Security MCP servers

1,833 tagged Security, measured the same way as everything else here.

Browse within: model-context-protocol 240compliance 74ai-security 70ai-governance 62AI Safety 59cybersecurity 43devsecops 42agent-security 36audit 32llm-security 31pipeworx 31CVE 24Guardrails 24x402 24

octowatch-mcp

361

extralabs/octowatch-mcp-server

MCP server Claude CodeCodexCursor +2

Read-only MCP server for OctoWatch DLP Cloud (console analytics, monitoring, risks, productivity). Runs locally from the octowatch-mcp Python package. Needs 4 environment variables to run.

not rated 2 8d ago A tokens not measured original MIT

mcpampel

362

MCPAmpel/mcpampel

MCP server Claude CodeCodexCursor +2

MCP security scanner plugin - scan your installed MCP servers with 16 engines. Runs locally from the mcpampel Python package. Needs 1 environment variable to run.

not rated 2 5mo ago A tokens not measured original Apache-2.0

qorami

363

loicfontaine-max/qorami-sdk

MCP server Claude CodeCodexCursor +2

Check an email before an AI agent sends it: send / ask a human / block. Detects prompt injection. Runs locally from the qorami-mcp npm package. Needs 1 environment variable to run.

not rated 2 2mo ago A tokens not measured original MIT

aishield

364

lm203688/aishield

MCP server Claude CodeCodexCursor +2

MCP server "aishield" as configured in lm203688/aishield. Runs api.mcp_server with python.

not rated 2 today A tokens not measured original MIT

mcp-audit-proxy

365

firatmio/mcp-audit-proxy

MCP server Claude CodeCodexCursor +2

Transparent audit proxy for MCP servers: logs every tool call, flags poisoning and rug pulls. Runs locally from the mcp-audit-proxy npm package.

not rated 2 22d ago A tokens not measured original Apache-2.0

flagrix

366

flagrix-io/flagrix-cli

MCP server Claude CodeCodexCursor +2

Scan GitHub repos and profiles for malware before cloning — commit-pinned risk verdicts for agents. Runs locally from the flagrix npm package. Needs 1 environment variable to run.

not rated 2 1mo ago A tokens not measured original MIT

dugganusa-cli

367

pduggusa/dugganusa-cli

MCP server Claude CodeCodexCursor +2

Local STDIO MCP for DugganUSA threat intel. 1.13M IOCs. Read-only. npm: dugganusa-cli. Runs locally from the dugganusa-cli npm package. Needs 1 environment variable to run.

not rated 2 2mo ago A tokens not measured original MIT

zyrax-guard

368

tiagosilva07/zyrax-guard

MCP server Claude CodeCodexCursor +2

Audit AI agent configs for prompt injection & rogue MCP servers; vet packages. Runs locally from the zyrax-guard npm package.

not rated 2 23d ago A tokens not measured original MIT

promptrejectormcp

369

revsmoke/promptrejectormcp

MCP server Claude CodeCodexCursor +2

Security gateway for AI agents: detects prompt injections, jailbreaks, and common vulnerabilities. Runs locally from the prompt-rejector npm package. Needs 1 environment variable to run.

not rated 2 3mo ago A tokens not measured original ISC

wundervault-mcp

370

wundervault/wundervault-mcp

MCP server Claude CodeCodexCursor +2

Zero-knowledge MCP secrets vault for AI agents: secrets injected at runtime, never seen by the model. Runs locally from the @wundervault/mcp-server npm package. Needs 2 environment variables to run.

not rated 2 7d ago A tokens not measured AGPL-3.0

tablecloth-mcp

371

yourtablecloth/TableClothMcp

MCP server Claude CodeCodexCursor +2

Open Korean e-Gov and finance sites in a clean, disposable Windows Sandbox with security programs. Runs locally from the tablecloth-mcp npm package.

not rated 2 1mo ago A tokens not measured AGPL-3.0

mcp

372

honeylabshq/honeylabs-mcp

MCP server Claude CodeCodexCursor +2

Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints. Remote server at mcp.honeylabs.net.

not rated 2 7d ago A tokens not measured original MIT

veriswarm-mcp

373

veriswarm/veriswarm-sdk

MCP server Claude CodeCodexCursor +2

VeriSwarm MCP Server — Trust infrastructure for AI agents via Model Context Protocol. Runs locally from the veriswarm-mcp Python package.

not rated 2 11d ago A tokens not measured original MIT

privacyscrubber-mcp

374

moxno/privacyscrubber-mcp

MCP server Claude CodeCodexCursor +2

Zero-Trust PII & secrets sanitizer. Locally scrubs data in-memory before sending context to LLMs. Runs locally from the @privacyscrubber/mcp-server npm package. Needs 1 environment variable to run.

not rated 2 5d ago A tokens not measured original MIT

whisper

375

whisper-sec/whisper-cli

MCP server Claude CodeCodexCursor +2

MCP server "whisper" as configured in whisper-sec/whisper-cli. Runs in Docker (ghcr.io/whisper-sec/whisper:0.210.1).

not rated 2 yesterday A tokens not measured original MIT

verification

376

Cybercentry/verification-mcp

MCP server Claude CodeCodexCursor +2

Twelve tools: token, wallet, contract and site security. Two free, the rest $1 in USDC over x402. Remote server at centry.cybercentry.co.uk.

not rated 2 13d ago A tokens not measured original MIT

mcp-code-sanitizer

377

notasandy/mcp-code-sanitizer

MCP server Claude CodeCodexCursor +2

Strict AI code reviewer MCP server powered by Groq — finds bugs, vulnerabilities and security issues. Runs locally from the mcp-code-sanitizer Python package. Needs 1 environment variable to run.

not rated 2 3mo ago A tokens not measured original MIT

vouch

378

notifuturo/vouch

MCP server Claude CodeCodexCursor +2

Check if a counterparty is safe to pay: trust/risk score for AI agents. Scam/phishing screen. Remote server at vouch.futuronoti.workers.dev.

not rated 2 1mo ago A tokens not measured original MIT

supabase-mcp-guard

379

askmeishi/supabase-mcp-guard

MCP server Claude CodeCodexCursor +2

Local policy wrapper for Supabase MCP with macOS Keychain-backed tokens, project allowlists, write locks, and audit logs. Runs locally from the supabase-mcp-guard npm package.

not rated 2 5mo ago A tokens not measured original MIT

linmas

380

TanKimGwan/linmas

MCP server Claude CodeCodexCursor +2

MCP server "linmas" as configured in TanKimGwan/linmas. Runs ./mcp/server.mjs with node.

not rated 2 yesterday A tokens not measured

hackerone

381

ASK191225/bugbounty-kit

MCP server Claude CodeCodexCursor +2

One of 5 in .mcp.json

MCP server "hackerone" as configured in ASK191225/bugbounty-kit. Runs C:\Users\ask92\Downloads\bugbounty-kit\scripts\hackerone_mcp.py with python. Needs 2 environment variables to run.

not rated 2 27d ago A tokens not measured

github

382

adudley78/mcp-audit

MCP server Claude CodeCodexCursor +2

One of 3 in claude_desktop_config.json

Lets the agent work with GitHub: search code, read and create issues and pull requests, and manage repositories through the GitHub API. Runs locally from the @modelcontextprotocol/server-github npm package. Needs 1 environment variable to run.

not rated 2 4d ago A tokens not measured copy · 89% Apache-2.0

custodian-codex-guard

383

KeyArgo/custodian-codex-guard

MCP server Claude CodeCodexCursor +2

MCP server "custodian-codex-guard" as configured in KeyArgo/custodian-codex-guard. Launched with custodian-codex-guard-mcp.

not rated 2 13d ago A tokens not measured original Apache-2.0

yesidleon1393/cybersec-mcp

MCP server Claude CodeCodexCursor

MCP server "cybersecurity-professor-mcp" as configured in yesidleon1393/cybersec-mcp. Runs locally from the cybersecurity-professor-mcp npm package.

not rated 2 3mo ago A tokens not measured

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: