Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Fence npm
A
mcp-fence

The bidirectional firewall for MCP — scans inputs AND outputs, detects rug-pulls at runtime, zero config.

Security & Testing Score 93/100 2 findings 219/wk Cap. High
Kastell npm
A
kastell

CLI toolkit for provisioning, securing, and managing self-hosted servers

Security & Testing Score 93/100 23 findings 214/wk Cap. High
Cli npm
A
mcp-cli

A secure MCP CLI server implementation with comprehensive path whitelist validation, providing controlled file system operations and command execution in a protected environment. Features include strict security measures, real-time path validation, secure

Security & Testing Score 93/100 2 findings 198/wk Cap. High
Android 2 implementations
A
best: android-mcp-server

MCP server for controlling Android emulators via ADB

Security & Testing Best score 93/100 4 findings 191/wk Cap. High
Security Detections npm
A
security-detections-mcp

Advanced MCP server for security detections with Detection Engineering Intelligence, Knowledge Graph (Tribal Knowledge), Elicitation, and Resource Subscriptions

Security & Testing Score 93/100 3 findings 191/wk Cap. High
Agent npm
A
@bvcc/agent-mcp

Model Context Protocol server exposing a BVCC Agent Wallet to AI runtimes (Claude Code, Cursor, Claude app). Tools are generated from the @bvcc/agent-sdk capability catalog.

Security & Testing Score 93/100 3 findings 186/wk Cap. High
Weapp Agent npm
A
@chaixueyuan/weapp-agent-mcp

Agent-first MCP server for WeChat Mini Program debugging, automation, and lightweight testing

Security & Testing Score 93/100 2 findings 179/wk Cap. High
Mobai npm
A
mobai-mcp

MCP server for MobAI - AI-powered mobile device automation

Security & Testing Score 93/100 3 findings 176/wk Cap. High
Android Debug Bridge npm
A
android-debug-bridge-mcp

MCP plugin to control Android devices via ADB for automation, testing, and agent integration

Security & Testing Score 93/100 1 finding 130/wk Cap. High
Vitest npm
A
@madrus/vitest-mcp-server

Advanced Model Context Protocol (MCP) server for Vitest testing with intelligent resources, coverage analysis, and AI-assisted development workflows

Security & Testing Score 93/100 2 findings 127/wk Cap. High
Tooltrust npm
A
tooltrust-mcp

MCP server that scans other MCP servers for prompt injection, data exfiltration, and privilege escalation. Add to your .mcp.json and let your AI agent audit its own tools.

Security & Testing Score 93/100 1 finding 123/wk Cap. High
Graneth npm
A
@graneth/mcp-server

Account-free MCP server: catch AI-hallucinated packages (npm, PyPI, crates.io, RubyGems, Go, Packagist), risk-score the dependencies an AI agent introduces, and find hardcoded secrets before you commit. Exposes the free pre_flight_check tool over stdio.

Security & Testing Score 93/100 1 finding 117/wk Cap. High
Gomission npm
A
@gomission/mcp

Mission Trust Graduation gate for Claude Desktop. Claude can do more for you once Mission decides what it's allowed to do.

Security & Testing Score 93/100 1 finding 112/wk Cap. High
Supply Chain npm
A
supply-chain-mcp-server

Software supply chain security MCP server — vulnerability scanning, package analysis, provenance verification, typosquatting detection, dependency intelligence across npm, PyPI, crates.io, Go, and more

Security & Testing Score 93/100 1 finding 109/wk Cap. High
Electron Test npm
A
electron-test-mcp

MCP server for testing Electron apps via Playwright - supports both CDP connection and direct launch

Security & Testing Score 93/100 7 findings 102/wk Cap. High
Blacksmith npm
A
blacksmith-mcp

MCP server for Blacksmith CI analytics

Security & Testing Score 93/100 1 finding 95/wk Cap. High
Test Genie npm
A
test-genie-mcp

AI-powered app test automation MCP server - scenario generation, execution, detection, and auto-fixing

Security & Testing Score 93/100 7 findings 95/wk Cap. High
Hal npm
A
hal-mcp

HAL (HTTP API Layer) - An MCP server that provides HTTP API capabilities to Large Language Models with OpenAPI/Swagger integration

Security & Testing Score 93/100 3 findings 94/wk Cap. High
Zebrunner npm
A
mcp-zebrunner

Advanced Zebrunner MCP Server — analytics, reporting, and safe mutations for Zebrunner. Complements the official Zebrunner MCP (beta). Tools registered as adv_<name> with legacy aliases kept for backward compatibility.

Security & Testing Score 93/100 2 findings 94/wk Cap. High
Navable npm
A
@navable/mcp

Free, real-browser accessibility scanner for AI coding agents. Scans localhost with Playwright + axe-core (and optionally Pa11y/HTMLCS), returns WCAG 2.1 Level A + AA violations with fix plans.

Security & Testing Score 93/100 1 finding 93/wk Cap. High
Electron Stagewright Core npm
A
@electron-stagewright/core

Core MCP server for Electron Stagewright. Drive Electron apps the way Playwright drives browsers.

Security & Testing Score 93/100 10 findings 89/wk Cap. High
Piqrypt npm
A
@piqrypt/mcp-server

Cryptographic audit trail for AI agents — sign, chain-verify and export every decision. GDPR / HIPAA / EU AI Act ready. Free & open source.

Security & Testing Score 93/100 1 finding 87/wk Cap. High
Mobile Device npm
A
mobile-device-mcp

MCP server that gives AI coding assistants (Claude, Cursor, Windsurf) the ability to see and interact with Android mobile devices via ADB — AI-powered visual inspection, element finding, and device automation

Security & Testing Score 93/100 3 findings 86/wk Cap. High
Leakferret npm
A
@leakferret/mcp

MCP (Model Context Protocol) server for leakferret. Stops AI agents from committing live secrets.

Security & Testing Score 93/100 2 findings 78/wk Cap. High