Penetration Testing
Tools and frameworks for security testing, vulnerability scanning, and penetration testing. Enables security professionals to identify and exploit security weaknesses in applications and networks.
MCP ServersBrowse all →
AlicenseAqualityAmaintenanceEnables agents to inspect web pages for Cloudflare Turnstile challenges without an API key, and clear Turnstile or WAF challenges using a SolveGate API key.6330 npm1MIT- AlicenseAqualityAmaintenanceEnables Android APK reverse engineering and Flutter runtime injection through a six-step pipeline of decompile, analyze, synthesize, inject, patch, and repackage. Provides MCP tools for authorized security research and penetration testing.2943 npm5MIT

Appknox MCP Serverofficial
AlicenseAqualityDmaintenanceA Model Context Protocol server that wraps the Appknox CLI for mobile application security testing.135 npmMIT- AlicenseAqualityAmaintenanceMCP server that provides AI-native access to BeVigil's OSINT API, enabling mobile app security research and asset discovery through tools for hosts, subdomains, S3 buckets, URLs, wordlists, and multi-step investigations.6724 npm1MIT
- AlicenseAqualityAmaintenanceEnables an LLM to author, validate, and test Wirefilter WAF and Smart Firewall rules using live schema and real CVE exploit templates.71MIT
- AlicenseBqualityCmaintenanceConnects Claude Code to a Latent Defense deployment to map GitHub repositories into an infrastructure graph, discover attack paths using the JEPA energy model, and triage findings from the terminal.85Apache 2.0

MCP Hub Securityofficial
AlicenseAqualityDmaintenanceSecurity gate that scans MCP servers and Claude Code Skills for vulnerabilities before execution.72MIT- AlicenseBqualityDmaintenanceEnables integration with Beagle Security API for managing security testing projects, applications, domain verification, and automated penetration tests. Provides 18 tools for creating, monitoring, and retrieving results from security assessments.171MIT
- AlicenseAqualityDmaintenanceA Model Context Protocol (MCP) server for the Ghost Security API, providing secure access to security findings and repository data through standardized tools.732 npm3MIT

MCP Security Scannerofficial
AlicenseAqualityDmaintenanceIntegrates Checkov, Semgrep, Bandit, and ASH to provide comprehensive code security analysis for AI coding assistants.1516MIT No Attribution- AlicenseAqualityBmaintenanceEnables AI assistants to run Offensive360 SAST scans on local codebases, returning security findings with file/line, severity, and fixes, plus scan status tracking.238 npmMIT

Grype MCP Serverofficial
AlicenseAqualityFmaintenanceEnables AI assistants to perform vulnerability scanning using Grype, supporting scans of directories, container images, and packages via the Model Context Protocol.99Apache 2.0
@konsulto/mcpofficial
AlicenseAqualityCmaintenanceMCP server that enables Claude Code to drive the Konsulto cybersecurity audit platform from the CLI, including reading and writing findings, managing evidence, and handling scope and assets.1911 npm1MIT- AlicenseAqualityDmaintenanceEnables AI assistants to execute security testing tools on a Kali Linux machine over SSH, including reconnaissance, web app scanning, and static/dynamic analysis.115 npmMIT

operant-mcpofficial
AlicenseAqualityFmaintenanceA comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.5149 npm23MIT
agentminds-mcpofficial
AlicenseAqualityCmaintenanceMCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.74 npmMIT
SiteLint Auditor MCPofficial
AlicenseAqualityAmaintenanceRuns WCAG accessibility, SEO, performance, and security audits on URLs or raw HTML via SiteLint Auditor. Enables LLM agents to audit web pages and check WCAG criteria through MCP tools.3689 npmMozilla Public 2.0- AlicenseAqualityBmaintenanceEnables MCP-native multi-agent security audits for Google Antigravity, orchestrating subagents for 0day research, static analysis, PoC verification, exploit chaining, reporting, and code remediation.8153MIT
- AlicenseBqualityFmaintenanceA security testing tool that enables automated vulnerability detection including XSS and SQL injection, along with comprehensive browser interaction capabilities for web application penetration testing.312246 npm22MIT
- AlicenseAqualityBmaintenanceThis local MCP server keeps vulnerability intelligence, research scope, scanner results, evidence receipts, Bugcrowd VRT assessments, and report drafts in one SQLite ledger. It is built for authorized defensive research and does not scan, exploit, or submit reports.191MIT

AgentAuditofficial
AlicenseAqualityDmaintenanceEnables AI agents to scan MCP servers and AI packages for vulnerabilities, prompt injection, and supply chain attacks.710 npmAGPL 3.0
PatrowlIntelMCPofficial
AlicenseAqualityCmaintenanceExposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.32MIT
Symbiotic MCP Serverofficial
AlicenseAqualityDmaintenanceEnables security analysis of code and infrastructure files via MCP, using Symbiotic CLI for scanning vulnerabilities.4MIT
Polygraphofficial
AlicenseAqualityAmaintenanceOpen behavioral litmus for MCP servers — grades A–F across tool-output injection, egress, sensitive-data, and adversarial-input, with reproducible, content-addressed evidence. Tools: run_litmus, verify_attestation.463 npm8Apache 2.0- AlicenseAqualityCmaintenanceMCP server exposing LIEF for cross-format binary analysis, enabling parsing, section listing, imports/exports, disassembly, and string extraction for PE, ELF, MachO, DEX, ART, and OAT files.17MIT
- AlicenseAqualityDmaintenanceA security-focused server that integrates with Cursor IDE to provide real-time vulnerability detection, exploit generation, and security insights during software development.72MIT
- AlicenseAqualityDmaintenanceProvides an MCP interface to a full Kali Linux environment running in Docker, enabling AI assistants to execute security tools like nmap, sqlmap, and metasploit. It allows users to start/stop the container, run shell commands, and transfer files for security testing and educational purposes.75 npm4MIT
- AlicenseAqualityFmaintenanceEnables AI assistants to perform password security auditing using John the Ripper on a remote Kali system via SSH, supporting cracking, hash management, and session control.12MIT
- AlicenseAqualityBmaintenanceA MCP-enabled asset mapping and vulnerability scanning agent with AI self-reflection, allowing natural language queries and automated scanning decisions.15722Apache 2.0
- AlicenseAqualityCmaintenanceProvides AI agents with 37 OSINT tools and 12 data sources to perform unified reconnaissance, domain analysis, and attack surface mapping. It enables agents to query, correlate, and reason across platforms like Shodan, VirusTotal, and Censys in parallel.37164 npm49MIT
MCP ConnectorsBrowse all →
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Production-safety audits for AI-generated code, with a fix for every finding.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Check a live app you own for public databases, leaked keys and exposed files.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Check breach exposure for your verified email and check locally computed password hash prefixes.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Explain a regex in plain English and detect catastrophic backtracking risk.
Penetration Testing Cost: the site's own MCP server — enquiry (enquiry = a human handoff, not a...
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Experimental MCP server for current empirical verification of explicit public HTTPS endpoint claims.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Free, read-only security scanner for remote MCP servers, before you connect them.
Exploit-DB: new public exploits & PoCs, daily. Register in-session — free testnet funds.
ドメインの設定を調べる MCP サーバー。SPF / DKIM / DMARC・DNS・SSL 証明書・セキュリティヘッダ・サブドメイン・類似ドメインを、公開情報だけで確認します。登録不要・無料。
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.