Best OWASP MCP Servers
The Open Web Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software through community-led open source software projects, hundreds of chapters worldwide, tens of thousands of members, and by hosting local and global conferences.
Why this server?
Allows fetching OWASP category details by ID, enabling security analysis reference.
AlicenseAqualityDmaintenanceA Model Context Protocol server that wraps the Appknox CLI for mobile application security testing.135 npmMITWhy this server?
Includes security scanning capabilities for OWASP Top-10 vulnerabilities and taint analysis as part of the security scanning features.
AlicenseAqualityAmaintenanceFramework-aware code intelligence MCP server that builds a cross-language dependency graph from source code. 53 integrations (Laravel, Django, Rails, Spring, NestJS, Next.js, and more) across 68 languages. 100+ tools for navigation, impact analysis, refactoring, security scanning, session memory, and CI/PR reports — up to 97% token reduction.292,023 npm180MITWhy this server?
Maps detected security findings to OWASP categories and standards to provide industry-standard vulnerability context.
AlicenseAqualityDmaintenanceAn AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time MITRE CWE data and npm audit. It enables users to perform comprehensive scans for authentication issues, exposed secrets, and dependency risks with structured remediation steps.24 npmMITWhy this server?
Enriches security audit findings with OWASP security categories and standardized vulnerability references.
AlicenseAqualityDmaintenanceAn AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time data from MITRE CWE and npm audit. It enables deep analysis of authentication, API security, and dependencies to provide structured findings and remediation steps.24 npm1MITWhy this server?
Facilitates security auditing based on OWASP standards, utilizing tools like OWASP ZAP for dynamic scanning and Top 10 coverage.
AlicenseBqualityCmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.6MITWhy this server?
Provides structured access to the OWASP Bug Logging Tool (BLT) ecosystem, allowing AI agents to submit issues, triage vulnerabilities, manage security workflows, and track contributor rankings and rewards.
AlicenseBqualityDmaintenanceProvides AI agents with structured access to the OWASP Bug Logging Tool (BLT) ecosystem for logging bugs, triaging issues, and managing security workflows. It enables actions like submitting vulnerabilities, tracking contributor leaderboards, and awarding gamified bacon points through a unified interface.49AGPL 3.0Why this server?
Provides crosswalk mappings between AIGF risks and controls and OWASP frameworks such as the LLM Top 10, enabling users to find AIGF items by OWASP reference keys and map controls to OWASP standards.
Why this server?
Integrates OWASP security guidelines and references for vulnerability classifications and remediation advice, mapping detected issues to OWASP Top 10 categories.
AlicenseAqualityDmaintenanceA security-focused server that integrates with Cursor IDE to provide real-time vulnerability detection, exploit generation, and security insights during software development.754 PyPI2MITWhy this server?
Implements OWASP-aligned security checks for authentication systems, allowing validation against industry-standard security practices
AlicenseBqualityDmaintenanceEnterprise-grade authentication solution that provides secure credential management with encryption, multi-protocol authentication (OAuth2, SAML, LDAP), and real-time threat detection for applications.81AGPL 3.0