Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Kvmfleet npm
A
@kvmfleet/mcp

MCP server for KVM Fleet — let an AI assistant read your fleet, audit log, and compliance state and (opt-in) act on it. Includes curated governance prompts. All calls go through the platform REST API, so RBAC, policy, JIT access, and audit apply.

Security & Testing Score 99/100 0 findings 19/wk Cap. Minimal
Package Verify npm
A
package-verify-mcp

MCP server that verifies an npm package name is real before a coding agent installs it — catching hallucinated ('slopsquat') package names and typosquats of popular packages, with age/downloads trust signals.

Security & Testing Score 99/100 0 findings 19/wk Cap. Minimal
Qastudio Dev npm
A
@qastudio-dev/mcp-server

MCP server for QA Studio - interact with your test management platform from Claude

Security & Testing Score 99/100 0 findings 19/wk Cap. Minimal
Railway npm
A
@crazyrabbitltc/railway-mcp

Railway MCP Server - 146+ tools with 100% Railway API coverage, comprehensive MCP testing framework, and real infrastructure management through AI assistants. Enhanced version with enterprise features, based on original work by Jason Tan.

Security & Testing Score 99/100 0 findings 19/wk Cap. Minimal
Security Scanner 6 implementations
A
best: @rupeshpanwar/security-scanner-mcp

MCP server for comprehensive security scanning of code repositories

Security & Testing Best score 99/100 0 findings 19/wk Cap. Minimal
Iso 27001 Ai npm
A
iso-27001-ai-mcp

AI-powered iso 27001 ai MCP server for agents. Supports audit isms, risk assessment, gap analysis. By MEOK AI Labs.

Security & Testing Score 99/100 0 findings 18/wk Cap. Minimal
Mcp Sandbox Cli npm
A
@mcp-sandbox/cli

Command-line interface for MCP Sandbox - turn any JavaScript module into an MCP server

Security & Testing Score 99/100 0 findings 18/wk Cap. Minimal
Testing Framework npm
A
mcp-testing-framework

Testing framework for MCP

Security & Testing Score 99/100 0 findings 18/wk Cap. Minimal
Twiddle npm
A
@twiddlethumb/twiddle-mcp

Stop your agent twiddling its thumbs — blocking wait_for primitives and semantic UI diffs for the iOS Simulator and Android Emulator

Security & Testing Score 99/100 0 findings 18/wk Cap. Minimal
Ai Agent Ledger Gateway npm
A
@ai-agent-ledger/mcp-gateway

Policy enforcement, tamper-evident audit trail, and kill switch for any MCP server — a drop-in governance proxy

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Cybersecurity Ai 2 implementations
A
best: cybersecurity-ai-mcp

Cybersecurity Ai MCP server. Tools: classify vulnerability, lookup cve, check security headers. Built by MEOK AI Labs.

Security & Testing Best score 99/100 0 findings 17/wk Cap. Minimal
Governance npm
A
@ithena-one/mcp-governance

Governance layer (Identity, RBAC, Credentials, Audit, Logging, Tracing) for Model Context Protocol (MCP) servers.

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Ipqualityscore npm
A
@pipeworx/mcp-ipqualityscore

IPQualityScore MCP — wraps the IPQualityScore fraud-prevention API

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Jwt Base64 Decoder npm
A
@mcp-listing/jwt-base64-decoder-mcp

Secure JWT and Base64 inspection Model Context Protocol (MCP) server. Decode and analyze tokens without exposing sensitive keys.

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Mandatez npm
A
@mandatez/mcp

MCP server for MandateZ — AI agent trust infrastructure via Model Context Protocol

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Qa npm
A
qa-mcp

MCP server for QA engineers to create TestRail test cases from Jira/ADO user stories

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Securitytrails npm
A
@pipeworx/mcp-securitytrails

SecurityTrails MCP — wraps SecurityTrails API (securitytrails.com)

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Shieldnet 2 implementations
A
best: shieldnet-mcp

ShieldNet Security Scanner — MCP Server for AI Agent Security Governance. Scans URLs for XSS, SQLi, SSTI, CORS misconfig, missing headers, info disclosure, and more. Returns ALLOW/WARN/BLOCK governance decisions.

Security & Testing Best score 99/100 0 findings 17/wk Cap. Minimal
Status Global npm
A
status-global-mcp

MCP Server for Status Global — Run web audits and get AI-ready improvement prompts directly from Claude Code or ChatGPT

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Threatfox npm
A
@pipeworx/mcp-threatfox

ThreatFox MCP — abuse.ch indicator-of-compromise feed (free, key required)

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Umami Analytics npm
A
umami-analytics-mcp

Security-first MCP server for Umami analytics (Cloud + self-hosted): set up, analyze, report, and manage your instance from any MCP client.

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Who Am I npm
A
@hyprmcp/mcp-who-am-i

This project is a Model Context Protocol (MCP) server that reports auth information about the current request. It parses the Authorization header as JWT and reports some decoded payload items from the JWT. The name is inspired by the `whoami` coreutils pa

Security & Testing Score 99/100 0 findings 17/wk Cap. Minimal
Agentverus Scanner npm
A
agentverus-scanner-mcp

MCP server wrapper for AgentVerus Scanner (scan SKILL.md via MCP tools)

Security & Testing Score 99/100 0 findings 16/wk Cap. Minimal
Appium Mcp Auth npm
A
@appclaw/appium-mcp-auth

Authentication & authorization for appium-mcp when hosted over SSE / HTTP Stream. Bearer API keys + OAuth JWT, scope-based authorization, per-caller session ownership — built entirely on the appium-mcp Plugin API (no core changes).

Security & Testing Score 99/100 1 finding 16/wk Cap. Minimal