Security & Testing MCP Servers

MCP servers for security scanning, vulnerability testing, secrets management and QA automation. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.

Gx PyPI
B
gx-mcp-server

Expose Great Expectations data-quality checks via MCP

Security & Testing Score 89/100 5 findings Cap. Minimal
Q Ring Source verified npm
B
@i4ctime/q-ring

Quantum keyring for AI coding tools — Cursor, Kiro, Claude Code. Secrets, superposition, entanglement, MCP.

Security & Testing Score 88/100 8 findings 331/wk Cap. High
Envcp Source verified npm
B
@fentz26/envcp

MCP server for secure environment variable management - Keep your secrets safe from AI agents

Security & Testing Score 88/100 8 findings 197/wk Cap. High
Midscene Source verified npm
B
@midscene/mcp

Deprecated - Use @midscene/web-bridge-mcp, @midscene/android-mcp, or @midscene/ios-mcp

Security & Testing Score 88/100 3 findings 172/wk Cap. High
Pop Pay Source verified npm
B
pop-pay

The runtime security layer for AI agent commerce. Drop-in CLI + MCP server — blocks hallucinated purchases and keeps card credentials out of agent context. It only takes 0.1% of hallucination to drain 100% of your wallet.

Security & Testing Score 88/100 7 findings 142/wk Cap. High
Getaegis Cli Source verified npm
B
@getaegis/cli

Credential isolation for AI agents. Store, guard, and record — your agent never sees your API keys.

Security & Testing Score 88/100 6 findings 106/wk Cap. High
Frida npm
B
frida-mcp

TypeScript MCP server for Frida 17 dynamic instrumentation

Security & Testing Score 88/100 4 findings 102/wk Cap. Critical
Lupa Source verified npm
B
@pawel-up/lupa-mcp

Standalone global MCP Server for Lupa Testing Framework

Security & Testing Score 88/100 2 findings 22/wk Cap. High
Gcontext PyPI
B
gcontext-mcp

gcontext connector — local MCP bridge: cloud structure, local secret values

Security & Testing Score 88/100 10 findings Cap. High
Trace Source verified npm
B
trace-mcp

Framework-aware code intelligence MCP server — 60 framework integrations, 81 languages, up to 99% token reduction

Security & Testing Score 87/100 17 findings 5.0k/wk Cap. High
Speclock npm
B
speclock

Stop AI from breaking code you told it not to touch. Enforces .cursorrules, CLAUDE.md, and AGENTS.md — not just suggests. Zero-config: npx speclock protect reads your existing AI rule files, extracts constraints, installs pre-commit hooks, and makes your

Security & Testing Score 87/100 5 findings 263/wk Cap. High
Alethia npm
B
@vitronai/alethia

MIT-licensed MCP bridge to the Alethia runtime — the patent-pending zero-IPC E2E test runtime for AI agents. 2-5x faster than Playwright MCP. Signed evidence packs, EA1 fail-closed safety gate, WCAG + NIST 800-53 audits built in. Local-first, zero telemet

Security & Testing Score 87/100 2 findings 141/wk Cap. High
Mneme Ai npm
B
@mneme-ai/mcp

MCP server that exposes Mneme to Claude Code, Cursor, Continue, and other AI clients

Security & Testing Score 87/100 13 findings 122/wk Cap. High
Sequential Thinking npm
B
mcp-server-sequential-thinking

Security research canary — not for production use. Part of an authorized bug bounty research project.

Security & Testing Score 87/100 0 findings 40/wk Cap. Minimal
Codeguardian Studio npm
B
codeguardian-studio

AI-powered code refactor engine for large repositories, built on Claude Code + MCP.

Security & Testing Score 87/100 11 findings 25/wk Cap. High
Robotframework npm
B
robotframework-mcp

Model Context Protocol implementation for Robot Framework

Security & Testing Score 87/100 2 findings 23/wk Cap. High
A11y Mcp Srv npm
B
@dallask/a11y-mcp-srv

MCP server for accessibility auditing with export, filter, aggregation, and visualization tools

Security & Testing Score 87/100 2 findings 22/wk Cap. High
Agentpay npm
B
agentpay

Reserved name for future AgentPay packages.

Security & Testing Score 87/100 0 findings 15/wk Cap. Minimal
Agentwall npm
B
@agentwall/agentwall

Run AI agents safely on your local machine — policy-enforcing MCP proxy

Security & Testing Score 87/100 6 findings 15/wk Cap. High
Figma Mcp Complete npm
B
figma-mcp-complete

Figma to Code MCP + Pixel Perfect Validation - Export Figma designs as ready-to-use HTML/CSS with pixel-perfect accuracy validation

Security & Testing Score 87/100 2 findings 14/wk Cap. High
Det Acp Core npm
B
@det-acp/core

Agent Governance Gateway — bounded, auditable, session-aware control for AI agents with MCP proxy, shell proxy, and HTTP API

Security & Testing Score 87/100 7 findings 13/wk Cap. High
Manos npm
B
manos-mcp

A CLI MCP server for ad-hoc UI testing of Android & iOS apps — a tight act+observe loop, device-condition control, log/crash & network capture, OCR targeting, accessibility audits, and session recording that exports a replayable flow.

Security & Testing Score 87/100 11 findings 13/wk Cap. High
Npm npm
B
npm-mcp-server

npm mcp server

Security & Testing Score 87/100 0 findings 12/wk Cap. Minimal
Adb npm
B
mcp-server-adb

Security scan results for the Adb MCP server.

Security & Testing Score 87/100 0 findings 11/wk Cap. Minimal