Penetration Testing
Tools and frameworks for security testing, vulnerability scanning, and penetration testing. Enables security professionals to identify and exploit security weaknesses in applications and networks.
MCP ServersBrowse all →
AlicenseAqualityAmaintenanceOpen behavioral litmus for MCP servers — grades A–F across tool-output injection, egress, sensitive-data, and adversarial-input, with reproducible, content-addressed evidence. Tools: run_litmus, verify_attestation.Last updated124867Apache 2.0- AlicenseBqualityDmaintenanceEnables integration with Beagle Security API for managing security testing projects, applications, domain verification, and automated penetration tests. Provides 18 tools for creating, monitoring, and retrieving results from security assessments.Last updated171MIT

Grype MCP Serverofficial
AlicenseAqualityFmaintenanceEnables AI assistants to perform vulnerability scanning using Grype, supporting scans of directories, container images, and packages via the Model Context Protocol.Last updated99Apache 2.0
agentminds-mcpofficial
AlicenseAqualityBmaintenanceMCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.Last updated710MIT
MCP Hub Securityofficial
AlicenseAqualityBmaintenanceSecurity gate that scans MCP servers and Claude Code Skills for vulnerabilities before execution.Last updated72MIT- AlicenseBqualityCmaintenanceConnects Claude Code to a Latent Defense deployment to map GitHub repositories into an infrastructure graph, discover attack paths using the JEPA energy model, and triage findings from the terminal.Last updated85Apache 2.0
- AlicenseAqualityCmaintenanceA comprehensive reconnaissance toolset that provides AI agents with 37 tools across 12 data sources like Shodan and VirusTotal for automated intelligence gathering. It enables agents to perform domain reconnaissance, attack surface mapping, and cross-platform data correlation within a single conversational interface.Last updated2372812MIT

Symbiotic MCP Serverofficial
AlicenseAqualityDmaintenanceEnables security analysis of code and infrastructure files via MCP, using Symbiotic CLI for scanning vulnerabilities.Last updated4MIT
PatrowlIntelMCPofficial
AlicenseAqualityCmaintenanceExposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.Last updated32MIT
operant-mcpofficial
AlicenseAqualityDmaintenanceA comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.Last updated519014MIT- AlicenseAqualityBmaintenanceAn Open Sourced Model Context Protocol (MCP) Local server that gives Claude real-time cybersecurity reconnaissance capabilitiesLast updated1419MIT

@konsulto/mcpofficial
AlicenseAqualityBmaintenanceMCP server that enables Claude Code to drive the Konsulto cybersecurity audit platform from the CLI, including reading and writing findings, managing evidence, and handling scope and assets.Last updated19281MIT- AlicenseAqualityBmaintenanceA universal digital fingerprinting MCP server that combines 103 techniques across TCP, TLS, SSH, HTTP, DNS, and more into a single interface for AI agents, enabling full-spectrum fingerprinting on demand.Last updated2131813AGPL 3.0
- AlicenseAqualityDmaintenanceA Model Context Protocol (MCP) server for the Ghost Security API, providing secure access to security findings and repository data through standardized tools.Last updated7953MIT
- MIT
- AlicenseAqualityAmaintenanceScans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.Last updated5MIT
- AlicenseAqualityBmaintenanceA security scanner for AI coding agents and autonomous assistants that scans code for vulnerabilities, detects hallucinated packages, blocks prompt injection, and provides LLM-powered semantic code review via MCP or CLI.Last updated221,336117MIT
- AlicenseBqualityCmaintenanceMCP server wrapping GDB and GEF for dynamic analysis, enabling interactive debugging and memory inspection via GDB/MI protocol.Last updated141MIT
- AlicenseAqualityBmaintenanceAn MCP server that enables AI assistants to execute NetExec network penetration testing commands via SSH to a Kali Linux machine, supporting protocols like SMB, WinRM, SSH, LDAP, and more.Last updated122MIT
- AlicenseBqualityDmaintenanceProvides a Model Context Protocol server implementation that allows AI agents and other MCP clients to programmatically interact with DefectDojo, a vulnerability management tool, for managing findings, products, and engagements.Last updated1114MIT

Snyk API & Web MCP Serverofficial
AlicenseCqualityAmaintenanceConnects AI coding assistants to Snyk API & Web for onboarding scan targets, configuring authentication, running DAST scans, and triaging findings through natural language.Last updated517Apache 2.0- AlicenseAqualityAmaintenanceMCP server for Cursor that scans codebases for security issues including hardcoded secrets, SAST, vulnerable dependencies, and IaC misconfigurations.Last updated7MIT
- AlicenseAqualityCmaintenanceMCP server exposing LIEF for cross-format binary analysis, enabling parsing, section listing, imports/exports, disassembly, and string extraction for PE, ELF, MachO, DEX, ART, and OAT files.Last updated17MIT
- AlicenseAqualityCmaintenanceAI-powered penetration testing reasoning engine (MCP server) for attack path planning, step scoring, and tool recommendations using Beam Search and Monte Carlo Tree Search.Last updated11MIT
- AlicenseAqualityFmaintenanceAn intentionally vulnerable MCP server for security training, enabling users to practice attacking and defending AI agents through realistic scenarios.Last updated2866MIT
- AlicenseAqualityCmaintenanceMCP server that wraps the Frida dynamic instrumentation toolkit, allowing users to attach to processes, hook functions, enumerate modules and exports, and manage scripts through natural language.Last updated101MIT
- AlicenseAqualityCmaintenanceMCP server for Android APK triage, providing tools to parse APK headers, list DEX classes, and decode AndroidManifest.xml using apktool or androguard backends.Last updated51MIT
- AlicenseBqualityBmaintenanceEnables security teams to run controlled adversarial penetration tests against authorized ML/LLM API endpoints, scoring responses and generating evidence for compliance frameworks such as SOC 2, ISO 27001, and GDPR.Last updated62MIT
- AlicenseAqualityBmaintenanceMCP server for DefectDojo vulnerability management, exposing 24 tools for managing products, engagements, tests, findings, scan imports, and finding lifecycle through the Model Context Protocol.Last updated24MIT
- AlicenseBqualityCmaintenanceA professional-grade network analysis MCP server that integrates Wireshark/TShark, Nmap, and threat intelligence to enable packet capture, network scanning, threat detection, and credential extraction through natural language.Last updated412MIT
MCP ConnectorsBrowse all →
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Verify a skill, tool, or package for malicious behavior before your agent installs it. Hosted.
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
No-account public website privacy risk scans with 20 new scans/day and free recent-result reuse.
Query 90 days of honeypot probe data: IP reputation, scanners, CVE probing, TLS/SSH fingerprints.
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Threat modeling, code/cloud/pipeline scanning, shadow-AI discovery, compliance checks and fixes.
Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP.
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
Free no-account URL security scan: 0-100 Launch Readiness score for any live site in ~15 seconds.
Post-quantum cryptography (PQC) vulnerability scanner. Detects ECDSA, RSA, AES-128 and other quantum-vulnerable algorithms in GitHub/GitLab/Bitbucket repos and Ethereum smart contracts. Returns risk score 0-100, CBOM (CycloneDX 1.6), and migration paths to NIST FIPS 203/204/205. Free tier: 10 scans/day, no key required.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
Security research: MCP registries verify identity, not tool behavior. See gtfo.dev.
Scan configs, files, or text for leaked secrets and obvious misconfigurations. Nothing stored.