Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Sint Source verified npm
A
sint-mcp

SINT MCP — Security-first multi-MCP proxy server with policy enforcement

Security & Testing Score 94/100 4 findings 12/wk Cap. High
Security Proxy Cli Source verified npm
A
@0disoft/mcp-security-proxy-cli

Deny-by-default local stdio proxy and policy inspection CLI for MCP servers.

Security & Testing Score 94/100 3 findings 11/wk Cap. High
Vex Source verified npm
A
vex-mcp

A transparent MCP security proxy: inspects tool descriptions for injection, pins tool definitions to detect rug-pulls, enforces a default-deny capability policy, and writes a tamper-evident audit log.

Security & Testing Score 94/100 1 finding 9/wk Cap. High
Slack Crunchtools PyPI
A
mcp-slack-crunchtools

Secure read-only MCP server for Slack workspaces

Security & Testing Score 94/100 1 finding Cap. Moderate
Lsp npm
A
lsp-mcp-server

MCP server bridging Claude Code to Language Server Protocol servers

Security & Testing Score 93/100 1 finding 2.8k/wk Cap. High
Works Source verified npm
A
@muggleai/works

Ship quality products with AI-powered E2E acceptance testing that validates your web app like a real user — from Claude Code and Cursor to PR.

Security & Testing Score 93/100 8 findings 2.2k/wk Cap. High
Envmcp npm
A
envmcp

A lightweight way to use environment variables in your Cursor MCP server definitions.

Security & Testing Score 93/100 1 finding 1.7k/wk Cap. High
Nexus Flow npm
A
@nexus-flow/mcp

Runner shim: fetch, verify (sha256 + minisign), cache, and exec the signed nxs binary as an MCP server for hosts where nxs is not installed.

Security & Testing Score 93/100 1 finding 1.6k/wk Cap. High
Wrongstack npm
A
@wrongstack/mcp

WrongStack Model Context Protocol client and registry: stdio, SSE, and streamable HTTP transports.

Security & Testing Score 93/100 1 finding 1.5k/wk Cap. High
Secure 2 implementations
A
best: mcp-secure-server

Secure-by-default MCP server with 5-layer validation for defense-in-depth protection

Security & Testing Best score 93/100 6 findings 1.2k/wk Cap. High
Cypress npm
A
cypress-mcp

MCP server for AI-driven Cypress test execution. Run, debug, and iterate on E2E tests directly from your AI agent.

Security & Testing Score 93/100 1 finding 1.1k/wk Cap. High
Ripgrep npm
A
mcp-ripgrep

An MCP server to wrap ripgrep

Security & Testing Score 93/100 3 findings 1.0k/wk Cap. High
Warden Source verified npm
A
@icoretech/warden-mcp

Vaultwarden/Bitwarden MCP server backed by Bitwarden CLI (bw).

Security & Testing Score 93/100 4 findings 904/wk Cap. High
Nsauditor Ai npm
A
nsauditor-ai

Modular AI-assisted network security audit platform — Community Edition

Security & Testing Score 93/100 10 findings 902/wk Cap. High
Bitwarden npm
A
@bitwarden/mcp-server

Bitwarden MCP Server

Security & Testing Score 93/100 2 findings 760/wk Cap. High
Webability npm
A
@webability/mcp

WebAbility MCP server — WCAG 2.2 / ADA / EAA accessibility scanning with three-tier confidence output (issues + incomplete + summary), framework-aware AI fix suggestions, and brand-palette contrast checks. For Cursor, Claude Code, and other IDEs.

Security & Testing Score 93/100 3 findings 616/wk Cap. High
Ghostlight npm
A
ghostlight

Governed browser automation over your own authenticated Chromium session, for AI coding agents. Thin npm launcher for the ghostlight binary.

Security & Testing Score 93/100 1 finding 592/wk Cap. High
Capxul npm
A
@capxul/mcp

Capxul MCP server — agent-facing financial-ops tools (auth, account readiness, balances, testnet faucet, payments) exposed over Streamable HTTP with OAuth bearer auth and a dev-mode custody gate.

Security & Testing Score 93/100 2 findings 556/wk Cap. High
Npmplus npm
A
npmplus-mcp-server

Production-ready MCP server for intelligent JavaScript package management. Works with Claude, Windsurf, Cursor, VS Code, and any MCP-compatible AI editor.

Security & Testing Score 93/100 10 findings 383/wk Cap. High
Whoisxmlapi npm
A
@whoisxmlapidotcom/mcp-whoisxmlapi

The official WhoisXML API MCP server: 32 first-party tools for WHOIS, DNS, IP geolocation, threat intel, typosquatting, email verification, and native bulk — in Claude, Cursor, VS Code, or any MCP client.

Security & Testing Score 93/100 1 finding 356/wk Cap. High
Privacyscrubber npm
A
@privacyscrubber/mcp-server

CISO-Approved Zero-Trust PII & Secrets Redaction MCP Server for Cursor, Windsurf, and Claude Desktop. Prevent API leaks and comply with HIPAA/SOC 2 locally.

Security & Testing Score 93/100 3 findings 327/wk Cap. High
Mailpouch Source verified npm
A
mailpouch

mailpouch — lean, permission-gated MCP access to Proton Mail via Proton Bridge, with up to 86 tools, resources, and prompts.

Security & Testing Score 93/100 12 findings 288/wk Cap. High
Xlsx For Ai Source verified npm
A
xlsx-for-ai

The MCP server that makes LLMs reliable on real-world Excel spreadsheets. Thin npm client over a hosted API — read, write, diff, redact, and supervise .xlsx files from any MCP-aware agent.

Security & Testing Score 93/100 5 findings 273/wk Cap. High
Ops npm
A
server-ops-mcp

General-purpose server-ops MCP server: log troubleshooting, resource monitoring, code edit, Nginx & certificate management. Local + SSH modes with confirmations & secret redaction.

Security & Testing Score 93/100 1 finding 261/wk Cap. High