Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Google Multi Source verified npm
A
mcp-google-multi

Local MCP server for Google Workspace (Gmail, Drive, Calendar, Sheets, Docs, Contacts, Tasks, Meet, Search Console, +Forms/Chat/Admin) across multiple accounts — OAuth-only, encrypted token storage, deny-by-default writes.

Security & Testing Score 97/100 0 findings 110/wk Cap. Moderate
Proof Of Commitment Source verified npm
A
proof-of-commitment

Supply chain security risk scorer for npm, PyPI, Cargo, and Go packages — behavioral signals that can't be faked

Security & Testing Score 97/100 1 finding 106/wk Cap. Moderate
Mitre Source verified npm
A
mitre-mcp

MCP server for MITRE ATT&CK knowledge base - technique lookup, threat intelligence, detection coverage analysis

Security & Testing Score 97/100 0 findings 35/wk Cap. Moderate
Misp Source verified npm
A
misp-mcp

MCP server for MISP threat intelligence platform - IOC lookups, event management, correlation discovery, and intelligence enrichment

Security & Testing Score 97/100 1 finding 34/wk Cap. Moderate
C2pa Source verified npm
A
@c2paviewer/c2pa-mcp

An open-source MCP server that verifies C2PA content credentials and returns LLM-ready provenance verdicts. Built by c2paviewer.com.

Security & Testing Score 97/100 2 findings 26/wk Cap. Moderate
Credentials Broker Source verified npm
A
mcp-credentials-broker

MCP Secrets & Token Broker - A security layer for managing short-lived credentials and tokens

Security & Testing Score 97/100 0 findings 22/wk Cap. Moderate
Pkistudiomcp Source verified npm
A
@pkistudio/pkistudiomcp

Local MCP server exposing PkiStudioJS ASN.1 and PKI key material tools.

Security & Testing Score 97/100 0 findings 20/wk Cap. Moderate
Audit Event Source verified npm
A
@kajaril/audit-event-mcp

Agent steward infrastructure — hash-chained audit log, Merkle notary, and GDPR/AI-Act compliance skill.

Security & Testing Score 97/100 6 findings 18/wk Cap. Moderate
Onlinecybertools Source verified npm
A
onlinecybertools-mcp-server

MCP server that exposes the Online Cyber Tools catalogue (https://onlinecybertools.com) to AI agents as native MCP tools.

Security & Testing Score 97/100 0 findings 17/wk Cap. Moderate
Sirrlock Source verified npm
A
@sirrlock/mcp

Sirr MCP server — lets Claude Code read and write ephemeral secrets

Security & Testing Score 97/100 3 findings 17/wk Cap. Moderate
Apviso Source verified npm
A
@apviso/mcp

MCP server for interacting with APVISO penetration testing platform

Security & Testing Score 97/100 0 findings 16/wk Cap. Moderate
Sapper Ai Source verified npm
A
@sapper-ai/mcp

Model Context Protocol (MCP) security proxy for SapperAI

Security & Testing Score 97/100 1 finding 14/wk Cap. Moderate
Contextlock Source verified npm
A
contextlock

Local-first MCP safety layer that blocks and redacts risky repo context before AI agents see it.

Security & Testing Score 97/100 1 finding 13/wk Cap. Moderate
Agent Ready Kit Remote
A
https://mudko.com/api/mcp

Free 18-check agent-readiness scanner, robots.txt + llms.txt generator, managed agent enablement.

Security & Testing Score 97/100 1 finding Cap. Moderate
Audit Remote
A
https://webmatik.ai/mcp

AI website growth audits: SEO, performance, AI readiness (GEO), conversion, a11y, security.

Security & Testing Score 97/100 0 findings Cap. Moderate
AxioRank — Agent Firewall Remote
A
https://app.axiorank.com/api/mcp-server/mcp

Security gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.

Security & Testing Score 97/100 0 findings Cap. Moderate
Boolsai Scan Remote
A
https://boolsai.ai/mcp

Live tech-stack scan of any public site — vendors, account IDs, scripts, JSON-LD. 2 tools.

Security & Testing Score 97/100 1 finding Cap. Moderate
DataNexus MCP Remote
A
https://datanexusmcp.com/mcp

Public data intelligence for AI agents — CVE, compliance, patents, contracts, domains.

Security & Testing Score 97/100 0 findings Cap. Moderate
Dns Remote
A
https://dns-mcp.blackveilsecurity.com/mcp

DNS & email security scanner — 51 tools for SPF, DMARC, DKIM, DNSSEC, SSL, and more.

Security & Testing Score 97/100 2 findings Cap. Moderate
Evidence Ledger Remote
A
https://saasdossier.com/mcp

Read-only MCP: free OpenAI security evidence ledger (55 fields) + SaaSDossier release register.

Security & Testing Score 97/100 0 findings Cap. Moderate
Exploit Intelligence Platform Remote
A
https://mcp.exploit-intel.com/mcp

Vulnerability and exploit intelligence for AI assistants (370K+ CVEs, 105K+ exploits)

Security & Testing Score 97/100 0 findings Cap. Moderate
GEIANT — Geospatial AI Governance Runtime Remote
A
https://packagesmcp-perception-production.up.railway.app/mcp

EU AI Act compliance for AI agents. Audit trail, delegation certs, and geospatial AI inference.

Security & Testing Score 97/100 0 findings Cap. Moderate
Incisory Remote
A
https://incisory.com/mcp

Audit whether ChatGPT/Gemini recommend a business, with verbatim receipts — then fix and prove it.

Security & Testing Score 97/100 0 findings Cap. Moderate
LaunchTrust Remote
A
https://mcp.launchtrust.co/mcp

Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.

Security & Testing Score 97/100 0 findings Cap. Moderate