Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Axe npm
B
axe-mcp-server

Axe DevTools accessibility analysis and remediation MCP Server for AI coding agents

Security & Testing Score 89/100 16 findings 1.4k/wk Cap. High
Lab Agent npm
B
mcp-lab-agent

Sistema de Inteligência em Qualidade de Software: executa, analisa, prevê, recomenda e aprende. Memória local + Learning Hub.

Security & Testing Score 89/100 7 findings 15/wk Cap. Critical
Magga npm
B
@8nobletruths/magga

Prove that a code change actually works, whether an agent wrote it or a pull request did.

Security & Testing Score 89/100 2 findings 15/wk Cap. High
Mcpvault npm
B
@elraian/mcpvault

Local MCP credential vault — multi-account credentials for AI agents (Claude, Cursor, Codex, custom MCP clients).

Security & Testing Score 89/100 15 findings 12/wk Cap. Critical
Crowdsentinel PyPI
B
crowdsentinel-mcp-server

AI-powered threat hunting and incident response MCP server for Elasticsearch/OpenSearch with 139 tools, 6,060 detection rules, and baseline behaviour analysis

Security & Testing Score 89/100 9 findings Cap. Critical
Gx PyPI
B
gx-mcp-server

Expose Great Expectations data-quality checks via MCP

Security & Testing Score 89/100 5 findings Cap. Minimal
Q Ring Source verified npm
B
@i4ctime/q-ring

Quantum keyring for AI coding tools — Cursor, Kiro, Claude Code. Secrets, superposition, entanglement, MCP.

Security & Testing Score 88/100 8 findings 331/wk Cap. High
Envcp Source verified npm
B
@fentz26/envcp

MCP server for secure environment variable management - Keep your secrets safe from AI agents

Security & Testing Score 88/100 8 findings 197/wk Cap. High
Midscene Source verified npm
B
@midscene/mcp

Deprecated - Use @midscene/web-bridge-mcp, @midscene/android-mcp, or @midscene/ios-mcp

Security & Testing Score 88/100 3 findings 172/wk Cap. High
Pop Pay Source verified npm
B
pop-pay

The runtime security layer for AI agent commerce. Drop-in CLI + MCP server — blocks hallucinated purchases and keeps card credentials out of agent context. It only takes 0.1% of hallucination to drain 100% of your wallet.

Security & Testing Score 88/100 7 findings 142/wk Cap. High
Getaegis Cli Source verified npm
B
@getaegis/cli

Credential isolation for AI agents. Store, guard, and record — your agent never sees your API keys.

Security & Testing Score 88/100 6 findings 106/wk Cap. High
Frida npm
B
frida-mcp

TypeScript MCP server for Frida 17 dynamic instrumentation

Security & Testing Score 88/100 4 findings 102/wk Cap. Critical
Lupa Source verified npm
B
@pawel-up/lupa-mcp

Standalone global MCP Server for Lupa Testing Framework

Security & Testing Score 88/100 2 findings 22/wk Cap. High
Gcontext PyPI
B
gcontext-mcp

gcontext connector — local MCP bridge: cloud structure, local secret values

Security & Testing Score 88/100 10 findings Cap. High
Trace Source verified npm
B
trace-mcp

Framework-aware code intelligence MCP server — 60 framework integrations, 81 languages, up to 99% token reduction

Security & Testing Score 87/100 17 findings 5.0k/wk Cap. High
Speclock npm
B
speclock

Stop AI from breaking code you told it not to touch. Enforces .cursorrules, CLAUDE.md, and AGENTS.md — not just suggests. Zero-config: npx speclock protect reads your existing AI rule files, extracts constraints, installs pre-commit hooks, and makes your

Security & Testing Score 87/100 5 findings 263/wk Cap. High
Alethia npm
B
@vitronai/alethia

MIT-licensed MCP bridge to the Alethia runtime — the patent-pending zero-IPC E2E test runtime for AI agents. 2-5x faster than Playwright MCP. Signed evidence packs, EA1 fail-closed safety gate, WCAG + NIST 800-53 audits built in. Local-first, zero telemet

Security & Testing Score 87/100 2 findings 141/wk Cap. High
Mneme Ai npm
B
@mneme-ai/mcp

MCP server that exposes Mneme to Claude Code, Cursor, Continue, and other AI clients

Security & Testing Score 87/100 13 findings 122/wk Cap. High
Sequential Thinking npm
B
mcp-server-sequential-thinking

Security research canary — not for production use. Part of an authorized bug bounty research project.

Security & Testing Score 87/100 0 findings 40/wk Cap. Minimal
Codeguardian Studio npm
B
codeguardian-studio

AI-powered code refactor engine for large repositories, built on Claude Code + MCP.

Security & Testing Score 87/100 11 findings 25/wk Cap. High
Robotframework npm
B
robotframework-mcp

Model Context Protocol implementation for Robot Framework

Security & Testing Score 87/100 2 findings 23/wk Cap. High
A11y Mcp Srv npm
B
@dallask/a11y-mcp-srv

MCP server for accessibility auditing with export, filter, aggregation, and visualization tools

Security & Testing Score 87/100 2 findings 22/wk Cap. High
Agentpay npm
B
agentpay

Reserved name for future AgentPay packages.

Security & Testing Score 87/100 0 findings 15/wk Cap. Minimal
Agentwall npm
B
@agentwall/agentwall

Run AI agents safely on your local machine — policy-enforcing MCP proxy

Security & Testing Score 87/100 6 findings 15/wk Cap. High