Skip to content
MCP ThesaurusMCP Thesaurus

Security MCP Servers

Servers for secrets, scanning, auditing and threat intelligence — the guardrails around everything else. The directory lists 195 in this category, of which 85 are hosted remote servers needing no local install. Ranking below reflects maintenance, documentation, install experience and adoption — never payment.

Highest scoring (12)

  1. OpenClaw MCP Server

    Community39/100183

    MCP server bridging Claude.ai/Desktop with self-hosted OpenClaw via OAuth 2.1.

    MITstdioupdated 23d ago

  2. CodeInspectus

    Community81/10044

    Local-first MCP security scanner and CLI for AI-generated applications.

    7 toolsApache-2.0stdioupdated 14d ago

  3. agent security scanner mcp

    Community39/100121

    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

    MITstdioupdated 27d ago

  4. clearfront

    Community77/1008

    OSINT sweep of a digital footprint: breaches, accounts, data brokers, domains and IPs

    30 toolsMITstdioupdated 13d ago

  5. shellward

    Community39/100131

    AI agent security: 7 MCP tools for injection detection, PII scanning, command safety, DLP.

    Apache-2.0stdioupdated 2mo ago

  6. virustotal

    Community39/100149

    MCP server for querying VirusTotal API with comprehensive security analysis tools.

    MITstdioupdated 3mo ago

  7. guardvibe

    Community83/1005

    Deterministic security layer your AI can't be. 462 rules, 39 tools, CLI + doctor + host audit.

    39 toolsApache-2.0stdioupdated 25d ago

  8. 1password

    Community78/10020

    MCP server for 1Password service accounts — tools and resources for vaults and credentials

    Apache-2.0stdioupdated 8d ago

  9. Hive Vault

    Community77/10010

    On-demand Obsidian vault access for AI coding assistants — 17 tools, 5 resources, 4 prompts.

    11 toolsMITstdioupdated 8d ago

  10. shodan

    Community39/100161

    MCP server for Shodan API — device search, IP lookup, DNS, and CVE/CPE queries.

    MITstdioupdated 5mo ago

  11. Vault Cortex

    Community79/10016

    Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1

    MITstdioupdated 7d ago

  12. Solana Security Standard

    Community39/10037

    Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.

    MITstdioupdated 20d ago

  13. See also

More Security servers

agent bom

msaad00

Community

Security scanner and graph for agentic infrastructure — agents, MCP, runtime, and blast radius.

Sep 1, 2026Security
Local service39/10031

grantex

mishrasanjeev

Community

OAuth 2.0 for AI agents — scoped delegation tokens, audit trails, and revocation.

Sep 1, 2026Security
Local service39/10031
Community

Generic markdown vault MCP with hybrid search

Aug 31, 2026Security
Local service39/10031
Community

Stop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm_ tokens.

Aug 31, 2026Security
Local service39/10016

mythos agent

mythos-agent

Community

Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.

May 23, 2026Security
Local service39/10043
Community

MCP server exposing Signet cryptographic signing, verification, and content hash tools over stdio.

May 28, 2026Security
Local service39/10038
Community

Agent-native knowledge OS on Markdown: typed graph, hybrid search, and compiler over MCP.

Jul 27, 2026Security
Local service39/10014

VulnCheck

vulncheck-oss

Community

VulnCheck exploit intelligence — CVE research, exploit data, advisories, and threat analysis.

Aug 26, 2026Security
Local service39/1008

patch tuesday

jonnybottles

Community

Query Microsoft Patch Tuesday security updates (MSRC) with EPSS and CISA KEV enrichment

Aug 12, 2026Security
Remote service75/1004

surf

GeckoVision

Community

Point Gecko at an OpenAPI spec; get first-call-correct, auth-hidden agent tools.

Aug 31, 2026Security
Remote service39/1006
Community

HSM-backed vault secrets for AI agents (JIT fetch) plus prompt-injection and threat scanning.

Aug 31, 2026Security
Local service81/1002

janee

rsdouglas

Community

Secure secrets proxy for AI agents — manages API keys so agents never see raw credentials.

Mar 17, 2026Security
Local service39/10030

Hosted Security servers

These run on the provider’s infrastructure — you connect by URL, with nothing to install locally.

Coach Watts

hdkiller

Community

Remote MCP server for training, nutrition, wellness, and performance data with OAuth 2.0.

Aug 31, 2026Security
Remote service39/10082
Community

55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.

Aug 31, 2026Security
Remote service39/10033
Community3

Sonatype component intelligence: versions, security analysis, and Trust Score recommendations

Jan 14, 2026Security
Remote service59/10073
Community3

AI security scanner for Solidity + free CC0 dataset of Sherlock audit-competition acceptance rates.

Aug 28, 2026Security
Remote service73/1008

hush

royashbrook

Community

A secret store for AI agents: the agent never sees the plaintext.

Aug 14, 2026Security
Remote service39/10020

ScopeGate

alifanov

Community

Permission gateway for AI agents: scoped MCP endpoints over 27 services, audited and revocable.

Sep 1, 2026Security
Remote service39/10015

Questions about Security MCP servers

How many Security MCP servers are there?
This directory currently lists 195 MCP servers in the Security category. The count changes as new servers are published to the official MCP registry, which is re-read daily.
How is the ranking on this page decided?
Order reflects a computed score combining maintenance (commit recency, release cadence, whether the repository is archived), documentation depth, licence and ownership verification, the number of tools exposed, and how many clients have a documented install path. Sponsorship has no effect on it: paid placements appear in separately labelled slots and never inside the ranked list.
Can I use Security MCP servers without installing anything?
Yes — 85 of the Security servers listed here are remote servers. They run on the provider's infrastructure and you connect over HTTP with a URL, so there is no local runtime to manage. The trade-off is that your requests and any credentials pass through a third party.
Which clients can I use these with?
Every entry carries install instructions for the clients we can generate a verified command for, including Claude Code, Claude Desktop, Cursor, VS Code, Codex CLI, Windsurf, Cline, Gemini CLI, Copilot CLI, Zed and Goose. Where a client's syntax cannot be confirmed, no snippet is shown rather than a guessed one.