Penetration Testing
Tools and frameworks for security testing, vulnerability scanning, and penetration testing. Enables security professionals to identify and exploit security weaknesses in applications and networks.
MCP ServersBrowse all →
AlicenseAqualityDmaintenanceMCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.737 npmMIT
PatrowlIntelMCPofficial
AlicenseAqualityDmaintenanceExposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.32MIT- AlicenseAqualityBmaintenanceEnables MCP-native multi-agent security audits for Google Antigravity, orchestrating subagents for 0day research, static analysis, PoC verification, exploit chaining, reporting, and code remediation.6153MIT

Symbiotic MCP Serverofficial
AlicenseAqualityDmaintenanceEnables security analysis of code and infrastructure files via MCP, using Symbiotic CLI for scanning vulnerabilities.4MIT
AgentAuditofficial
AlicenseAqualityDmaintenanceEnables AI agents to scan MCP servers and AI packages for vulnerabilities, prompt injection, and supply chain attacks.7167 npmAGPL 3.0- AlicenseBqualityDmaintenanceConnects Claude Code to a Latent Defense deployment to map GitHub repositories into an infrastructure graph, discover attack paths using the JEPA energy model, and triage findings from the terminal.85Apache 2.0
- AlicenseAqualityAmaintenanceThis server enables AI-assisted APK reverse-engineering entirely on-device, orchestrating jadx, apktool, adb, frida, and APKiD through a job/workflow engine, and exposing those agents as native MCP tools for Claude without any cloud dependency.38208MIT

shipsafe-mcpofficial
AlicenseAqualityCmaintenanceEnables AI coding assistants to scan projects for security issues such as leaked API keys, missing Supabase RLS, open Firebase rules, unauthenticated routes, and hallucinated packages, then fix and verify the results.8MIT
solvegate-mcpofficial
AlicenseAqualityAmaintenanceEnables agents to inspect web pages for Cloudflare Turnstile challenges without an API key, and clear Turnstile or WAF challenges using a SolveGate API key.342 npm1MIT- AlicenseAqualityAmaintenanceProvides passive OSINT reconnaissance for domains and IPs using public sources, with tools for WHOIS/RDAP, DNS, subdomain enumeration, Wayback Machine, HTTP headers, Shodan InternetDB, email security, TLS certificates, and ASN lookups, all without requiring API keys.211MIT

operant-mcpofficial
AlicenseAqualityFmaintenanceA comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.51110 npm24MIT- AlicenseAqualityBmaintenanceThis local MCP server keeps vulnerability intelligence, research scope, scanner results, evidence receipts, Bugcrowd VRT assessments, and report drafts in one SQLite ledger. It is built for authorized defensive research and does not scan, exploit, or submit reports.191MIT
- AlicenseBqualityDmaintenanceEnables integration with Beagle Security API for managing security testing projects, applications, domain verification, and automated penetration tests. Provides 18 tools for creating, monitoring, and retrieving results from security assessments.171MIT
- AlicenseBqualityFmaintenanceA security testing tool that enables automated vulnerability detection including XSS and SQL injection, along with comprehensive browser interaction capabilities for web application penetration testing.312204 npm22MIT
- AlicenseAqualityAmaintenanceEnables an LLM to author, validate, and test Wirefilter WAF and Smart Firewall rules using live schema and real CVE exploit templates.71MIT

Grype MCP Serverofficial
AlicenseAqualityFmaintenanceEnables AI assistants to perform vulnerability scanning using Grype, supporting scans of directories, container images, and packages via the Model Context Protocol.99Apache 2.0- AlicenseAqualityBmaintenanceMCP server that exposes 31 OSINT checks from Lissy93/web-check as tools for website analysis, including SSL, DNS, headers, WHOIS, and security presets. Enables natural-language-driven web recon and health checks.188MIT

MCP Security Scannerofficial
AlicenseAqualityDmaintenanceIntegrates Checkov, Semgrep, Bandit, and ASH to provide comprehensive code security analysis for AI coding assistants.1516MIT No Attribution
everthreadofficial
AlicenseAqualityBmaintenanceEnables plain-English website security checks from an MCP client, offering tools to assess site findings, explain individual issues, and list all available security checks.3236 npmMIT
MCP Hub Securityofficial
AlicenseAqualityDmaintenanceSecurity gate that scans MCP servers and Claude Code Skills for vulnerabilities before execution.72MIT
Polygraphofficial
AlicenseAqualityCmaintenanceOpen behavioral litmus for MCP servers — grades A–F across tool-output injection, egress, sensitive-data, and adversarial-input, with reproducible, content-addressed evidence. Tools: run_litmus, verify_attestation.4269 npm8Apache 2.0
Appknox MCP Serverofficial
AlicenseAqualityDmaintenanceA Model Context Protocol server that wraps the Appknox CLI for mobile application security testing.1313 npmMIT- AlicenseAqualityDmaintenanceEnables AI assistants to execute security testing tools on a Kali Linux machine over SSH, including reconnaissance, web app scanning, and static/dynamic analysis.1111 npmMIT

SiteLint Auditor MCPofficial
AlicenseAqualityAmaintenanceRuns WCAG accessibility, SEO, performance, and security audits on URLs or raw HTML via SiteLint Auditor. Enables LLM agents to audit web pages and check WCAG criteria through MCP tools.3445 npmMozilla Public 2.0- AlicenseAqualityAmaintenanceEnables AI agents to run multi-stage CyberChef recipes, decode and encode data, deobfuscate payloads, calculate entropy, and decode JWTs through MCP tools.4182,584 npm1Apache 2.0
- AlicenseAqualityAmaintenanceEnables Android APK reverse engineering and Flutter runtime injection through a six-step pipeline of decompile, analyze, synthesize, inject, patch, and repackage. Provides MCP tools for authorized security research and penetration testing.2943 npm5MIT
- AlicenseAqualityBmaintenanceEnables AI agents to check industrial and IT devices by vendor, product, and firmware version, returning affecting CVEs, fixes, vendor advisories, fix plans, and change tracking through read-only tools.4MIT
- AlicenseAqualityCmaintenanceEnables AI assistants to run Offensive360 SAST scans on local codebases, returning security findings with file/line, severity, and fixes, plus scan status tracking.240 npmMIT
- AlicenseAqualityDmaintenanceA Model Context Protocol (MCP) server for the Ghost Security API, providing secure access to security findings and repository data through standardized tools.734 npm3MIT

bounty-operatorofficial
AlicenseAqualityBmaintenanceConnects MCP clients to pre-submission review that argues against a draft bug-bounty report or smart-contract finding the way a triager would, tying every claim to a supplied file and line and returning a submit, rewrite-then-submit, prove-first, hold-duplicate or drop verdict. Exposes tools to list review profiles, prepare reviews for the agent's own model, build hash-verified review packets, and — with a connection token — run hosted profiles on your own provider key.61MIT
MCP ConnectorsBrowse all →
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
23 security tools for AI agents: phishing links, exposure maps, DNS, SSL, PQC, headers, email.
Free AI security tools: injection payloads, OWASP LLM mapper, ADLC release planner, test builder.
Production-safety audits for AI-generated code, with a fix for every finding.
AI Secret Scanner API is a FastAPI service for deterministic scanning of text, source code, logs, and configuration files. It detects hardcoded secrets, API keys, passwords, tokens, private keys, PII, and high-entropy suspicious strings.
Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Router default logins, compliance index, MAC/OUI lookup. Reads free; submit_correction is Pro.
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
CVE, KEV, EPSS, SBOM and advisory lookups; per-CVE exposure from Shodan data (© Shodan). Keyless.
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Triage a CVE: how severe it is, whether it is exploited, and how likely exploitation is.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.