Security MCP Servers

895 servers . page 1 of 18

This page lists 895 MCP servers in the Security category, from 688 publishers. 448 publish a hosted endpoint you can connect to without installing anything, and 262 come from a publisher whose domain has been verified. Sorted by most recent registry activity, 50 to a page.

Servers for security tooling. Some of these read your secret stores, which makes the trust question sharper than for most other categories.

Tick the box on any row to line servers up side by side. Pick two or three, then open the comparison. Servers must share a category for the comparison to mean anything.

Hosting Package
Security MCP Servers
ServerPublisherCategoryPackageVersion
HelpMyAgent Pay-per-call data APIs for AI agents: business, compliance, procurement, VAT and IBAN via x402.helpmyagentSecurityhosted1.5.9
BlackVeil DNS & Email Security Scanner VERIFIEDDNS and email security scanner with 79 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.blackveilsecuritySecurityhosted3.77.0
Go Vulnerability Database Tracker, buy per-query in-session (govulnwatch) VERIFIEDGo vulnerability database: new GO-IDs, CVE aliases, amended advisories for Go deps.a2awireSecurityhosted0.1.0
Delega Delega MCP client. Public hosted access retired July 28, 2026; existing owner credentials only.delega-devSecuritynpm1.19.0
Pretorin Compliance Access Pretorin compliance systems, controls, evidence, and narratives from your AI tools.pretorin-aiSecuritypypi0.29.2
shyn VERIFIEDLocal-first ambient memory for your Mac, pages, meetings, notes, encrypted on-device.shynSecuritymcpb0.5.6-alpha
ComplyEdge TrustLint, offline EU AI Act compliance checks Offline TrustLint checks: EU AI Act Article 5, Article 50, GPAI, plus GDPR and HIPAA.ComplyEdgeSecuritypypi, npm0.2.18
Ofw OurFamilyWizard co-parenting for Claude, messages, calendar, expenses, and journal.chrischallSecuritynpm2.16.0
agentguard MCP policy proxy: spend caps, approvals for destructive tools, kill switch, dry-run, audit log.agentwaresSecuritynpm0.1.3
ReClip Inspect and download authorized media or precise clips locally with yt-dlp.yagyaanshKSecuritypypi0.1.2
Rust Crate Security Advisories, buy per-query in-session (rustsecwatch) VERIFIEDNew RustSec advisories: crate vulnerabilities, malicious crates, unmaintained crates.a2awireSecurityhosted0.1.0
Avala Read Physical AI datasets, projects, fleet and quality data. Requires authorized Avala access.avala-aiSecurityhosted1.0.0
YunoHost MCP Nostr-authenticated MCP server for secure YunoHost administration.imattauSecuritypypi0.8.46
Siftable Siftable MCP server for governed work, knowledge, calendar, people, datasets, and Vault.Tom-R-MainSecuritynpm1.4.0
Pillowfort Private encrypted rooms for agents and people to invite, chat, draw, and play. Local and hosted MCP.slee1996Securitynpm1.1.0
ATTENTIO, darowizny i petycje VERIFIEDPetycje i darowizny Stowarzyszenia Osób Dorosłych z ADHD. Zwraca gotowy adres strony wpłaty.orgSecurityhosted1.0.0
French Rental Compliance VERIFIEDFR/EN tools for French rental, frontalier & home-employment (CCN 3239), sourced, dated answers.adminlandingSecurityhosted1.14.1
Cybersec Toolkit Authorization-gated MCP server to discover and run 670+ security tools for CTF, pentest, and DFIR.26zlSecurityoci1.2.0
MCP VERIFIEDQuery your team's drift, vulnerability, and upgrade data from any AI assistant. OAuth 2.1, 51 tools.vibgrateSecurityhosted2026.907.2
Vaultbeat Apple Health Your AI agent reads your Apple Health data: sleep, HRV, cycle, workouts. Decrypted on your machine.Fino-windSecuritypypi0.7.1
Vaemail Email infrastructure for AI agents: send, authenticate domains, track delivery, diagnose issues.vaemailSecuritynpm1.0.2
Ubuntu Security Notices / USN (usnwatch), buy per-query in-session VERIFIEDUbuntu security notices (USN): Linux kernel & package vulnerability fixes with CVE lists.a2awireSecurityhosted0.1.0
Vizier Deterministic authorization for one proposed AI agent action, returned with a signed receipt.vassiliylakhoninSecurityhosted0.3.0
IntoDNS.ai DNS & Email Security Scanner VERIFIEDDNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.intodnsSecuritynpm1.10.3
CodeInspectus Local-first MCP security scanner and CLI for AI-generated applications.SynvoyaSecuritynpm3.2.0
Dvalincode Deterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.arthurpanhkuSecuritynpm0.19.0
Depot (depot.dev) Read-only MCP server for Depot (depot.dev): CI failure diagnosis, build forensics, and usage.akshayjain3450Securitynpm0.2.0
Agent360 Browser MCP Your AI agent drives a real, logged-in Chrome, test authenticated apps, 2FA flows, scrape logins.Agent360dkSecuritynpm1.29.0
BlueNexus Universal MCP VERIFIEDConnect your AI to all your data - 200+ sources, intelligently filtered, compliance-ready.bluenexusSecurityhosted1.19.1
Sparkforensics MCP server for diagnosing Apache Spark event-log performance issues and comparing runs.shuffle-worksSecuritynpm0.1.0
Site VERIFIEDRight to Work Wizard: the site's own MCP server, checker, enquiry (enquiry = a human handoff.righttoworkwizardSecurityhosted1.0.0
Site VERIFIEDPenetration Testing Cost: the site's own MCP server, enquiry (enquiry = a human handoff, not a.penetrationtestingcostSecurityhosted1.0.0
Site VERIFIEDForensic Accountant Cost: the site's own MCP server, enquiry (enquiry = a human handoff, not a.forensicaccountantcostSecurityhosted1.0.0
Site VERIFIEDFire Compliance Cost: the site's own MCP server, enquiry (enquiry = a human handoff, not a.firecompliancecostSecurityhosted1.0.0
独行录 / opcmenu Find founders, collaboration opportunities and events; manage authorized signups and messages.yzleeSecurityhosted0.5.0
SkillTotal VERIFIEDDeterministic security scan of MCP servers, agent skills and npm/PyPI packages. Runs locally.skilltotalSecuritypypi0.43.1
CrowdStrike MCP Every CrowdStrike Falcon MSP operation, plus a Flight-Control-aware local store that answers.ServositySecuritymcpb0.1.4
Action1 MCP Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations.ServositySecuritymcpb0.1.3
KeibiDrop Give two agents on two machines the same encrypted folder. P2P, no cloud, only read bytes move.KeibiSoftSecuritymcpb0.4.5
Compliance Check VERIFIEDPreview a TCPA/GDPR/CASL/10DLC gate result before spending a paid send. No key needed.hatchloopSecurityhosted0.2.13
Agent Broker VERIFIED23 MCP. compliance, verification, messaging, booking, US contracts. 15 need no key.hatchloopSecurityhosted0.2.13
Agent Decision & Evidence Tools (MCP + x402) 40 MCP. multi-chain RPC, market and transaction decisions, AI, EU compliance and US imports.PatrickPi1312Securityhosted1.6.0
BriefGate Your coding agent asks the client for logos, copy and credentials; BriefGate chases them for you.sekera-radimSecuritynpm0.9.0
Lumethic Photo Verification VERIFIEDVerify photos are real camera captures, not AI: C2PA and RAW+JPEG forensics. OAuth or API key.lumethicSecurityhosted1.1.0
TvojeLajky VERIFIEDInstagram and TikTok services: live CZK quotes, orders and customer-authorized prepaid purchases.tvojelajkySecurityhosted1.0.0
HTTP 401 unauthorized Meaning of HTTP 401.sadri-dridiSecurityhosted1.0.0
Notes Vault Indexed search, schema-checked writes and session hooks for a markdown notes vault.gronareSecuritypypi0.2.6
Guardrail MCP Deterministic preflight checks for credentials, fund transfers, writes, and prompt overrides.kadopiSecurityhosted0.0.1
meek_defoneos_audit_logging_mcp MEEK DEFONEOS Audit Logging MCP, SIEM + audit chain + compliance logs. MIT-licensed.CSOAI-ORGSecuritypypi1.0.1
csoai-governance-crosswalk-mcp Csoai Governance Crosswalk MCP server. query crosswalk, crosswalk bridge, compliance gap anal.CSOAI-ORGSecuritypypi1.0.18

Frequently asked questions

What are security MCP servers?
Secrets management, scanning, identity and compliance They are Model Context Protocol servers, which means an AI client can call their tools directly once connected.
How many security MCP servers are there?
This catalogue lists 890 servers in the Security category, out of 890 in total.
Which security servers work without installing anything?
445 of the 890 servers in this category publish a hosted endpoint, so a client can connect over the network instead of running a local process.
Do security MCP servers need API keys?
Most do. 232 of 890 in this category declare at least one required environment variable, which is roughly 26 percent.
Are these servers official?
259 of 890 are published under a company domain namespace, which confirms the publisher controls that domain. The rest are community published. Neither status means the server has been reviewed for quality or security.
How do I add one of these servers to my client?
Open the server page for the details. Servers with a package are added by putting the install command in your client configuration file. Servers with a hosted endpoint are added by giving the client the endpoint URL.
How is this category assigned?
The MCP Registry does not publish categories, so this catalogue assigns them by matching known product names and topic keywords in each server entry. A server can appear in one category only, chosen by the strongest match.
Where does this data come from?
Server names, descriptions, versions, packages and endpoints come from the official MCP Registry. Repository details come from public source hosts. Nothing here is supplied by the vendors directly.