MCP servers for security scanning, vulnerability assessment, and compliance. Integrate security tools and services into your AI workflow.
408 servers available
Identity, trust, and A2A orchestration for autonomous AI agents. Official A2A partner.
Rust MCP server and CLI for Apprise notification fan-out across dozens of delivery backends.
Rust MCP server and CLI for Arcane Docker and container management.
Rust MCP server and CLI for Gotify push notifications and message management.
Rust MCP gateway with Code Mode, authentication, setup, logs, CLI, HTTP API, and operator web UI.
Apprise notifications over MCP and CLI with authenticated stdio and HTTP transports.
Arcane Docker and Compose management over MCP and CLI with authenticated stdio and HTTP.
Gotify notifications and app, client, and message management over MCP and CLI.
Tailscale device, route, DNS, key, user, and ACL management over MCP and CLI.
Rust MCP server and CLI for UniFi Network controller operations.
RMCP runtime for provider-backed agents with CLI, REST, HTTP MCP, plugins, and scaffold support.
Rust MCP server and CLI for Tailscale devices, users, keys, policies, and auth.
Rust MCP server and CLI for UniFi Network controller operations.
Rust MCP server and CLI for Unraid GraphQL, NAS, Docker, VM, and storage workflows.
Governance runtime for compliance: verified, human-approved writes to a tamper-evident record.
Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
Presentations.AI MCP server — create designed slide decks from a topic, text, or document.
Free IPv4 lookups against a distributed attacker-observation corpus.
Safety-first MCP server for Discord with privacy-safe reads, audits, and reviewed administration
MCP server for the SCF Controls Platform — 135 tools for controls, evidence, risk, and TPRM.
OAuth-enabled MyMLH MCP server for accessing MyMLH data.
Extract, search and tag any document: invoices, receipts, contracts, templates. OAuth or API key.
An MCP server for Arcjet - the runtime security platform that ships with your AI code.
Connect to Atlassian Jira, Confluence, and Compass to search, create, and manage your work.
Official Checkmarx MCP Server
OAuth scope approvals and consent receipts for remote MCP servers.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Free catalog and 2,048-character secret-scan preview for Fabler's x402 agent tools on Base.
Every agent action watched, every money-moving one gated, every verdict independently verifiable.
One MCP URL for all your connectors — scoped writes, enforced constraints, and a full audit trail.
Local-first MCP that scores your codebase's build readiness. Your code never leaves your machine.
Run a Japan proxy-buying business from your AI: inventory, orders, buyers, shipping fee split.
Look up independent trust ratings and security, maintenance, and adoption evidence for MCP servers.
Local-first secret scanning, rotation, vault, and audit-log tools for AI agents.
Social intelligence for 8 networks: read posts, creators and trends, then create from them.
Plan, book, and manage business travel.
Your AI meets theirs before you do — private matching for needs, offers, and opportunities over MCP.
Semantic search over free-to-use stock photos from 9 libraries: by words, image, or similar.
The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.
Generate AI UGC video ads from any product URL — avatars, voiceover, OAuth Connect.
A secret store for AI agents: the agent never sees the plaintext.
Personalised developer security learning pathways from SecDim's challenges and courses.
Search Shopify stores, enrich domains, and reveal approved contact channels.
Person-owned AI memory that learns, not just stores — portable context for any MCP client.
Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
SSL/TLS scanning, free Let's Encrypt issuance, and certificate-expiry monitoring.
Detects leaked secrets (API keys, tokens, private keys) in source code.
Local-first MCP server: version-correct library docs, code map, and offline drift for your repo.
Encrypted-first embedded database with vector search and agent memory, exposed as MCP tools
MCP server connecting AI agents to 100+ apps (Gmail, Slack, Notion, GitHub) via one-click OAuth.
Code intelligence MCP server: call graphs, type inference, and symbol search for Python/Go.
Package intelligence MCP for AI agents — 22 tools, 19 ecosystems, AGPL SDK, free.
Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk.
Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step.
Encrypted environment variable vault with AI access policies, keeping secrets safe from AI agents.
Detect prompt injection, jailbreaks, and code injection in untrusted text before it reaches an LLM.
Finds quantum-vulnerable crypto in your codebase: secp256k1, Ed25519, BLS, Schnorr, RSA. Offline.
Runtime security for AI agent commerce. CLI + MCP server blocks hallucinated purchases.
The static analyzer your AI agent reads — fix-ready, machine-readable scan reports over MCP.
Read-focused, prompt-injection-hardened email MCP server for any IMAP provider
Local AES-256-GCM vault for AI agents. Secrets stay local, LLMs never see real API keys.
Security proxy that wraps MCP servers with real-time monitoring and policy enforcement
Security scanner for AI Agent skills, plugins, and MCP servers with A-F grading.
Read-only queries over Aileron audit journals: verify integrity, search recorded tool calls
Guardrailed FHIR access for AI agents: PHI redaction, audit trail, step-up auth, tenant isolation
Google Search Console MCP for analytics, indexing, sitemaps, and SEO diagnostics.
Connect AI agents to multiple Shopify Admin stores for reports, comparisons, and guarded updates.
Search, move, mark, delete and draft your real mail over a self-hosted index.
ARGUS-3 stdio MCP with WARDEN firewall: argus_ask, argus_status, argus_capabilities.
Multi-layer security scanner for MCP servers and agent skills (injection, exfiltration)
Permission gateway for AI agents: scoped MCP endpoints over 27 services, audited and revocable.
Fail-closed, read-only PostgreSQL and MongoDB access for AI agents over MCP.
Unified threat intel - OTX, AbuseIPDB, GreyNoise, abuse.ch, Feodo Tracker
AI pentester for PRs — finds exploitable bugs and hands your developer agent the fix.
A secured scoped SSH MCP server for executing safe read-only diagnostic DevOps / SysOps commands
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Audit Make.com blueprints before importing: hardcoded secrets, dangling refs, risky settings.
Governed MCP workflows with policy validation, findings tracking, and review gates.
Stop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm_ tokens.
Audits any website for AI agent readiness and safety, scoring prompt injection risk and llms.txt.
Agent-native collaboration network: orchestrate a team of long-running agents from any MCP client.
Security analysis for Aiken smart contracts on Cardano. 75 vulnerability detectors.
Offline deterministic engineering-trust certificates for repositories, with no telemetry.
Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.
Multi-account tool broker for AI agents — CLI and MCP.
Prompt-injection firewall for AI agents — scan untrusted text before LLM calls.
Read-only breach intel, full history 2007-today: reports THAT an org was breached, never the data.
iptables for MCP — blocks dangerous tool calls, scans for secrets, logs everything.
Zero-knowledge encrypted storage for humans and AI agents. Client-side AES-256-GCM, EU-hosted.
Pre-transaction token risk checks for autonomous agents on six chains. Read-only; paid via x402.
MCP server to mount and unmount VeraCrypt containers with secure stdin password handling.
OAuth 2.1/OIDC resource-server reference for secure MCP authorization
MCP server for Shodan API — device search, IP lookup, DNS, and CVE/CPE queries.
MCP server for querying VirusTotal API with comprehensive security analysis tools.
Scan an MCP server or agent config for injection, exfiltration, and risky capabilities.
Reddit Ads API v3: campaigns, ad groups, ads, reports, plus working writes with safety tiers.
MCP server for Kalshi prediction markets: native RSA-PSS auth, rate limiting, demo/prod safety.
MCP server for credential isolation — bots use passwords and API keys without seeing them
Security-first SendGrid MCP server: dry-run default, recipient allowlists, rate caps, audit log.
An MCP server that provides LinkedIn & Reddit data
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.
The WAF for agents. Pattern-based + heuristic firewall scans prompts, RAG documents, tool argume...
Cybersecurity Ai MCP Server by MEOK AI Labs
MITRE ATLAS — Adversarial Threat Landscape for AI Systems. Tactics + techniques for attacking AI...
Owasp Agentic MCP Server by MEOK AI Labs
Software Bill of Materials generation + validation in CycloneDX 1.6 and SPDX 2.3 formats. Requir...
Scam Detector MCP Server by MEOK AI Labs
Security Scanner Ai MCP Server by MEOK AI Labs
Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Pay-per-call x402 gateway: agent tools, OpenAI-compatible LLM, market data, RPC, security audits.
WAF security testing: 5,500+ payloads, 25 WAF fingerprints, 21 recon checks, bypass AI
Unofficial Google Ads MCP for campaigns, keywords, budgets, and gated mutations.
Privacy-first unofficial Google Health API v4 MCP server for health, sleep, activity, HR agents
Local-first TikTok Content Posting API for AI agents: OAuth checks, dry-run and live uploads.
Agent-first YouTube Shorts uploader: dry-run validation, OAuth checks, synthetic-media metadata.
Real-time semantic security for AI coding agents and MCP tools
Intent-bound action authorization for AI agents: policy, human approval, and a signed audit trail.
Local supply-chain CVE scanner via OSV/NVD. Scans deps and IDE extensions. No upload.
Translates a lockfile diff into a human-readable upgrade plan for npm and PyPI.
Secure secret management with a Human-In-The-Loop (HITL) interceptor for agent mutations.
A security-focused MCP server for self-hosted n8n Community Edition.
Official DSers MCP for dropshipping: import, edit, price, and publish products to Shopify and Wix.
Self-hosted MCP gateway. Turn any REST API into MCP tools via YAML (DADL). Authz, audit, policies.
Dead code, security, secrets detection and code quality for Python, TypeScript, Go.
MCP server for Reolink cameras: snapshots, device state, AI detection, PTZ, and deterrence controls
PostgreSQL MCP wrapper with .env credential mapping, tool selection, and safe read-only defaults.
MCP marketplace with 8,845 security-audited skills. 9-layer Sentinel audit + ATC trust cards.
Deterministic cross-repo contract analysis for AI agents: frontend calls vs backend endpoints.
Structural similarity-based code filter. Stops malicious code pattern reaching execution tools.
Trust score for AI-generated code: scan repos, guard agent file writes, get a 0-100 score.
Local GitHub Actions/CI maintenance check (action pinning, token perms). Not a full security audit.
Detects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.
Scan agent skills and MCP servers for malicious patterns before you load them
Exact-action approval for consequential agent actions: request, track, and verify signed receipts.
Guardian layer for AI agents: identity, secrets, audit via MCP.
Read-only OctoWatch DLP Cloud MCP: risks, idle time, productivity, monitoring.
Deterministic payment policy guardrail for AI agents - budgets, allowlists, signed mandates.
Read Proton Mail, extract bounded attachment text, and create explicitly confirmed drafts.
Encrypted environment variable vault with AI access policies, keeping secrets safe from AI agents.
Real-time Python package and vulnerability data for AI coding agents.
Scan GitHub repos and profiles for malware before cloning — commit-pinned risk verdicts for agents
Execution engine for AI agents. 412 modules: browser, file, Docker, data, crypto.
Your office's procedures inside Claude or ChatGPT - verified citations or an honest refusal.
AI job search MCP — fact-checked jobs, application tracker, alerts. ChatGPT, Claude, Cursor.
Encrypted local ledger of structured user state, shared across every MCP-aware AI tool.
A verified dependency-audit verdict any AI agent can call over MCP, not a raw scan.
MCP server bridging Claude.ai/Desktop with self-hosted OpenClaw via OAuth 2.1.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Draft, translate and update Help Center articles and manage Zendesk tickets from your AI assistant.
Full-featured ADB MCP server — 209 tools across 49 modules, from UI to baseband.
Policy review and purchase discovery for AI-agent commerce actions.
Local-first AI memory engine — 4-tier memory, people graph, Bayesian beliefs. Encrypted, 62µs.
Security scanner for AI agent skills and MCP servers
Scan skills, MCP configs, and agent content for injection and supply-chain risks. Offline, no LLM.
MCP proxy adding security scanning, behavioral profiling, risk gating, and safe tool call execution.
AWS security scanner with attack chain detection, IAM privilege escalation, and fixes
Precision-first security scanning for Model Context Protocol servers.
Credential isolation for AI agents. Inject secrets at the network boundary.
MCP package manager with trust scoring, a runtime guard, and Sigstore provenance verification.
Deterministic security layer your AI can't be. 462 rules, 39 tools, CLI + doctor + host audit.
Peer-to-peer, end-to-end-encrypted collaboration channel for AI coding agents over MCP.
Run AI-driven web-app and API security scans (DAST) from Claude or any MCP agent. Windows.
EU-hosted website monitoring + 17-framework compliance MCP. One anonymous tool, four authenticated.
Audit any MCP server's security & quality — OWASP MCP Top 10 + explainable 0-100 MCP Score
Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.
The smart memory layer for everything Ai. 95.10% LongMemEval (highest published).
MCP wrapper for Yad, a local browser-automation companion, for coding agents.
Webhook signature-verification audit. Stripe, GitHub, Shopify, Twilio +17. Local. Deterministic.
Open Identity Standard for AI Agents — DID, Agent Cards, delegation, reputation, payment & escrow
Quantum-inspired keyring for AI coding agents with superposition, entanglement, and tunneling.
Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402.
Govern your backend control plane from your AI agent - signed, human-approval-gated.
Security co-pilot for AI agents. Scan for vulnerabilities, audit MCP servers, verify governance.
The agent eval standard for MCP. Score every agent output for quality, safety, and cost.
Sandboxed shell exec for MCP clients: run untrusted agent commands in a gVisor container.
Write secrets into .env without the agent ever seeing the value - Windows masked dialog (繁中 UI)
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.
Verifiable action logs for AI agents. Every action is recorded in a SHA-256 hash chain.
Query Microsoft Patch Tuesday security updates (MSRC) with EPSS and CISA KEV enrichment
Query a verified document collection: passages that answer a question, with their source.
19 tools + 5 resources for ServiceNow: CMDB, update sets, tables. OAuth 2.1. Tokyo+, PKCE SanDiego+
Agent-first secrets vault. Store, rotate, and share credentials from chat. 20 tools.
Pre-tool policy enforcement + JSONL audit for AI agents. Apache 2.0.
45 judges that evaluate AI-generated code for security, cost, and quality with built-in AST.
Security suite for AI agents: flag drains, permit-phishing & risky actions before signing.
An open-source API for collecting and managing contacts and signups.
MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
MCP runtime security proxy. Blocks dangerous AI agent tool calls with a policy engine.
Kubernetes MCP server with RBAC-style, context-scoped guardrails for AI agents.
Administers Linux via typed, approval-gated actions with an Ed25519-signed audit trail.
Context-aware secret scanner: lets an AI agent scan, verify, and rewrite secrets before committing.
Verify-before-act safety checks for AI agents: packages, lockfiles, manifests, CI workflows.
Microsoft Outlook MCP server — 20 tools for email, calendar, contacts, and settings via Graph API.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
MCP server to scan smart contracts on Base for honeypots, rug pulls, and vulnerabilities.
End-to-end encrypted access to a Standard Notes vault (protocol 004, local stdio only).
SSH & Kubernetes access broker for AI agents; the model never touches a credential.
Bounded local MCP access to one approved repository for AI read/search and structured handoffs.
Control plane MCP that dedups scanner output, rate-limits hosts, and runs non-destructive proofs.
MCP server for the ESET ecosystem - Connect cloud + PROTECT On-Prem, multi-tenant, RO/RW
Real-time threat intel for AI agents: 890K+ IOCs incl. prompt-injection & AI-skill threats
Real-time Firestore schema context for AI coding agents. Stop hallucinating field names.
Runtime proxy for MCP security, cost governance & audit
Explain any lockfile or workflow-pin change: bumps, vulns, ages, deprecations — 61 formats
npm/PyPI dependency upgrades: package security, compatibility, target ranking, and migration plans.
Durable agentic memory, encrypted at rest. Fully offline: no network, no API key, no cloud.
Load OpenAPI 2.x/3.x specs and expose generic tools to discover and call multiple APIs.
Real-time DNS security analysis — DNSSEC, email auth, and RDAP. Built for SOC investigations.
Security proxy that automatically wraps MCP servers with real-time monitoring and policy enforcement
Security scanning and threat detection for AI agents
Branchable LLM history DAG + encrypted context capsules agents can save, restore, and crypto-shred.
Official Lumail email marketing MCP for campaigns, subscribers, and workflows.
Zendesk MCP server for Claude Code and other MCP clients
MCP server for secureFlows (secure-flows.com). Alias of io.github.michal-lefler/secureflows-mcp.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
SQL over real-world data — FDA, SEC, blockchain, genomics, CVEs, and more. No config.
Use Strava's official MCP from Codex and other local stdio clients without a developer app.
OAuth 2.0 for AI agents — scoped delegation tokens, audit trails, and revocation.
Code security scanner for AI agents. 45+ vulnerability patterns, AST analysis, Solana micropayments.
Full Google Sheets MCP: 26 tools + run_sheets_script escape hatch. User OAuth, no service account.
Solana token safety for AI agents — rug-pull, honeypot & Token-2022 trap detection before you buy.
Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.
Read-only network & security recon tools (DNS, TLS, headers, CORS) for AI agents, each graded.
Local secret & credential checks for AI-assisted dev — runs on your machine, results redacted.
SQLite MCP server with OAuth 2.1, HTTP/SSE, 122 tools, and smart tool filtering
Serve a secret to an agent exactly N times from locked RAM, then wipe it and self-destruct.
Independent A-F trust grade for any MCP server, watched for drift. Free, never for sale.
MCP server for GreyNoise API - Check if IPs are internet background noise or targeted attacks
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.
MCP tools from three.ws: free + paid text-to-3D, rigging, agent reputation, market intel.
3D AI Agent Avatar — render any GLB, give it a Solana wallet, a voice, and pump.fun powers.
Trending agents and coins, the $THREE holder leaderboard, and the site-wide activity ticker.
Browse the AgenC on-chain task marketplace, query the agent registry, and link identities.
Self-custodial pump.fun sniper: arm strategies, snipe, manage positions. Simulate by default.
Governed x402 payment sessions: pay any endpoint with budget, allowlist & per-tx caps, no key.
Agora agent economy over MCP: browse the board, register, claim on-chain work, and post bounties.
Create, update, and delete pump.fun alert rules and read fired-alert history across channels.
Alibaba Cloud DashScope MCP: Qwen chat, embeddings, and model discovery on your own account.
Generate a paste-ready embed for a floating 3D avatar chatbot on any website.
Text-to-speech, speech-to-text, audio-to-face lipsync, and motion-capture clips for 3D agents.
Set autopilot scopes and a daily SOL spend cap, then propose, execute, and undo agent actions.
An agent's account economics — plan quotas, metered usage, invoices, receipts, and earnings.
List LLM providers and run chat completions through the three.ws multi-provider router.
Play three.ws Coin Clash — read the faction battle board and leaderboard, enlist, and rally.
Ask any website's AI concierge a grounded question, and generate the embed to add one to a site.
Manage copy-trade follows — follow leaders, tune sizing and guard rules, and track fees owed.
Generate Ethereum wallets with BIP39 mnemonics, HD paths, vanity addresses, private key backup
IBM watsonx.ai MCP by three.ws: chat, text generation, embeddings, and tokenization.
x402 pay-per-use IBM Granite AI: chat, code, embeddings, analysis, forecasting. Pay USDC per call.
Pay-per-use IBM Granite AI via x402: chat, code, embeddings, forecasting. USDC on Base or Solana.
Coin smart-money scores, wallet reputation, signal feeds, and KOL leaderboards.
Encrypt/decrypt Ethereum keystore JSON V3 with scrypt/PBKDF2 for secure cold storage
Per-wallet KOL deep dive — a tracked trader's portfolio P&L and its trades on a given mint.
Browse the community 3D-creation gallery, fetch a creation with its viewer URL, and submit it.
Browse and discover the public three.ws agent marketplace and skills catalog. Read-only.
Deploy AI agents on-chain on Solana with an EIP-8004 identity. Deploy fee funds $THREE buybacks.
On-chain identity for AI agents: resolve .sol names, reverse-lookup wallets, check handles.
Read the inbox, mark items read, manage delivery preferences, and register Web Push devices.
An agent's trading state — portfolio value, PnL, live balances, trade feed, and signed transfers.
Append-only, signed, on-chain-verifiable agent action log — record and audit what agents did.
Free, read-only pump.fun + Solana MCP: token discovery, on-chain analysis, SNS, 3D snapshots.
Compose a placed 3D diorama from one sentence, export a forged world, browse saved scenes.
Discover signal feeds ranked by proven edge, rank publishers, and subscribe + track results.
Sign Ethereum messages - EIP-191, EIP-712 typed data, Permit2, signature verification and recovery
Price, hold, and burn $THREE on Solana — the first MCP server whose actions burn a token.
3D avatars, embeds, glTF tools, agent memory, and on-chain agent identity from three.ws.
Turn text or an image into an animation-ready 3D model (GLB): generate, rig, animate, retexture.
Free text/image → 3D: generate, rig, avatar-ify, and refine GLB models. No auth, no payment.
Give your AI agent an x402 wallet: discover and pay for services in USDC, or earn from your own.
three.ws 3D avatars in your agent: render a live, interactive 3D avatar inline, or get an embed.
Free pump.fun and Solana token discovery and on-chain analysis tools, by three.ws.
Discover and price paid agent services across the live x402 network, by three.ws.
Build and sign Ethereum transactions - EIP-1559, gas estimation, RLP, ERC-20 transfers
Read a Pay-As-You-Learn tutoring session's itemized tab and close it for an attested invoice.
Validate Ethereum addresses, keys, checksums, keccak256 hashes, function selectors, ENS
Read the three.ws vanity-address market: quote difficulty + USDC price, browse the board.
Image understanding for AI agents — analyze and describe any image via the three.ws pipeline.
Pay any x402 endpoint on the open web: auto-paying bridge with Bazaar discovery and spend caps.
Self-custodial x402 wallet for AI agents: pay any service in USDC or $THREE from your own key.
Extract regular expressions from code, each with a ReDoS safety verdict.
Detect hardcoded secrets in source and config. Reports masked previews, never the values.
Dependency vulnerability scanner with EPSS scoring. 9 MCP tools. Free tier + x402.
Aggregate multiple MCP backends behind a single stdio endpoint with namespaced routing.
Secure MCP SSH automation server with policy controls, resources, prompts, stdio, and HTTP.
Zero-trust MCP security proxy with policy enforcement, PII scrubbing, approvals, and audit trails.
Secure MCP SSH automation server with policy controls, resources, prompts, stdio, and HTTP.
AI URL safety validator: SAFE/SUSPICIOUS/DANGEROUS verdict, trust score, threat intel.
Zero-auth research MCP: web, academic, finance, news, weather, macro, social, SEC. No keys.
AI-powered OSINT agent & MCP server. 16 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.
12-layer security configs for AI coding agents. Autonomous purchase via x402 (USDC on Base).
The bridge from K2 agents through Wrangler to your master AI - safe, approval-gated Cloudflare ops.
Security-first MCP gateway for Odoo 17/18/19 — YAML-driven security, 27 tools
Retired, superseded by google-health-mcp. Fitbit Web API shuts down 30 Sept 2026.
Read-only MCP server for the Monzo banking API: OAuth, local transaction cache, spending analysis.
MCP server for the Withings Health API with OAuth, local SQLite cache, and trend analysis.
Typed on-prem knowledge graph for AI agents — read-only for humans, write-only for agents via MCP.
Persistent, encrypted, deterministic memory for AI agents. Local-first, 173 canonical tools.
Security gate for agent-driven WhatsApp: allowlist, secret scan, rate limit, audit log.
Supply chain risk scoring for npm, PyPI, Cargo, and Go. 9 tools. Behavioral signals.
Zero-knowledge persistent memory for Claude — encrypted, semantic search, EU hosted.
Read-only IBM MQ diagnostics for AI agents. Cited root cause, never destructive.
MCP server exposing Signet cryptographic signing, verification, and content hash tools over stdio.
MCP server for creating and managing SOPS-encrypted secrets
Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.
Zero-dependency Web Crypto & AI Agent MCP Server (AES-256-GCM, RSA-4096, PQC, Signatures).
Portable workspaces for AI agents: one encrypted link any agent can read and write
Fail-closed action authorization, MCP risk scanning, x402 checks, and signed receipts.
MCP server for Alert Logic MDR — incident response, log search, SOAR, and SOC workflows
Community extension of CrowdStrike falcon-mcp with near-complete Falcon API coverage
Full Qualys portal management over MCP: VMDR, PC, WAS, Cloud Agent, Container Security & more
MCP server for Sophos Central — endpoint security, XDR/MDR, and MSSP multi-tenant ops
HTTP client, JWT decode, header analysis for AI agents
License check, outdated deps, security for AI agents
MCP server for encrypted SQLite databases (SQLCipher 4) - Works with MoneyMoney, KeePass and more
MCP server for SQLCipher 4 encrypted SQLite databases with full CRUD operations and query support
Scan code for Korean compliance risks — PIPA/개인정보보호법, Network Act, Credit Info. Not legal advice.
Hosted CVE + bug-bounty-mechanic MCP: exploitation-first ranking, CVE fact-check, mechanic transfer
Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.
Security, cost, and health governance proxy for MCP infrastructure
Wraps the ShimGuard CLI as a single generic MCP tool for agent-shim provenance checks.
Security scanner for third-party AI agent-skill files (SKILL.md, hooks, scripts) via MCP.
Wraps the truesignal CLI as a single generic MCP tool for threat/connector status checks.
Scan, enumerate, and risk-score every MCP server configured on your machine.
Check the danger grade of any public MCP server before you connect.
Protect your AI agents and IDEs from malicious open-source packages.
Local-first memory for AI agents that reaches backward to find a failure's root cause.
Discover mobile app attack surfaces via BeVigil OSINT — hosts, subdomains, URLs, and more.
Security for AI agents: MCP audits, secret redaction, skill vetting, network scans, agent checkout.
Open-source MCP proxy for AI agent access control with CEL policies, RBAC, and audit.
Weavatrix Online extension: guarded sync, advisories, malware review, architecture contracts.
Keep credentials out of AI coding agents with local approvals, scoped injection, and audit trails.
Security scanning for websites, public repositories, and Open CLAW skills.
Stdio-to-HTTP gateway — connects MCP clients to remote HTTP MCP servers
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Security-first MCP server for reverse engineering, malware analysis, forensics, and SAST.
Email infrastructure and authentication for developers: domains, inbox routes, auth apps, deploys.
MCP tools for testing mobile and TV apps on iOS simulators, Android phones, and Apple/Android TV.
Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants.
AI-powered OSINT agent & MCP server. 16 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.
Security scanner for MCP servers. SSRF, path traversal, injection, auth, secrets. Grade A-F.
ZKshare stdio MCP: store/prove/share, semantic search, sandbox proxy to HTTPS /api/v1/context.
Deterministic guardrail your coding agent runs on itself: diff-scoped findings, zero LLM tokens.
Merged agent permission rules: which settings file wins, and which rules your client ignores.
Static analysis scanner for MCP server code and multi-tenant SaaS applications.
Deterministic no-LLM MCP server that scrubs secrets before they reach an agent. Never leaks values.
Audit agent skills/prompts against 8 supply-chain attack patterns. Deterministic, no-LLM scanner.
Pre-execution safety for AI agents on Base. Guard a token, tx or address: block/review/clear.
Web search, news, page retrieval, sitemaps, and trending topics through Search1API.
Local-first MCP security scanner and CLI for AI-generated applications.
Guest check-in and SES.HOSPEDAJES status for short-term rental hosts. No guest PII exposed.
Read-only Shipcheck launch-risk scans for authorized JS, TS, and MCP repos.
Vet third-party AI agent extensions + agent-config files (AGENTS.md, .cursor/rules, CLAUDE.md).
Security-first MCP server that connects any OpenAPI, GraphQL, gRPC or SOAP API to AI agents.
Threadlinqs threat-intelligence MCP — 49 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
The dependency bloodhound for AI coding agents. Zero API keys, zero config.
Detects catastrophic-backtracking (ReDoS) regex risk via AST parsing, with JS-safe rewrites.
Self-hosted WordPress MCP server with per-capability permission controls and a full audit log.
Security audit for docker-compose.yml — 25 checks: secrets, privileges, network, volumes, images.
Hadolint-grade Dockerfile audit — 19 checks: secrets, privileges, supply chain, hygiene.
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
Four IaC audits in one call: Compose, Dockerfile, GitHub Actions, Kubernetes. 131 checks.
kube-linter audit for Kubernetes manifests — 63 checks: security, availability, RBAC, network.
Security middleware for MCP. Blocks prompt injection, PII leakage, and resource exhaustion.
Deterministic, zero-token security scanner your AI agent calls to find and re-verify issues.
Charter-bound defensive security copilot: secrets, obfuscation, deps, Dockerfile, IaC scans.
Query trust scores for MCP servers and agent skills. Check if a tool is safe.
Scans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it.
VMware NSX security: DFW policies and exclusions, groups, tags, Traceflow, IDPS — 22 MCP tools.
Memory for AI agents: persistent L1/L2/L3, web-search savings, thread memory.
VulnCheck exploit intelligence — CVE research, exploit data, advisories, and threat analysis.
MCP server for Front: conversations, contacts, messages, tags, and inbox workflows.
Weavatrix Online extension: guarded sync, advisories, malware review, architecture contracts.
The internet's infrastructure graph for AI agents - 46B nodes and edges, free trial via 2 HTTP calls
One firewall and password manager for all your AI coding agents' MCP servers and secrets.
Zero-knowledge MCP secrets vault for AI agents: secrets injected at runtime, never seen by the model
MCP server for Blumira SIEM — query findings, evidence, and detection data via the Blumira API.
MCP server for Huntress — accounts, organizations, agents, incidents, and reports.
Multitenant Streamable HTTP wrapper for the SentinelOne purple-mcp server.
MCP server for ThreatLocker — zero-trust endpoint protection, allowlisting, and policies.
MCP server for Blumira SIEM — query findings, evidence, and detection data via the Blumira API.
MCP server for Huntress — accounts, organizations, agents, incidents, and reports.
Multitenant Streamable HTTP wrapper for the SentinelOne purple-mcp server.
MCP server for ThreatLocker — zero-trust endpoint protection, allowlisting, and policies.
End-to-end-encrypted, sovereign inbox for AI agents. The server only ever sees ciphertext.
Cybersecurity MCP server: 323 prompts + 7 workflows for red team, blue team, SOC, cloud, OSINT.
Read-only access to secrets in a local KeePassXC vault. Runs commands with them injected.
Read-only MCP server for the OrchestKit docs: full-text search + Markdown fetch. No auth.
AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
VMware NSX security: DFW policies, security groups, tags, Traceflow, IDPS — 21 MCP tools.
AI writes. SPARDA proves. Deterministic, offline security gate for AI edits.
Trust scoring for MCP servers, AI skills & npm packages — 15 signals + safety scanning.
Official PicSee MCP server for short links, link management, click analytics, and optional OAuth.
Security sidecar for MCP servers: prompt-injection scan, Ed25519 verify, tools/list drift. 10 tools.
MCP conformance test harness. JSON-RPC, OAuth 2.1 PKCE, schemas, smoke, annotations. CLI + lib.
Ed25519-signed MCP tool manifests + spawn attestation. Layer-2 supply-chain hardening.
Defense-in-depth for MCP stdio servers: shell-injection guard, AST audit CLI, RCE blocking.
Store, retrieve, and pin encrypted files on IPFS via MCP tools for AI agents and workflows
AgentGuard — 20-tool AI safety MCP: policy preflight, risk scoring, audit logging, rate limits.
Daily Ed25519-signed security intelligence for AI-agent stacks; CVEs & advisories, paid via x402.
Give AI agents secure access to ZERNO project briefs, tasks, and context over remote MCP.
Issue, rotate and revoke scoped API-key passes for 25+ providers — the agent never sees a real key
Ask your AI about bank accounts, spending, debts, holdings, and investment activity.