpriseenvironment-natureerrorsevent-driveneventsfetchfigmafile-systemsfilesfilesystemfinancefinance-fintechgaminggcpgeocodinggitgithubgitlabgogooglegoogle-cloudgoogle-mapsgptgrafanagraphgraphqlhashicorphome-automationhostinghttphubspotiacidentityincidentsinfrastructureissuesjamstackjavascriptjirak8skafkakanbanknowledge-baseknowledge-graphknowledge-memorykotlinkuberneteslegallibrarieslibsqllinearllmlocationlocation-serviceslogginglogsmapsmarkdownmarketingmediamemorymessagingmetricsmicrosoftmigrationsmilvusmongodbmonitoringmultimedia-processmysqlneo4jneonnetlifynewrelicnextjsno-codenodenosqlnotebooksnotesnotionobservabilityobsidianofficialolapon-callopenaiopenapiordersormos-automationother-tools-and-integrationspagerdutypaymentsperformancepersistencepersonapineconeplanningplaywrightpostgresprdprismaproblem-solvingproduct-analyticsproduct-managementproductivityproductsproject-managementpuppeteerpythonqdrantragraygunreactreal-timereasoningredisresearchresendrestrustsalessalesforcesandboxsastschemascrapingsearchsearch-data-extractionsecuritysemanticsemgrepsentryserverlessshopifyslacksmssnowflakesocialsocial-mediasoqlsoul-specspeech-to-textsportsspreadsheetsqlsqlitestatic-analysisstoragestorestreamingstripesupabasesupport-service-managementswaggerswiftsybil-detectiontaskmastertasksterraformtestingtext-to-speechthinkingtimetimezonetinybirdtransactionaltranscriptstransformationstranslation-servicestravel-transportationtrellotrusttursotwiliotypescriptuiupstashutilityvcsvector-databasevercelversion-controlvideovueweaviatewebworkersworkflowworkplace-productivityyoutube