Security
Identity and security management tools. Enables authentication, data protection, and system monitoring.
MCP ServersBrowse all →
AlicenseAqualityDmaintenanceTrust Graduation gate for AI agents: visible approval ceremonies and receipt-backed boundaries for consequential actions.8545 npmApache 2.0
AISIX AI Gatewayofficial
AlicenseAqualityAmaintenanceSelf-hosted MCP gateway that registers upstream MCP servers and fronts them behind one governed Streamable HTTP endpoint: per-tool access control by caller API key, guardrails over tool arguments and results, rate limits, and usage logs. The same Rust gateway also proxies LLM and A2A agent traffic.21152Apache 2.0
DataNexus MCPofficial
AlicenseAqualityBmaintenanceProvides AI-ready access to US/UK nonprofit data and OSS vulnerability intelligence via MCP, with 10 tools and no API key required.655358 npm3-- AlicenseAqualityAmaintenancePolicy proxy that governs what AI assistants can reach and do: it refuses forbidden tool calls before the upstream is contacted, with per-user memory and a tamper-evident audit. Stops prompt-injection exfiltration and forbidden data combinations across connectors.2121Apache 2.0

WhisperGraphofficial
AlicenseAqualityCmaintenanceSelf-hostable MCP server for WhisperGraph — a graph of 7.39B nodes / 39B edges mapping DNS, BGP, GeoIP, WHOIS, and threat intelligence. Six read-only tools (Cypher query + schema introspection + threat assessment), six resources, eight investigation prompts. stdio and Streamable HTTP transports.826 npm1Apache 2.0
Strac MCP DLPofficial
AlicenseAqualityAmaintenanceDetect and redact PII, PHI, PCI and secrets — SSNs, credit cards, passports, API keys and cloud credentials — in text and in local files, using the Strac DLP API. Five tools: redact_text, detect_sensitive_data, detect_file, redact_file and detokenize.57MIT- AlicenseBqualityAmaintenanceGCHQ CyberChef's 504 data-transformation operations as MCP tools — encryption, encoding, compression and forensics — w/ 19 analysis tools for work a single operation cannot express, such as: hash identification, RSA and ECDSA attacks, XOR key-length recovery, cipher solving, X.509 chain validation and NIST post-quantum identification (ML-KEM/ML-DSA/SLH-DSA).8231,416 npm19GPL 3.0

ZeroPath MCP Serverofficial
AlicenseBqualityDmaintenanceAllows developers to query security findings (SAST issues, secrets, patches) using natural language within AI-assisted tools like Claude Desktop, Cursor, and other MCP-compatible environments.179MIT
Fidensa MCP Serverofficial
AlicenseAqualityDmaintenanceEnables AI agents to verify trust scores, search certified capabilities, compare side-by-side, and submit experience reports through Fidensa's certification authority.753 npmMIT
Bitwarden MCP Serverofficial
AlicenseBqualityAmaintenanceEnables AI assistants to securely manage Bitwarden vault items, folders, attachments, and organization administration through the Model Context Protocol.594,594 npm252GPL 3.0
@agledger/mcp-serverofficial
AlicenseAqualityBmaintenanceConnects MCP-compatible AI agents to the AGLedger API for change control, recording every change with signed, hash-chained records. Provides API pass-through tools and an offline audit verifier.327 npm-
Hellō Admin MCP Serverofficial
AlicenseAqualityDmaintenanceEnables AI assistants to create and manage Hellō applications with full developer context, supporting app creation, updates, secret generation, and logo management through a single unified tool.120 npm4MIT
a202-mcpofficial
AlicenseAqualityBmaintenanceOfficial reference MCP server for A202, the Verifiable Agreement Protocol for Agent-Led Commerce. Gives an agent the seven capabilities two organisations need to buy and sell directly: issue a mandate, check what an agent may do under it, approve an act needing a person, form an agreement, exchange obligations, verify a record by replay, and read the transaction record back.74Apache 2.0
PatrowlIntelMCPofficial
AlicenseAqualityCmaintenanceExposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.32MIT
pageguard-mcpofficial
AlicenseAqualityFmaintenanceScan any project or website for privacy compliance issues directly in your AI coding tool. Detects tracking tech, cookies, and third-party data collection. Works in Claude Code, Cursor, and Windsurf.324 npm1MIT- AlicenseAqualityBmaintenanceEnables MCP-capable agents to create and invoke OpenServerless endpoints, manage secrets, and configure integrations such as S3, PostgreSQL, Redis, Milvus, and MongoDB.13Apache 2.0

delentia-sovereignofficial
AlicenseAqualityAmaintenanceConnects autonomous AI agents and IDEs to the Delentia Sovereign Edge Network, providing deterministic security gating, structured reasoning, context compression, and swarm coordination tools.535 npmApache 2.0- AlicenseAqualityDmaintenanceExposes the Agent Policy Router (APR) as MCP tools, allowing any MCP-compatible AI agent to gate its actions through compliance policies before execution.12MIT
- AlicenseAqualityCmaintenanceEmail validation MCP server using MailboxValidator API to determine validity of an email address.334 npm1MIT

Symbiotic MCP Serverofficial
AlicenseAqualityDmaintenanceEnables security analysis of code and infrastructure files via MCP, using Symbiotic CLI for scanning vulnerabilities.4MIT
AgentAuditofficial
AlicenseAqualityDmaintenanceEnables AI agents to scan MCP servers and AI packages for vulnerabilities, prompt injection, and supply chain attacks.78 npmAGPL 3.0- AlicenseAqualityCmaintenanceKaspersky OpenTIP Model Context Protocol Server. This server gives access to Kaspersky OpenTIP API to agentic applications.625Apache 2.0

crowdsec-local-mcpofficial
AlicenseBqualityCmaintenanceGenerates, validates, and deploys CrowdSec WAF rules and scenarios through natural language.2422MIT
Precogly MCPofficial
AlicenseAqualityBmaintenanceMCP server for Precogly threat modeling, enabling users to integrate threat modeling capabilities into AI assistants.1Apache 2.0- AlicenseAqualityCmaintenanceProtects AI agents from prompt injection and destructive actions while enabling self-improving prompts through a security pipeline.1028 npmMIT

@attestd/mcpofficial
AlicenseAqualityBmaintenanceEnables checking of package vulnerabilities and supply-chain risks using Attestd API. Supports single and batch checks, CVE details, and covered products listing.423 npmMIT- AlicenseBqualityAmaintenanceProvides redacted access to a private local knowledgebase for coding agents, allowing them to inspect files while hiding sensitive names and identifiers.14141MIT

Trestle MCPofficial
AlicenseAqualityAmaintenanceMCP server to easily use compliance-trestle for OSCAL compliance workflows from any MCP-compliant client.92Apache 2.0- AlicenseAqualityBmaintenanceInvestigate fraud directly from Claude, Cursor, or any MCP-compatible client. Analyze suspicious activity with clear, evidence-backed verdicts. Pivot from a single signup to every account sharing the same device, IP address, or email inbox. Check entities against a cross-operator abuse network, review linked accounts, and efficiently process your fraud review queue. Read-only by default, with no r10232 npmMIT

attest-mcpofficial
AlicenseAqualityDmaintenanceEnables AI agents to scan payment endpoints for safety, returning a letter grade (A–F) and verdict before authorizing payments.221 npmMIT
MCP ConnectorsBrowse all →
Live BGP routing table and registry lookups: IP origin, ASN prefixes, transit, org search.
Pre-trade token safety check for AI agents. Simulates a sell before you buy, then returns one low/medium/high/unknown verdict with the signals behind it: sellability, buy/sell tax, liquidity depth, pair age, same-ticker impersonation, owner powers from bytecode. Ethereum, BSC, Base, Solana. Fail-closed - a check that cannot run answers unknown, never low. Publishes its own measured error rate with the benchmark harness in the repo. Free, no signup, no API key, MIT.
OAuth website audits: security, SEO, AI visibility, integrations, accessibility and performance.
Verify claims, resolve FIGI identity, extract claims, and sign x402 delivery receipts over MCP.
Inspect one endpoint's served certificate, expiry, hostname coverage, and accepted TLS versions.
Zero-auth cryptographic provenance and notarization engine anchoring AI outputs, audits, and agreements to TON Blockchain with strict zero-storage.
Scan, fix, verify and monitor DNS: SPF, DMARC, DKIM, propagation, health, expiry. Validated fixes.
Built for human creators. Register a timestamp on Polygon proving you made something, the moment you did. Your file is never uploaded, watermarked, or altered: only its cryptographic fingerprint ever reaches spArxx.io, zero-knowledge by design. A human still provisions the account behind the connection. This is deliberate, since this registration only means something with a human behind it.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Pre-send EVM address checks: free pre-check, $0.01 check, $0.05 deep scan. x402: payment is auth.
AI URL safety validator: SAFE/SUSPICIOUS/DANGEROUS verdict, trust score, threat intel.
Classify data safety before storing or sharing. GDPR, HIPAA, PCI-DSS, CCPA. AI-powered.
SEO, AEO, GEO, Local SEO & CRO Growth Auditor + Safe Code Fixer with multi-page sitemap crawling, HTTP security headers inspection (HSTS, CSP), and universal WebMCP support.
Live-checks whether a WordPress site is ready to be safely operated by AI agents.
Entity verification, sanctions screening, and trust scoring for AI agents via x402 micropayments.
AI reasoning checks any document against known international standards before your agent acts on it.
DMARC analytics and domain onboarding for AI assistants — health, SPF/DKIM, compliance, anomalies.
Pay-per-call x402 tools for AI agents: onchain, finance, risk, content, web & SEC data on Base.
Persistent knowledge graph for AI-augmented teams. Store decisions, findings, and standing rules across agent sessions with semantic search and typed connections. Includes cross-session memory, audit trail, workspace isolation, and secret detection. Built for teams running agents that need to remember. Free until launch with team tier as default, anon trial available.
Discover Agents and MCP capabilities with versions, permissions, and real-work trust context.