Best OWASP MCP Servers
The Open Web Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software through community-led open source software projects, hundreds of chapters worldwide, tens of thousands of members, and by hosting local and global conferences.
Why this server?
Allows fetching OWASP category details by ID, enabling security analysis reference.
AlicenseAqualityDmaintenanceA Model Context Protocol server that wraps the Appknox CLI for mobile application security testing.1314MITWhy this server?
Provides structured access to the OWASP Bug Logging Tool (BLT) ecosystem, allowing AI agents to submit issues, triage vulnerabilities, manage security workflows, and track contributor rankings and rewards.
AlicenseBqualityDmaintenanceProvides AI agents with structured access to the OWASP Bug Logging Tool (BLT) ecosystem for logging bugs, triaging issues, and managing security workflows. It enables actions like submitting vulnerabilities, tracking contributor leaderboards, and awarding gamified bacon points through a unified interface.49AGPL 3.0Why this server?
Supports implementation of protection against OWASP top 10 vulnerabilities through rule creation and configuration.
AlicenseBqualityDmaintenanceProvides seamless integration with Fastly's Next-Gen Web Application Firewall API, enabling AI assistants to manage web application security through natural language interactions.291MITWhy this server?
Facilitates security auditing based on OWASP standards, utilizing tools like OWASP ZAP for dynamic scanning and Top 10 coverage.
AlicenseBqualityDmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.6MITWhy this server?
Maps detected security findings to OWASP categories and standards to provide industry-standard vulnerability context.
AlicenseAqualityDmaintenanceAn AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time MITRE CWE data and npm audit. It enables users to perform comprehensive scans for authentication issues, exposed secrets, and dependency risks with structured remediation steps.26MITWhy this server?
Enriches security audit findings with OWASP security categories and standardized vulnerability references.
AlicenseAqualityDmaintenanceAn AI-powered security audit tool that analyzes codebases for vulnerabilities using real-time data from MITRE CWE and npm audit. It enables deep analysis of authentication, API security, and dependencies to provide structured findings and remediation steps.261MITWhy this server?
Provides read-only access to OWASP testing guides (WSTG, MASTG, ISTG, AITG), enabling precise lookup, natural-language search, and browsing of test procedures with full provenance.
AlicenseAqualityBmaintenanceRead-only MCP server for precise lookup, search, and versioned retrieval of OWASP testing guides (WSTG, MASTG, ISTG, AITG) with full provenance on every result.11Apache 2.0Why this server?
Integrates OWASP security guidelines and references for vulnerability classifications and remediation advice, mapping detected issues to OWASP Top 10 categories.
AlicenseAqualityDmaintenanceA security-focused server that integrates with Cursor IDE to provide real-time vulnerability detection, exploit generation, and security insights during software development.72MITWhy this server?
Implements OWASP-aligned security checks for authentication systems, allowing validation against industry-standard security practices
AlicenseBqualityDmaintenanceEnterprise-grade authentication solution that provides secure credential management with encryption, multi-protocol authentication (OAuth2, SAML, LDAP), and real-time threat detection for applications.81AGPL 3.0