Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Safe Gmail npm
A
safe-gmail-mcp

Security-focused local MCP server for reading Gmail headers and explicitly confirming Gmail sends.

Security & Testing Score 93/100 3 findings 20/wk Cap. High
Factifai Source verified npm
A
@presidio-dev/factifai-mcp-server

A MCP server for Factifai

Security & Testing Score 93/100 3 findings 19/wk Cap. High
Lanchu npm
A
lanchu

Control and trust layer for coordinating multiple AI agents. MCP, 100% local, open source.

Security & Testing Score 93/100 11 findings 19/wk Cap. High
Mcp Workbench npm
A
@mcp-workbench/mcp-server

MCP server adapter for MCP Workbench — expose inspect, generate, and test capabilities to AI agents

Security & Testing Score 93/100 7 findings 19/wk Cap. High
Pbi Webview2 npm
A
pbi-webview2

MCP server that drives the LIVE Power BI Desktop report canvas (WebView2) over CDP — switch pages, click slicers, fire bookmarks, read cards/matrices as data, judge cross-filters, run the Performance Analyzer, and screenshot, with no reload and no OCR.

Security & Testing Score 93/100 8 findings 19/wk Cap. High
Say npm
A
say-mcp-server

MCP server for macOS text-to-speech functionality

Security & Testing Score 93/100 1 finding 19/wk Cap. High
Appknox npm
A
@appknox/mcp-server

Official Model Context Protocol (MCP) server for Appknox - enables AI assistants to perform mobile application security testing

Security & Testing Score 93/100 1 finding 18/wk Cap. High
Aster Guard npm
A
@asterworks/aster-guard

A lightweight MCP security guard for Claude Code users and indie AI builders. Claude Codeユーザーのための、接続前MCPセキュリティ診断ツール。

Security & Testing Score 93/100 2 findings 18/wk Cap. High
Mcphub npm
A
@pcandido/mcphub

A zero-dependency MCP gateway. Connect multiple AI agents to multiple MCP servers through a single, centrally-managed stdio interface. No overhead, no bloat — just the Node.js stdlib. Secrets stay in the OS keychain, never in config files.

Security & Testing Score 93/100 4 findings 18/wk Cap. High
Nimbus npm
A
nimbus-mcp

Nimbus - AWS Security Assessment MCP Server - 45 Tools with Full OWASP MCP Security

Security & Testing Score 93/100 3 findings 18/wk Cap. High
Remote Acn npm
A
mcp-remote-acn

Remote proxy for Model Context Protocol, allowing local-only clients to connect to remote servers using oAuth. Fork by Accenture with token-file support and stable session handling.

Security & Testing Score 93/100 1 finding 18/wk Cap. High
Runcue npm
A
runcue

Developer UI navigation tool — run business flows with a single command

Security & Testing Score 93/100 2 findings 18/wk Cap. High
Compliance Validator npm
A
mcp-compliance-validator

Security validation system for MCP server implementations with enterprise-grade authentication and authorization checks

Security & Testing Score 93/100 4 findings 17/wk Cap. High
Get Mcp Keys npm
A
@masonator/get-mcp-keys

A lightweight utility that securely loads API keys for Cursor MCP servers from your home directory, preventing accidental exposure of secrets in repositories. Keep your credentials safe while maintaining seamless integration with AI coding assistants.

Security & Testing Score 93/100 1 finding 17/wk Cap. High
Hello npm
A
hello-mcp

hello-mcp is a tour and guide to Claude Desktop MCP Config Manager for MCP(Model Context Protocol) beginners

Security & Testing Score 93/100 4 findings 17/wk Cap. High
Phantom npm
A
phantom-mcp

MCP server for mobile testing — iOS Simulator, Android Emulator, and real devices. 22 tools to test mobile apps from Claude Code.

Security & Testing Score 93/100 4 findings 17/wk Cap. High
Claude Secrets npm
A
@vaultry/claude-secrets

Encrypted secrets store for Claude Code (MCP) + CLI + .env placeholder expansion. macOS Keychain backed.

Security & Testing Score 93/100 3 findings 16/wk Cap. High
Orcho Risk npm
A
@orcho_risk/mcp-server

Orcho Risk Assessment MCP Server for Cursor - Analyze coding prompts for security and safety risks

Security & Testing Score 93/100 1 finding 16/wk Cap. High
Quality npm
A
quality-mcp

An MCP server that analyzes to your codebase, with plugin support for DCD and Simian. 🏍️ "The only Zen you find on the tops of mountains is the Zen you bring up there."

Security & Testing Score 93/100 4 findings 16/wk Cap. High
Rebar npm
A
rebar-mcp

Reinforcement for AI-generated code. Enforcement hooks, quality audits, and opinionated templates that prevent AI coding tools from shipping broken code.

Security & Testing Score 93/100 9 findings 16/wk Cap. High
Scanline npm
A
@mrzadexinho/scanline

Security scanning MCP server — semgrep integration, SARIF parsing, and finding triage for Claude Code

Security & Testing Score 93/100 1 finding 16/wk Cap. High
Secure Env Elicit npm
A
@grec0/mcp-secure-env-elicit

MCP wrapper that launches other MCP servers with secret env vars collected interactively via elicitation — placeholders in config, values held AES-encrypted in memory, never on disk.

Security & Testing Score 93/100 4 findings 16/wk Cap. High
Sentinel Warden npm
A
sentinel-warden

Supply-chain firewall for AI agent skills, MCP servers, and rules files. Scans for prompt injection, data exfiltration, and tool poisoning before you install — and emits an agent-BOM + compliance evidence as a byproduct.

Security & Testing Score 93/100 1 finding 16/wk Cap. High
Sipp npm
A
sipp-mcp-server

Model Context Protocol server for SIPp - SIP protocol testing tool

Security & Testing Score 93/100 1 finding 16/wk Cap. High