Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Flagrix Source verified npm
A
flagrix

Scan GitHub repos and profiles for malware before you clone — CLI and MCP server for the Flagrix scanner

Security & Testing Score 94/100 4 findings 69/wk Cap. High
Opzyai Source verified npm
A
@opzyai/mcp

Local-first security check MCP server for AI coding agents — finds hardcoded secrets, exposed .env files, secrets in git history, and vulnerable dependencies in your workspace, entirely on your machine.

Security & Testing Score 94/100 1 finding 68/wk Cap. High
Heimdall Scan Source verified npm
A
mcp-heimdall-scan

Heimdall — a security scanner for Model Context Protocol (MCP) servers. Vet a server, or a whole agent config, before your agent trusts it.

Security & Testing Score 94/100 8 findings 65/wk Cap. High
Tablecloth Source verified npm
A
tablecloth-mcp

MCP server that finds Korean e-Gov/finance sites and opens them in a clean, disposable Windows Sandbox with the required security software. Discovery + safe-launch only (no RPA). Node/TS implementation (counterpart of the .NET dnx build). Dual-licensed: A

Security & Testing Score 94/100 2 findings 58/wk Cap. High
Pgconsole Source verified npm
A
@pgplex/pgconsole

Postgres Editor with Guardrails

Security & Testing Score 94/100 5 findings 39/wk Cap. High
Sanctuary Framework Source verified npm
A
@sanctuary-framework/mcp-server

The open source standard for secure, private AI: a wall the operating system enforces in both directions, and your data under your own keys, portable anywhere. Any agent, local or cloud, solo or fleet.

Security & Testing Score 94/100 6 findings 35/wk Cap. High
Maltego Source verified npm
A
maltego-mcp

MCP server for authoring Maltego graph files and running primitive OSINT lookups.

Security & Testing Score 94/100 3 findings 34/wk Cap. High
Mock Source verified npm
A
mock-mcp

An MCP server enabling LLMs to write integration tests through live test environment interaction

Security & Testing Score 94/100 10 findings 29/wk Cap. High
Fractascan Source verified npm
A
fractascan-mcp

Model Context Protocol server exposing Fracta scan tools (passive_scan, scan_repo, …)

Security & Testing Score 94/100 3 findings 27/wk Cap. High
Autousers Source verified npm
A
@autousers/mcp

Official MCP server for Autousers — UX evaluation, calibrated AI personas, side-by-side design review.

Security & Testing Score 94/100 1 finding 26/wk Cap. High
Security Auditor Source verified npm
A
mcp-security-auditor

Security scanner for MCP (Model Context Protocol) servers. Detect vulnerabilities, secrets, injection risks, and misconfigurations before deployment.

Security & Testing Score 94/100 4 findings 25/wk Cap. High
Proton Pass Community Source verified npm
A
proton-pass-community-mcp

Unofficial MCP server that integrates with the Proton Pass CLI

Security & Testing Score 94/100 1 finding 24/wk Cap. High
Domere Source verified npm
A
@weave_protocol/domere

The Judge Protocol - Thread identity, intent verification, and blockchain anchoring

Security & Testing Score 94/100 6 findings 23/wk Cap. High
Dependency Checker Source verified npm
A
@djodjonx/dependency-checker-mcp

MCP server to check dependencies against OSV.dev and Socket.dev

Security & Testing Score 94/100 1 finding 22/wk Cap. High
Agentest Source verified npm
A
agentest

AI-driven mobile app testing via MCP — any AI agent can test any Android app

Security & Testing Score 94/100 2 findings 20/wk Cap. High
Atlasent Source verified npm
A
@atlasent/mcp-server

AtlaSent MCP server — authorize-before-execute for any MCP-compatible AI agent

Security & Testing Score 94/100 3 findings 20/wk Cap. High
Hord Source verified npm
A
@weave_protocol/hord

The Vault Protocol - Cryptographic containment and capability management for AI agents

Security & Testing Score 94/100 4 findings 16/wk Cap. High
Perfscale Source verified npm
A
@perfscale/mcp

MCP server for the perfscale OSS CLI: run load tests, lint and manage test/config YAML locally

Security & Testing Score 94/100 2 findings 16/wk Cap. High
Transport Firewall Source verified npm
A
mcp-transport-firewall

Fail-closed stdio firewall for risky local MCP JSON-RPC tool calls

Security & Testing Score 94/100 2 findings 16/wk Cap. High
Agentscore Source verified npm
A
agentscore-mcp

Trust scoring for AI agents. Investigate, verify, and compare agent trustworthiness through MCP.

Security & Testing Score 94/100 1 finding 15/wk Cap. High
Outfit Source verified npm
A
@myceliuminc/outfit

Portable, enforced agent personas. One spec - any runtime.

Security & Testing Score 94/100 3 findings 14/wk Cap. High
Wishmock Source verified npm
A
wishmock

gRPC and connect RPC mock server with hot reload, and rule-based responses

Security & Testing Score 94/100 5 findings 13/wk Cap. High
Eslint Plugin Mcp Security Source verified npm
A
eslint-plugin-mcp-security

ESLint security rules for Model Context Protocol (MCP) servers — catches SANDWORM_MODE credential harvesting, path traversal, command injection, and CVE patterns at dev time

Security & Testing Score 94/100 3 findings 12/wk Cap. High
Security Scan npm
A
mcp-security-scan

Security scanner for MCP (Model Context Protocol) servers. Detect authentication gaps, credential exposure, SSRF risks, and misconfigurations. Maps findings to OWASP MCP Top 10.

Security & Testing Score 94/100 2 findings 12/wk Cap. Moderate