Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Blackwall npm
A
blackwall-mcp

BLACK_WALL MCP server — a pre-action risk check your AI agent calls before any irreversible action (send email, move money, run SQL, delete data).

Security & Testing Score 99/100 0 findings 523/wk Cap. Minimal
Apollo Io npm
A
@thevgergroup/apollo-io-mcp

Model Context Protocol (MCP) server for Apollo.io API integration

Security & Testing Score 99/100 2 findings 507/wk Cap. Minimal
Nist Nvd npm
A
@cyanheads/nist-nvd-mcp-server

Search and audit CVEs by keyword, severity, CWE, CISA KEV status, and CPE via the NIST National Vulnerability Database. STDIO or Streamable HTTP.

Security & Testing Score 99/100 0 findings 501/wk Cap. Minimal
Baseline Ui npm
A
@baseline-ui/mcp

MCP server for Baseline UI design system documentation

Security & Testing Score 99/100 0 findings 373/wk Cap. Minimal
Shodan npm
A
@burtthecoder/mcp-shodan

A Model Context Protocol server for Shodan API queries.

Security & Testing Score 99/100 0 findings 367/wk Cap. Minimal
Github Security 2 implementations
A
best: github-security-mcp

GitHub security posture audit tools for AI agents — organization, repository, Actions, secrets, supply chain analysis via MCP

Security & Testing Best score 99/100 0 findings 313/wk Cap. Minimal
Onelogin npm
A
@onelogin/onelogin-mcp

Model Context Protocol server for OneLogin API - enables Claude and other MCP clients to manage users, apps, roles, and authentication

Security & Testing Score 99/100 0 findings 303/wk Cap. Minimal
Novada npm
A
novada-mcp

One MCP server for all web data. Search, scrape, crawl, proxy, and AI research in one install.

Security & Testing Score 99/100 0 findings 289/wk Cap. Minimal
Pseolint npm
A
@pseolint/mcp

MCP server for pseolint — audit programmatic SEO sites from AI coding assistants. v0.5 adds the AI-orchestrated audit tool that produces a fix manifest with concrete patches.

Security & Testing Score 99/100 0 findings 271/wk Cap. Minimal
Media Pipeline Mcp Security npm
A
@reaatech/media-pipeline-mcp-security

Enterprise security features — API key and JWT authentication, RBAC, token bucket rate limiting, audit logging with SIEM export

Security & Testing Score 99/100 0 findings 270/wk Cap. Minimal
Ai Test Process npm
A
ai-test-process-mcp

MCP server providing AI-assisted test process tools, starting with JSTQB-based test plan draft generation and test design techniques.

Security & Testing Score 99/100 0 findings 266/wk Cap. Minimal
A11y npm
A
a11y-mcp-server

An MCP server for accessibility testing using Axe-core

Security & Testing Score 99/100 0 findings 233/wk Cap. Minimal
Lazaretto npm
A
lazaretto-mcp

MCP server for Lazaretto: check a lockfile for known-malicious dependencies (free, no key), or scan a skill, tool, or package before an agent installs it.

Security & Testing Score 99/100 0 findings 212/wk Cap. Minimal
Zephyr Scale 3 implementations
A
best: zephyr-scale-mcp-server

Model Context Protocol (MCP) server for Zephyr Scale test case management with comprehensive STEP_BY_STEP, PLAIN_TEXT, and BDD support

Security & Testing Best score 99/100 0 findings 200/wk Cap. Minimal
Attack Surface npm
A
@cyanheads/attack-surface-mcp-server

Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan via MCP. STDIO or Streamable HTTP.

Security & Testing Score 99/100 0 findings 149/wk Cap. Minimal
Threatintel npm
A
mcp-threatintel-server

MCP server for unified threat intelligence - AlienVault OTX, AbuseIPDB, GreyNoise, and abuse.ch feeds

Security & Testing Score 99/100 0 findings 149/wk Cap. Minimal
Tideorg npm
A
@tideorg/mcp

MCP server exposing Tide operational guidance — canon, playbooks, skills, prompts, adapters, and scenarios for AI coding agents

Security & Testing Score 99/100 0 findings 136/wk Cap. Minimal
Lucairn npm
A
@lucairn/mcp-server

Model Context Protocol server for Lucairn — privacy-preserving AI gateway

Security & Testing Score 99/100 0 findings 128/wk Cap. Minimal
Agentscore Xyz npm
A
@agentscore-xyz/mcp-server

MCP security trust layer. Scan packages, inspect repo MCP dependencies, generate Policy Gate setup, install the workflow directly, check exposure, and query abuse data.

Security & Testing Score 99/100 0 findings 121/wk Cap. Minimal
Nervous System npm
A
mcp-nervous-system

Deterministic governance lint for MCP server configurations, plus reference tools for the 7 rules. audit_mcp_config and check_preflight do real work locally. Every other tool is named get_* because it returns instructions, not actions. The write-capable t

Security & Testing Score 99/100 0 findings 118/wk Cap. Minimal
Openui npm
A
@nuwax-ai/openui-mcp

Durable file-based OpenUI artifacts over MCP for Nuwax.

Security & Testing Score 99/100 0 findings 116/wk Cap. Minimal
A2a Trustgate npm
A
a2a-trustgate

A2A TrustGate CLI — Safety, compliance, and governance for AI agents. Screen every action before it executes.

Security & Testing Score 99/100 0 findings 112/wk Cap. Minimal
Allure Testops npm
A
allure-testops-mcp

MCP server for Allure TestOps test cases and launches

Security & Testing Score 99/100 0 findings 108/wk Cap. Minimal
Pihole npm
A
mcp-pihole-server

MCP server for Pi-hole v6 API - manage DNS blocking, view statistics, and control your Pi-hole

Security & Testing Score 99/100 0 findings 95/wk Cap. Minimal