Penetration Testing
Tools and frameworks for security testing, vulnerability scanning, and penetration testing. Enables security professionals to identify and exploit security weaknesses in applications and networks.
MCP ServersBrowse all →
AlicenseAqualityBmaintenanceProvides AI-ready access to US/UK nonprofit data and OSS vulnerability intelligence via MCP, with 10 tools and no API key required.Last updated2435355MIT- AlicenseAqualityBmaintenance14 atomic MCP tools for AppSec and AI Security engineers: source/schema/prompt audit primitives, JWT inspect, HTTP diff, pentest atoms (default creds, GraphQL introspect, phpggc, interactsh OOB), and a defensive helpers library that fixes the bugs the detectors flag. SARIF output, PyPI Trusted Publishing with Sigstore provenance.Last updated614MIT

operant-mcpofficial
AlicenseAqualityCmaintenanceA comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.Last updated51198MIT- AlicenseAqualityCmaintenanceCyberSecurity MCP Server extends Claude with real-time cybersecurity reconnaissance capabilities that Claude doesn't have by default. Instead of manually running 5 different tools across different terminals, just tell Claude "analyze google.com" and get a complete security breakdown instantly. Tools included: * WHOIS Lookup — registrar, ownership, creation/expiry dates * DNS Enumeration — A,Last updated2282MIT

@konsulto/mcpofficial
AlicenseAqualityCmaintenanceMCP server that enables Claude Code to drive the Konsulto cybersecurity audit platform from the CLI, including reading and writing findings, managing evidence, and handling scope and assets.Last updated19241MIT
agentminds-mcpofficial
AlicenseAqualityCmaintenanceMCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.Last updated748MIT- AlicenseBqualityCmaintenanceEnables integration with Beagle Security API for managing security testing projects, applications, domain verification, and automated penetration tests. Provides 18 tools for creating, monitoring, and retrieving results from security assessments.Last updated171MIT
- AlicenseAqualityBmaintenanceBawbel MCP Server lets any agent scan MCP servers and skill files for security vulnerabilities mid-conversation. Seven tools covering server-card scanning, conformance scoring, rug pull detection, and AVE threat intelligence queries. Powered by the AVE standard with OWASP MCP Top 10 mapping on every finding. Free, Apache 2.0, no API key required.Last updated46101Apache 2.0
- AlicenseAqualityCmaintenanceA real security scanning MCP server for medical information systems, supporting port scanning, vulnerability detection, medical system identification, and compliance report generation.Last updated141MIT
- MIT
- AlicenseBqualityCmaintenanceThis MCP server enables AI assistants to control Ligolo-ng operations on a remote Kali Linux machine via SSH, providing tools for managing proxy, agents, tunnels, routes, and listeners for network pivoting during security assessments.Last updated19MIT
- AlicenseAqualityBmaintenanceOWASP Agentic - MCP server providing AI-powered tools and automation by MEOK AI LabsLast updated5MIT
- MIT
- AlicenseAqualityBmaintenanceThe js hook toolkit that all you needLast updated77201,541AGPL 3.0
- AlicenseAqualityCmaintenanceProvides Claude Code with access to a comprehensive bug bounty knowledge base including techniques, payloads, wordlists, and real-world reports through 14 tools for searching, retrieving payloads, and assessing report quality.Last updated1411GPL 3.0
- AlicenseBqualityBmaintenanceAn MCP server that enables AI-assisted mobile security testing by exposing Frida functionality for Android application research. It provides tools for hooking Java methods, manipulating memory, managing device processes, and executing custom Frida scripts.Last updated3712MIT
- AlicenseAqualityBmaintenanceProvides AI agents with 37 OSINT tools and 12 data sources to perform unified reconnaissance, domain analysis, and attack surface mapping. It enables agents to query, correlate, and reason across platforms like Shodan, VirusTotal, and Censys in parallel.Last updated3718518MIT
- AlicenseAqualityCmaintenanceMCP server for TurboPentest — run AI-powered penetration tests and review findings from your coding assistant.Last updated853MIT
- AlicenseBqualityBmaintenanceMCP server for Packmate, a CTF network traffic analyzer, enabling LLMs to analyze network traffic streams, search patterns, and manage pcap files.Last updated16MIT
- AlicenseBqualityCmaintenanceProvides a Model Context Protocol server implementation that allows AI agents and other MCP clients to programmatically interact with DefectDojo, a vulnerability management tool, for managing findings, products, and engagements.Last updated1113MIT
- AlicenseBqualityFmaintenanceProvides access to Shodan API functionality, enabling AI assistants to query information about internet-connected devices for cybersecurity research and threat intelligence.Last updated2341MIT

Snyk API & Web MCP Serverofficial
AlicenseCqualityBmaintenanceConnects AI coding assistants to Snyk API & Web for onboarding scan targets, configuring authentication, running DAST scans, and triaging findings through natural language.Last updated516Apache 2.0- AlicenseAqualityBmaintenanceEnables interaction with the APVISO AI-powered penetration testing platform to manage targets, initiate scans, and retrieve vulnerability findings. It allows developers to integrate security testing workflows directly into MCP-compatible tools like Claude Code and Cursor.Last updated1810MIT
- AlicenseBqualityDmaintenanceAI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.Last updated4731MIT

Sekrd Security Scannerofficial
FlicenseAqualityCmaintenanceEnables deep security auditing of web applications directly from AI IDEs including Cursor and Claude Code. Scans URLs for vulnerabilities, returns security scores with SHIP/BLOCK verdicts, and provides specific fix prompts for remediation.Last updated3- AlicenseAqualityCmaintenanceA security-focused server that integrates with Cursor IDE to provide real-time vulnerability detection, exploit generation, and security insights during software development.Last updated71MIT
- AlicenseAqualityCmaintenanceEnables out-of-band interaction testing by integrating ProjectDiscovery's interactsh service as an MCP server. Allows AI agents to create callback domains, send probes, and capture DNS/HTTP interactions for security testing and verification workflows.Last updated4332MIT
- AlicenseBqualityCmaintenanceEnables security professionals to query and analyze Active Directory attack paths from BloodHound Community Edition data using natural language through Claude Desktop's Model Context Protocol interface.Last updated7987GPL 3.0
- AlicenseAqualityCmaintenanceEnables comprehensive security reconnaissance, vulnerability assessment, and threat intelligence gathering by integrating Shodan's API. It provides tools for searching internet-connected devices, performing DNS operations, and querying the Shodan exploit database.Last updated11Apache 2.0
- AlicenseBqualityDmaintenanceProvides AI agents with structured access to the OWASP Bug Logging Tool (BLT) ecosystem for logging bugs, triaging issues, and managing security workflows. It enables actions like submitting vulnerabilities, tracking contributor leaderboards, and awarding gamified bacon points through a unified interface.Last updated49AGPL 3.0
MCP ConnectorsBrowse all →
53 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Real-time CVE, exploit, and vulnerability intelligence for AI assistants (350K+ CVEs, 115K+ PoCs)
Scan any URL, domain, or IP address for security threats using URLScanner.online. Returns a full security report including: Threat verdict (safe / suspicious / malicious) and 0–100 security score Threat intelligence across 70+ feeds (malware, phishing, blocklists) SSL certificate validity, expiry, issuer, and OCSP status HTTP security headers audit (missing / misconfigured) DNS records (A, AAAA, MX, TXT, NS, SOA) And More! Free to use. No account required. 10 scans/day
Query 90 days of honeypot probe data: IP reputation, scanners, CVE probing, TLS/SSH fingerprints.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
Hunt zero-days by talking to binaries. 40+ tools. Hosted, OAuth + SSO, invite: hi@byteray.ai
urlscan.io URL scanner — search/result keyless, submit needs key
CyberShield - 12 cybersecurity tools: NIS2 mapping, MITRE ATT&CK, vulns, threat intel.
- tlptC
TLPTOracle — 17-tool TIBER-EU TLPT framework: scope, threat intel, scenarios, reports.
Query and retrieve information about various adversarial tactics and techniques used in cyber atta…
CVE intelligence, STRIDE, OWASP test cases via Ansvar Gateway. Cited, OAuth + paid.
A paid remote MCP for developer endpoint scanner MCP, built to return verdicts, receipts, usage logs
- MCP FortressOAuth
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
AI-powered threat intelligence, smart contract auditing, and cybersecurity OSINT.
Paid remote MCP for LLM security scans, jailbreak checks, analytics, checkout, and readiness.
MCP server for the Revensi API. Scan domains from any MCP client.