Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Agentledger npm
A
agentledger-mcp

MCP servers for AgentLedger — user agent and supervisor agent

Security & Testing Score 99/100 0 findings 12/wk Cap. Minimal
Lockfile Guardian npm
A
lockfile-guardian-mcp

Audit a package-lock.json for supply-chain attacks BEFORE npm install. Cross-checks every resolved dependency against the live npm registry: blocks integrity (sha512) mismatches (lockfile poisoning) and not-on-registry entries, and flags new/fresh depende

Security & Testing Score 99/100 0 findings 12/wk Cap. Minimal
Omitly Leak Check npm
A
omitly-leak-check-mcp

Moved: this MCP server is published as `omitly-mcp`. Run `npx -y omitly-mcp` instead. This package exists only to keep the old name from being claimed by someone else.

Security & Testing Score 99/100 0 findings 12/wk Cap. Minimal
Prmaat npm
A
@prmaat/mcp

Model Context Protocol (MCP) server for PrMaat — expose your agent passport, rooms, audit proofs, Verifiable Execution Receipts (v0.2), and Governance Trust ledger (v0.3.1) as tools in Claude Desktop, Claude Code, Cursor, or any MCP client. 9 tools. Legac

Security & Testing Score 99/100 0 findings 12/wk Cap. Minimal
Rubiscout npm
A
rubiscout-mcp

MCP server for Rubiscout email analysis — analyze, retrieve, and list phishing/BEC forensic reports from Claude, Cursor, and other MCP-compatible agents

Security & Testing Score 99/100 0 findings 12/wk Cap. Minimal
Threat npm
A
@jamjet/mcp-threat

Deterministic MCP threat controls: tool-definition drift, shadowing, token passthrough, trust baseline, and MCP Security Receipts. Pure, portable, reusable across JamJet MCP adapters.

Security & Testing Score 99/100 0 findings 12/wk Cap. Minimal
Validator Ai 2 implementations
A
best: validator-ai-mcp

AI-powered validator ai MCP server for agents. Supports validate json, validate email, validate url. By MEOK AI Labs.

Security & Testing Best score 99/100 0 findings 12/wk Cap. Minimal
Verify npm
A
@crestdeploymentsystems/verify-mcp

MCP server for Crest Verify. Check any x402 endpoint before your agent spends. Returns SPEND / CAUTION / INVESTIGATE / DO NOT SPEND backed by 50K+ classified services.

Security & Testing Score 99/100 0 findings 12/wk Cap. Minimal
01protocol npm
A
@01protocol/mcp-server

MCP server for 01 Protocol — AI agent identity tools for Claude Desktop and MCP-compatible apps

Security & Testing Score 99/100 0 findings 11/wk Cap. Minimal
Secret Scanner npm
A
secret-scanner-mcp

Scan a blob of code/text/diff for LEAKED SECRETS before you commit or share — API keys (AWS, GitHub, OpenAI, Stripe, Google, Slack…), tokens, private keys (RSA/EC/SSH/PGP), DB connection strings, .env dumps, JWTs and high-entropy strings. MCP server + pay

Security & Testing Score 99/100 0 findings 10/wk Cap. Minimal
Web Doctor npm
A
web-doctor-mcp

Live web health & security check for any domain or URL, as an MCP tool and a pay-per-call x402 endpoint. Does a real TLS handshake to grade the SSL/TLS certificate (validity, issuer, days-to-expiry, hostname match, self-signed), the TLS version, HTTP->HTT

Security & Testing Score 99/100 0 findings 10/wk Cap. Minimal
Zitadel npm
A
zitadel-mcp-server

MCP server for Zitadel identity management — manage users, projects, apps, roles, and service accounts

Security & Testing Score 99/100 0 findings 10/wk Cap. Minimal
Zentao Bugs npm
A
mcp-zentao-bugs

MCP server for ZenTao via FastMCP (HTTP stream + SSE)

Security & Testing Score 99/100 0 findings 9/wk Cap. Minimal
Action Firewall PyPI
A
mcp-action-firewall

A transparent MCP proxy that intercepts dangerous tool calls and requires OTP-based user approval.

Security & Testing Score 99/100 0 findings Cap. Minimal
Agent Audit Logger PyPI
A
agent-audit-logger-mcp

Hash-chained HMAC-signed audit log MCP for A2A (agent-to-agent) calls. Every tool-call, agent-handoff, decision gets a tamper-evident signed record. EU AI Act Art 12 automatic logs, DORA Art 17 ICT incident logs, ISO 42001 clause 9 monitoring — auditor-ready end-of-day attestations. By MEOK AI Labs.

Security & Testing Score 99/100 0 findings Cap. Minimal
Agent Audit Trail PyPI
A
agent-audit-trail-mcp

Immutable audit logging for AI agents — hash-chained event log, integrity verification, EU AI Act compliance

Security & Testing Score 99/100 0 findings Cap. Minimal
Agent Identity PyPI
A
agent-identity-mcp-server

MCP Server for AI agent identity and authorization — create, verify, and manage agent identities

Security & Testing Score 99/100 0 findings Cap. Minimal
Agent Rate Limiter PyPI
A
agent-rate-limiter-mcp

Fleet-wide shared rate limiter for A2A + multi-MCP deployments. Most MCP servers rate-limit independently — a hostile agent hitting 10 MCPs gets 10x quota. This MCP is the shared counter: every MCP checks here before allowing a call. Sliding window + concurrency grants + signed enforcement attestations. By MEOK AI Labs.

Security & Testing Score 99/100 0 findings Cap. Minimal
Agent Safety PyPI
A
agent-safety-mcp

MCP server for AI agent safety — cost guards, injection scanning, decision tracing, agent identity (KYA), and signed receipts

Security & Testing Score 99/100 0 findings Cap. Minimal
Agent Validator PyPI
A
agent-validator-mcp-server

Lighthouse for AI agents — test if APIs and services are properly accessible to AI agents

Security & Testing Score 99/100 0 findings Cap. Minimal
Agentic Identity PyPI
A
agentic-identity

Cryptographic trust anchor for AI agents

Security & Testing Score 99/100 0 findings Cap. Minimal
Ai Firewall PyPI
A
ai-firewall-mcp

MCP server for AI Firewall - multi-agent LLM security layer

Security & Testing Score 99/100 0 findings Cap. Minimal
Altr PyPI
A
altr-mcp

MCP server for ALTR data security — 135 tools across 13 domains with structured responses, middleware, and multi-transport support

Security & Testing Score 99/100 0 findings Cap. Minimal
Arc Gate PyPI
A
arc-gate-mcp

Runtime governance for MCP tool calls — Arc Gate for the MCP protocol layer

Security & Testing Score 99/100 0 findings Cap. Minimal