mcp-security-toolkit
Related Servers
Alternatives to mcp-security-toolkit
No user-submitted related servers found.
Related Servers
- AlicenseAqualityCmaintenance14 atomic MCP tools for AppSec and AI Security engineers: source/schema/prompt audit primitives, JWT inspect, HTTP diff, pentest atoms (default creds, GraphQL introspect, phpggc, interactsh OOB), and a defensive helpers library that fixes the bugs the detectors flag. SARIF output, PyPI Trusted Publishing with Sigstore provenance.14MIT
- AlicenseNot gradedqualityCmaintenanceEnables enterprise MCP security auditing through 12 deterministic no-LLM tools for evidence-gated claims, skill/prompt supply-chain audits, token profiling, and server auth-mode checks.MIT
- AlicenseNot gradedqualityAmaintenancenpm audit for MCP servers. Point it at an MCP server and get a security grade (A–F) covering missing auth, SSRF surface, high-privilege tools, prompt-injection-prone tool descriptions, and leaked secrets.17 npmMIT
- AlicenseNot gradedqualityBmaintenancePassive security scanner that audits a running MCP server against the OWASP MCP Top 10 and grades it A-F. Read-only static analysis of the advertised tools, prompts and resources with console/JSON/SARIF output, and it also runs as an MCP server itself.59 npmMIT
- AlicenseNot gradedqualityAmaintenanceAudits MCP server configurations for security risks including capability inventory, SSRF, prompt injection, and drift detection. Works in read-only mode and can also be used as an MCP server to let AI agents audit their own attack surface.4MIT
- AlicenseNot gradedqualityBmaintenanceSecurity scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.19 npm2MIT
TDQS
Scored across 14 tools
Each tool has a clearly distinct purpose, from auditing agent tool schemas to generating PHP gadget chains. No two tools overlap in functionality or target domain.
All tool names follow a consistent snake_case pattern with a domain-specific prefix (e.g., graphql_introspect, jwt_inspect, wordlist_gen), making them predictable and easy to distinguish.
14 tools is a well-scoped collection for a security toolkit. Each tool serves a distinct purpose without redundancy, and the count is neither too small nor too large for the domain.
The toolkit covers a wide range of security utilities, but there are notable gaps for a generic security toolkit (e.g., no port scanning, exploitation beyond PHP gadget chains, or vulnerability scanning). The focus seems skewed toward MCP and LLM security, but the presence of generic tools like default_creds_lookup suggests a broader scope, which is not fully covered.