Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Fabric Mcp Linux X64 Official npm
A
@microsoft/fabric-mcp-linux-x64

Microsoft Fabric MCP Server - Model Context Protocol implementation for Fabric, for linux on x64

Security & Testing Score 94/100 1 finding 1.1k/wk Cap. High
Pwa Kit Official npm
A
@salesforce/pwa-kit-mcp

MCP server that helps you build Salesforce Commerce Cloud PWA Kit Composable Storefront

Security & Testing Score 94/100 1 finding 1.1k/wk Cap. High
Express Recon Source verified npm
A
express-recon

Inventory & audit harness for Express 4/5 route surfaces — for humans, CI, and AI agents. Statically or at runtime enumerate routes, middleware chains, and flag unauthenticated endpoints.

Security & Testing Score 94/100 4 findings 777/wk Cap. High
Ledd Mcp Audit Source verified npm
A
ledd-mcp-audit-server

MCP server interface for AI agent and MCP security auditing — config analysis, trust audits, prompt injection testing, tool probing, and data flow tracing

Security & Testing Score 94/100 4 findings 485/wk Cap. High
Testingbot Source verified npm
A
@testingbot/mcp-server

TestingBot's official MCP Server for AI-powered testing automation

Security & Testing Score 94/100 1 finding 484/wk Cap. High
Panguard Source verified npm
A
@panguard-ai/panguard-mcp

MCP server for Panguard AI — control security from Claude/Cursor / 透過 Claude/Cursor 控制 Panguard 的 MCP 伺服器

Security & Testing Score 94/100 3 findings 426/wk Cap. High
Getmcpm Cli Source verified npm
A
@getmcpm/cli

MCP package manager — search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf

Security & Testing Score 94/100 7 findings 423/wk Cap. High
Ews Meeting Source verified npm
A
ews-meeting-mcp

MCP server and CLI for scheduling meetings through on-prem Exchange EWS.

Security & Testing Score 94/100 3 findings 420/wk Cap. High
1password Source verified 2 implementations
A
best: @takescake/1password-mcp

MCP server for 1Password service accounts — tools, prompts, and resources for vault and credential management

Security & Testing Best score 94/100 6 findings 405/wk Cap. High
Expo Android Source verified npm
A
@fndchagas/expo-android

MCP server for Android emulator automation via ADB.

Security & Testing Score 94/100 1 finding 267/wk Cap. High
Miftah Source verified npm
A
@lubab/miftah

Wrap any MCP. Use the right account without reconnecting.

Security & Testing Score 94/100 2 findings 196/wk Cap. High
Ms 365 Admin Source verified npm
A
@okapi-ca/ms-365-admin-mcp-server

A Model Context Protocol (MCP) server for Microsoft 365 admin operations via Graph API application permissions

Security & Testing Score 94/100 1 finding 169/wk Cap. High
Codexa Source verified npm
A
@mirnoorata/codexa

Local change evidence, impact review, and verification receipts for developers, CI, and coding agents.

Security & Testing Score 94/100 13 findings 166/wk Cap. High
Code Council Source verified npm
A
@klitchevo/code-council

Multi-model AI code review server using OpenRouter - get diverse perspectives from multiple LLMs in parallel

Security & Testing Score 94/100 4 findings 161/wk Cap. High
Rea Agents Source verified npm
A
rea-agents

Reverse engineer anything from your terminal or agent with one CLI and MCP server.

Security & Testing Score 94/100 14 findings 158/wk Cap. High
Gaffer Sh Source verified npm
A
@gaffer-sh/mcp

MCP server for Gaffer test history - give your AI assistant memory of your tests

Security & Testing Score 94/100 4 findings 130/wk Cap. High
S Gw Source verified npm
A
@s-gw/s-gw

Local credential control for AI coding agents.

Security & Testing Score 94/100 16 findings 118/wk Cap. High
Agentic Sdlc Source verified npm
A
agentic-sdlc-mcp

An MCP Server acting as an Agentic SDLC Control Plane — helps AI coding agents plan, create, test, review, secure, and release software following GitHub Agentic AI best practices.

Security & Testing Score 94/100 2 findings 115/wk Cap. High
Marketing npm
A
marketing-mcp

Read-only agency Marketing MCP — Google Ads, GA4, GSC, Meta, Ahrefs

Security & Testing Score 94/100 2 findings 113/wk Cap. Moderate
Mcpwall Source verified npm
A
mcpwall

Deterministic security proxy for MCP tool calls. Blocks dangerous requests, redacts secrets from responses, catches prompt injection. No AI, no cloud, pure rules.

Security & Testing Score 94/100 2 findings 113/wk Cap. High
Vaultpilot Source verified npm
A
vaultpilot-mcp

Safety first. Hardware-verified DeFi for AI agents — designed for when the AI can be compromised.

Security & Testing Score 94/100 3 findings 91/wk Cap. High
Fusionauth Api Source verified npm
A
@fusionauth/mcp-api

MCP Server generated from OpenAPI spec for fusionauth-api

Security & Testing Score 94/100 4 findings 90/wk Cap. High
Db Access Source verified npm
A
@rheopyrin/db-access-mcp

MCP stdio server that gives AI agents access to Postgres, MySQL, Redshift and SQL Server — with SSH/AWS SSM tunnels and pluggable secret providers (env, Vault, AWS Secrets Manager, RDS IAM).

Security & Testing Score 94/100 3 findings 79/wk Cap. High
Aauth Proxy Source verified npm
A
@aauth/proxy

The user's AAuth agent in MCP form — discovery, identity, interaction relay

Security & Testing Score 94/100 1 finding 72/wk Cap. High