Penetration Testing
Tools and frameworks for security testing, vulnerability scanning, and penetration testing. Enables security professionals to identify and exploit security weaknesses in applications and networks.
MCP ServersBrowse all →
AlicenseAqualityDmaintenanceEnables security analysis of code and infrastructure files via MCP, using Symbiotic CLI for scanning vulnerabilities.4MIT- AlicenseAqualityBmaintenanceEnables AI assistants to run Offensive360 SAST scans on local codebases, returning security findings with file/line, severity, and fixes, plus scan status tracking.2111MIT

Grype MCP Serverofficial
AlicenseAqualityFmaintenanceEnables AI assistants to perform vulnerability scanning using Grype, supporting scans of directories, container images, and packages via the Model Context Protocol.99Apache 2.0
PatrowlIntelMCPofficial
AlicenseAqualityCmaintenanceExposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.32MIT
@konsulto/mcpofficial
AlicenseAqualityBmaintenanceMCP server that enables Claude Code to drive the Konsulto cybersecurity audit platform from the CLI, including reading and writing findings, managing evidence, and handling scope and assets.19231MIT
MCP Security Scannerofficial
AlicenseAqualityDmaintenanceIntegrates Checkov, Semgrep, Bandit, and ASH to provide comprehensive code security analysis for AI coding assistants.1515MIT No Attribution- AlicenseAqualityCmaintenanceMLNops is a local-first MCP server for authorized infrastructure reconnaissance and security posture analysis. It provides DNS, WHOIS, SSL/TLS, subdomain, ASN, cloud exposure, and full-recon tools for MCP clients.415MIT

MCP Hub Securityofficial
AlicenseAqualityDmaintenanceSecurity gate that scans MCP servers and Claude Code Skills for vulnerabilities before execution.72MIT- AlicenseAqualityDmaintenanceA Model Context Protocol (MCP) server for the Ghost Security API, providing secure access to security findings and repository data through standardized tools.7473MIT
- MIT
- AlicenseBqualityDmaintenanceEnables integration with Beagle Security API for managing security testing projects, applications, domain verification, and automated penetration tests. Provides 18 tools for creating, monitoring, and retrieving results from security assessments.171MIT

agentminds-mcpofficial
AlicenseAqualityCmaintenanceMCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.729MIT
Polygraphofficial
AlicenseAqualityAmaintenanceOpen behavioral litmus for MCP servers — grades A–F across tool-output injection, egress, sensitive-data, and adversarial-input, with reproducible, content-addressed evidence. Tools: run_litmus, verify_attestation.41577Apache 2.0- AlicenseAqualityAmaintenanceEnables an LLM to author, validate, and test Wirefilter WAF and Smart Firewall rules using live schema and real CVE exploit templates.71MIT

operant-mcpofficial
AlicenseAqualityFmaintenanceA comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.515723MIT- AlicenseAqualityBmaintenanceEnables Android APK reverse engineering and Flutter runtime injection through a six-step pipeline of decompile, analyze, synthesize, inject, patch, and repackage. Provides MCP tools for authorized security research and penetration testing.891,6183MIT

AgentAuditofficial
AlicenseAqualityDmaintenanceEnables AI agents to scan MCP servers and AI packages for vulnerabilities, prompt injection, and supply chain attacks.7156AGPL 3.0- AlicenseBqualityCmaintenanceConnects Claude Code to a Latent Defense deployment to map GitHub repositories into an infrastructure graph, discover attack paths using the JEPA energy model, and triage findings from the terminal.85Apache 2.0

Appknox MCP Serverofficial
AlicenseAqualityDmaintenanceA Model Context Protocol server that wraps the Appknox CLI for mobile application security testing.1319MIT
SiteLint Auditor MCPofficial
AlicenseAqualityAmaintenanceRuns WCAG accessibility, SEO, performance, and security audits on URLs or raw HTML via SiteLint Auditor. Enables LLM agents to audit web pages and check WCAG criteria through MCP tools.382Mozilla Public 2.0- AlicenseAqualityBmaintenanceThis local MCP server keeps vulnerability intelligence, research scope, scanner results, evidence receipts, Bugcrowd VRT assessments, and report drafts in one SQLite ledger. It is built for authorized defensive research and does not scan, exploit, or submit reports.191MIT
- AlicenseAqualityDmaintenanceProvides 28 MCP tools across 16 analysis engines for comprehensive Python code quality assessment, including complexity scoring, security scanning, dead code detection, dependency auditing, and test quality analysis.28MIT
- AlicenseAqualityBmaintenanceTalk to your Flipper Zero from Claude Code — or any MCP client. Storage, app deployment, screen capture, button automation, JavaScript execution on the device, and honest answers about what is nearby.66MIT
- AlicenseAqualityCmaintenanceMCP server for Android APK triage, providing tools to parse APK headers, list DEX classes, and decode AndroidManifest.xml using apktool or androguard backends.51MIT
- AlicenseAqualityBmaintenancePrivacy-first OSINT scanning MCP server that aggregates ~25 sources into a risk report, running locally with no data leaving your machine.51AGPL 3.0
- AlicenseAqualityCmaintenanceEnables policy-first defensive security operations for MCP, providing repository and web-security analysis with controlled authorization, scoped execution, and auditability.9MIT
- AlicenseAqualityCmaintenanceAn MCP server that lets an AI agent probe a live URL and confirm whether sensitive files (e.g., .git, .env, source maps) are genuinely served by fetching and validating the content, avoiding false positives.291MIT
- AlicenseBqualityFmaintenanceA security testing tool that enables automated vulnerability detection including XSS and SQL injection, along with comprehensive browser interaction capabilities for web application penetration testing.1210022MIT
- AlicenseAqualityBmaintenanceMCP server that enables LLMs to operate Acunetix/Invicti web vulnerability scanners through 15 tools, covering authentication, target management, scanning, vulnerability retrieval, and reporting via GraphQL and REST APIs.151MIT
- AlicenseAqualityAmaintenanceGives AI assistants access to the Exploit Intelligence Platform for vulnerability and exploit intelligence. Supports searching CVEs, exploits, and generating pentest findings.17MIT
MCP ConnectorsBrowse all →
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Query 90 days of honeypot probe data: IP reputation, scanners, CVE probing, TLS/SSH fingerprints.
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Scan agent skills and MCP servers for malicious patterns before you load them
Free lockfile malware check plus paid pre-install scan of any skill, tool, or package.
Check if an MCP server tool changed or hides injection patterns before you trust it.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Verificação de segurança e conformidade de sites: cabeçalhos, TLS, DNS, e-mail, LGPD e pentest.
Exposes FEDLIN's public security scanners as agent-callable tools over Streamable HTTP.
Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes
Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups
Scan any website or MCP server for agent-trust-readiness; returns a signed, verifiable scorecard.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
urlscan.io URL scanner — search/result keyless, submit needs key
Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.