Home / Topics / Security & Pentesting MCP servers

Topic · updated 2026-10-05

Security & Pentesting MCP servers

491 Security & Pentesting MCP servers indexed on awesomemcp.in. Every entry links to a live GitHub repository with a known author, is de-duplicated across the official MCP registry and community lists, and carries an automated vulnerability-check badge. Built by @rad-security, @kontext-security, @sinewaveai, @Pantheon-Security, @qianniuspace and 451 other authors.

491servers
483scan passed
26official
201one-click install

Top 60 Security & Pentesting MCP servers

  1. by @rad-security · official · TypeScript · rad-security/mcp-server

    Query the RAD Security API for Kubernetes and cloud security findings, reports and runtime data.

    Scan passed
    ★ 6
    2026-09-30
  2. Browser automation with browser-use, including a Dockerfile to run Chromium in Docker with a VNC server.

    Scan passed
    ★ 848
    2026-05-20
  3. Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

    Scan passed
    ★ 122
    2026-09-30
  4. Security-hardened NotebookLM MCP with post-quantum encryption

    Scan passed
    ★ 85
    2026-09-03
  5. Audit npm package dependencies for security vulnerabilities with real-time checks against the npm registry.

    Scan passed
    ★ 57
    2025-07-18
  6. Abnormal Security email threats, cases, and reporting in your terminal and your AI agents.

    Scan passed
    ★ 48
    2026-10-03
  7. Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.

    Scan passed
    ★ 38
    2026-09-16
  8. Demonstrates remote attestation of an MCP server running in a Gramine TEE via RA-TLS, so clients can verify the server before connecting.

    Scan passed
    ★ 22
    2026-05-20
  9. by @MadaBurns · TypeScript · MadaBurns/bv-mcp

    DNS and email security scanner with 81 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.

    Scan passed
    ★ 9
    2026-10-05
  10. Security-hardened Chrome automation and logins with post-quantum encryption, a credential vault, memory scrubbing and audit logging.

    Scan passed
    ★ 8
    2026-01-23
  11. Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs

    Scan passed
    ★ 6
    2026-10-05
  12. VMware NSX security: DFW policies and exclusions, groups, tags, Traceflow, IDPS — 22 MCP tools.

    Scan passed
    ★ 4
    2026-10-01
  13. Agent supply-chain security, scanner consensus, x402 reliability, and commerce MCP tools.

    Scan passed
    ★ 3
    2026-09-29
  14. DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.

    Scan passed
    ★ 2
    2026-09-07
  15. Governs what AI agents do: tool calls, SQL, commands, files checked against policy before they run.

    Scan passed
    ★ 2
    2026-10-02
  16. Scan installed MCP servers for security vulnerabilities with 16 detection engines.

    Scan passed
    ★ 2
    2026-04-02
  17. by @GuardBee · TypeScript · GuardBee/guardbee-mcp

    MCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log

    Scan passed
    ★ 1
    2026-10-05
  18. by @GuardBee · TypeScript · GuardBee/guardbee-mcp

    Bundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence

    Scan passed
    ★ 1
    2026-10-05
  19. by @GuardBee · TypeScript · GuardBee/guardbee-mcp

    Triggers GuardBee scans, queries findings, AI-assisted remediation guidance

    Scan passed
    ★ 1
    2026-10-05
  20. Paid hosted MCP for agent-to-agent compute routing. 25% of net revenue funds conservation.

    Scan passed
    ★ 1
    2026-10-02
  21. by @nouchix · TypeScript · nouchix/PQC-Khepra-MCP

    Post-quantum CMMC compliance scanner & AI agent attestation. FIPS 140-3, ML-DSA-65, 36K+ mappings.

    Scan passed
    ★ 1
    2026-10-05
  22. Connect AI assistants to the Rubrik Security Cloud GraphQL API to discover, query, and automate.

    Scan passed
    ★ 1
    2026-10-02
  23. Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.

    Scan passed
    ★ 0
    2026-10-05
  24. by @semgrep · official · Python · semgrep/semgrep

    Scan code for security vulnerabilities using Semgrep.

    Scan passed
    ★ 16,884
    2026-10-05
  25. by @metorial · official · TypeScript · metorial/metorial

    Integration platform connecting AI agents to many services through one interface, with OAuth, scaling and monitoring.

    Needs review
    ★ 3,363
    2026-10-01
  26. by @safedep · official · Go · safedep/vet

    Locally check npm and PyPI packages, such as those suggested by AI coding tools, for vulnerabilities and malicious code.

    Scan passed
    ★ 1,108
    2026-10-05
  27. Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants.

    Scan passed
    ★ 657
    2026-10-05
  28. by @ucsandman · official · TypeScript · ucsandman/DashClaw

    Policy checks, approvals, records, and governed HTTP capabilities for unattended agents.

    Scan passed
    ★ 310
    2026-10-03
  29. by @timescale · official · Rust · timescale/rsigma

    Author, lint, validate and convert Sigma detection rules with RSigma, evaluate and explain detections against log events, and inspect correlation state.

    Scan passed
    ★ 154
    2026-10-05
  30. by @cycodehq · official · Python · cycodehq/cycode-cli

    Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning with Cycode.

    Scan passed
    ★ 99
    2026-10-05
  31. by @mobb-dev · official · TypeScript · mobb-dev/bugsy

    Mobb Vibe Shield identifies and remediates vulnerabilities in human and AI-written code.

    Scan passed
    ★ 69
    2026-08-31
  32. by @snyk · official · TypeScript · snyk/studio-mcp

    Easily find and fix security issues in your applications leveraging Snyk platform capabilities.

    Scan passed
    ★ 55
    2026-09-30
  33. by @panther-labs · official · Python · panther-labs/mcp-panther

    Use Panther's SIEM platform in natural language to write detections, query logs and manage alerts.

    Scan passed
    ★ 47
    2026-10-05
  34. by @swnotmetal · official · TypeScript · swnotmetal/Project-Koma

    Classifies prompt injection, jailbreaks, and out-of-scope user input before agents act on it.

    Scan passed
    ★ 12
    2026-09-27
  35. by @conan-io · official · Python · conan-io/conan-mcp

    Conan C/C++ package manager: create projects, manage dependencies, check licenses and scan for security vulnerabilities.

    Scan passed
    ★ 10
    2026-02-12
  36. Read-only attack-path tools: reachable routes to sensitive assets, and what a fix would cut.

    Scan passed
    ★ 9
    2026-10-05
  37. by @urldna · official · Python · urldna/mcp

    URL scanning and phishing triage: capture DOM snapshots, network requests and screenshots, and hunt historical scans with a custom query language.

    Scan passed
    ★ 7
    2026-08-21
  38. by @sekera-radim · official · TypeScript · sekera-radim/impri

    Impri MCP server — human-in-the-loop approval inbox for AI agents

    Scan passed
    ★ 5
    2026-10-02
  39. by @scalekit-inc · official · TypeScript · scalekit-inc/scalekit-mcp-server

    Manage Scalekit organizations, users and SSO.

    Scan passed
    ★ 5
    2026-09-28
  40. Cryptographic identity, delegation, governance, and commerce for AI agents. 152 tools.

    Scan passed
    ★ 4
    2026-10-03
  41. by @maxfain · official · TypeScript · maxfain/basedagents

    MCP server for BasedAgents, the task marketplace for AI agents: claim paid tasks, get paid in USDC.

    Scan passed
    ★ 2
    2026-10-03
  42. by @alexar76 · official · Python · alexar76/aimarket-mcp

    Stdio + HTTP MCP gateway: SSRF-hardened web_fetch, web_search, metis_verify, market_search.

    Scan passed
    ★ 1
    2026-09-22
  43. by @alexar76 · official · TypeScript · alexar76/argus

    ARGUS-3 stdio MCP with WARDEN firewall: argus_ask, argus_status, argus_capabilities.

    Scan passed
    ★ 1
    2026-10-02
  44. by @kakunin-ai · official · TypeScript · kakunin-ai/kakunin-mcp

    X.509 identity, risk scoring, and audit logging for AI agents. MiCA + EU AI Act compliant.

    Scan passed
    ★ 1
    2026-09-07
  45. by @true-alter · official · TypeScript · true-alter/cli

    Mint an agent identity in two free calls. Verify anyone. Earn 75% when someone reads you.

    Scan passed
    ★ 0
    2026-09-22
  46. by @shieldly-io · official · TypeScript · shieldly-io/mcp

    AI-Powered AWS security analysis: scan IAM policies and CloudFormation for risks and escalation.

    Scan passed
    ★ 0
    2026-07-18
  47. by @thyn-ai · official · Python · thyn-ai/algenta-sdk

    Governed data discovery, exact queries, decisions, simulations, and runtime utilities over MCP.

    Scan passed
    ★ 0
    2026-10-05
  48. by @trustscoreagent · official · TypeScript · trustscoreagent/trustscoreagent

    Check the reputation of AI microservices and public APIs from an open trust registry.

    Scan passed
    ★ 0
    2026-10-05
  49. IDA Pro plugin for binary analysis: decompilation, disassembly and automatic malware analysis reports.

    Scan passed
    ★ 12,480
    2026-09-26
  50. Autonomous reverse engineering with Ghidra: decompile binaries, rename methods and data, and list methods, classes, imports and exports.

    Needs review
    ★ 10,306
    2025-06-23
  51. JADX decompiler plugin providing live, LLM-assisted reverse engineering.

    Scan passed
    ★ 2,853
    2026-09-23
  52. Honeypot framework for building decoy MCP tools that an agent would never use in normal work, to detect prompt injection and malicious agent behavior.

    Scan passed
    ★ 2,191
    2026-10-01
  53. by @vmoranv · TypeScript · vmoranv/jshookmcp

    MCP server for JavaScript analysis, security auditing, browser automation and hooks

    Scan passed
    ★ 2,022
    2026-10-05
  54. AI-powered OSINT agent & MCP server. 20 tools: email, breach, IP, WHOIS, DNS, Shodan, GitHub & more.

    Scan passed
    ★ 1,692
    2026-10-05
  55. MySQL database integration with configurable access controls, schema inspection and security guidelines.

    Scan passed
    ★ 1,399
    2026-08-02
  56. SQL-native query and provisioning engine for cloud infrastructure, served over MCP.

    Scan passed
    ★ 1,065
    2026-10-05
  57. Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server.

    Scan passed
    ★ 780
    2026-10-05
  58. Native Ghidra integration with GUI configuration, logging and no external dependencies.

    Scan passed
    ★ 760
    2026-08-03
  59. Automate reverse engineering of Android APKs with Apktool.

    Scan passed
    ★ 661
    2026-07-02
  60. Local-first memory for AI agents that reaches backward to find a failure's root cause.

    Scan passed
    ★ 645
    2026-10-05

Search all 491 in the interactive index →

Quick install

Add the most popular option to Claude Code:

# see https://github.com/rad-security/mcp-server for setup

FAQ

What is the best security & pentesting mcp server?

By GitHub stars, the most popular is mcp-server by @rad-security (6 stars). awesomemcp.in lists 491 MCP servers for this topic, ranked by official status and popularity.

Are these MCP servers safe to install?

483 of 491 passed our automated vulnerability check (OSV.dev advisories for the published package, OpenSSF Scorecard, license, maintenance and provenance). The check is automated and does not guarantee 100% safety — review the code and permissions before installing.

How do I install mcp-server?

With Claude Code: # see https://github.com/rad-security/mcp-server for setup. Every listing on awesomemcp.in includes an install command and, where available, an mcp.json snippet for Claude Desktop, Cursor and other MCP clients.

Can AI agents read this list?

Yes. The full catalog is available as JSON at https://awesomemcp.in/api/mcps.json and https://awesomemcp.in/api/skills.json, and as plain text at https://awesomemcp.in/llms.txt.

Related topics