Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Phishtank npm
A
@pipeworx/mcp-phishtank

PhishTank MCP — wraps PhishTank API (checkurl.phishtank.com)

Security & Testing Score 99/100 0 findings 15/wk Cap. Minimal
Regex Toolkit npm
A
@mcp-listing/regex-toolkit-mcp

Deterministic regex execution Model Context Protocol (MCP) server. Test, evaluate, and extract data using regular expressions safely.

Security & Testing Score 99/100 0 findings 15/wk Cap. Minimal
Sailpoint Iiq npm
A
sailpoint-iiq-mcp-server

Model Context Protocol (MCP) server for SailPoint IdentityIQ — 63 tools covering SCIM and REST APIs for identity lifecycle, access requests, certifications, provisioning, and custom IIQ automation.

Security & Testing Score 99/100 0 findings 15/wk Cap. Minimal
Sgraal npm
A
@sgraal/mcp

AI agent memory governance MCP server — preflight validation before every action. Works with Claude Desktop, LangGraph, and any MCP-compatible client.

Security & Testing Score 99/100 0 findings 15/wk Cap. Minimal
Workos npm
A
@tellahq/workos-mcp

MCP server for WorkOS User Management API

Security & Testing Score 99/100 0 findings 15/wk Cap. Minimal
Dataprivacy Ai 2 implementations
A
best: dataprivacy-ai-mcp

Dataprivacy Ai automation via MCP. Includes classify personal data, assess lawful basis, generate dpia. By MEOK AI Labs.

Security & Testing Best score 99/100 0 findings 14/wk Cap. Minimal
Hibp npm
A
@pipeworx/mcp-hibp

Have I Been Pwned MCP

Security & Testing Score 99/100 0 findings 14/wk Cap. Minimal
Nobulex npm
A
@nobulex/mcp-server

Nobulex MCP compliance server — covenant rule checking, hash-chained audit logs, and integrity verification for any MCP-compatible agent.

Security & Testing Score 99/100 0 findings 14/wk Cap. Minimal
Password npm
A
@mukundakatta/password-mcp

MCP server: generate strong passwords and score password strength with zxcvbn.

Security & Testing Score 99/100 0 findings 14/wk Cap. Minimal
Security Feeds npm
A
@pipeworx/mcp-security-feeds

Security Feeds MCP.

Security & Testing Score 99/100 0 findings 14/wk Cap. Minimal
Tester npm
A
mcp-tester

Proxy service for MCP Stack

Security & Testing Score 99/100 0 findings 14/wk Cap. Minimal
Agent Policy Gateway 2 implementations
A
best: @aiagentkarl/agent-policy-gateway-mcp

MCP Server for AI agent policy enforcement - PII detection, guardrails, GDPR/EU AI Act compliance, audit logging, and emergency kill switch

Security & Testing Best score 99/100 0 findings 13/wk Cap. Minimal
Agentindex npm
A
@agentindex/mcp-server

MCP server for Agent Index - discover x402 endpoints from Claude Desktop

Security & Testing Score 99/100 0 findings 13/wk Cap. Minimal
Covenant npm
A
covenant-mcp

COVENANT MCP server — Stripe for Agent Trust on Pharos Atlantic. Install: npx covenant-mcp

Security & Testing Score 99/100 0 findings 13/wk Cap. Minimal
Cryptofort npm
A
cryptofort

Encrypted-at-rest credential vault with pluggable DB backends and an MCP server for agents.

Security & Testing Score 99/100 0 findings 13/wk Cap. Minimal
Malwarebazaar npm
A
@pipeworx/mcp-malwarebazaar

MalwareBazaar MCP — abuse.ch malware sample database (free, key required)

Security & Testing Score 99/100 0 findings 13/wk Cap. Minimal
Membrane npm
A
@p31/mcp-membrane

MCP server for post-deploy verification — DORA metrics, deploy checks, gamified XP/LOVE, and artifact minting

Security & Testing Score 99/100 0 findings 13/wk Cap. Minimal
Playwright Mcp Yaml Test npm
A
playwright-mcp-yaml-test

YAML-based Playwright MCP testing framework with data-driven CSV support for Gemini CLI

Security & Testing Score 99/100 1 finding 13/wk Cap. Minimal
Plsql Test npm
A
@vaallk/plsql-test-mcp

MCP server for IFS PL/SQL unit test analysis, annotation, generation, and execution

Security & Testing Score 99/100 0 findings 13/wk Cap. Minimal
Scanner 2 implementations
A
best: @agentsid/mcp-scanner

MCP security scanner. Scores any MCP server against the AgentsID trust framework and looks up pre-scanned results from the public registry.

Security & Testing Best score 99/100 0 findings 13/wk Cap. Minimal
Security Lens npm
A
mcp-security-lens

MCP security trust-check alias for AgentSecurityLens: safe install decisions before agents install MCP servers.

Security & Testing Score 99/100 0 findings 13/wk Cap. Minimal
Trust Chain 2 implementations
A
best: trust-chain-mcp

Trust Chain MCP server. Tools: create trust anchor, verify chain, add attestation. Built by MEOK AI Labs.

Security & Testing Best score 99/100 0 findings 13/wk Cap. Minimal
Web Exposure npm
A
web-exposure-mcp

MCP server that points an AI agent at a LIVE URL and confirms which secret files are publicly served — exposed .git, .env, JS source maps, backup/SQL dumps, directory listing and dotfiles — by fetching the bytes, not a checklist. Zero deps, read-only.

Security & Testing Score 99/100 2 findings 13/wk Cap. Minimal
Agentfence npm
A
agentfence

Developer-first security scanner for AI agents, MCP servers, and tool-connected LLM workflows.

Security & Testing Score 99/100 0 findings 12/wk Cap. Minimal