mcp-security-guard
Related Servers
Alternatives to mcp-security-guard
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityAmaintenanceScans MCP servers for prompt injection, supply chain attacks, excessive permissions, and code execution risks. Includes an offline blacklist that catches known-compromised packages like LiteLLM 1.82.7/1.82.8 and Trivy with zero latency.19MIT
- AlicenseCqualityDmaintenanceSecurity scanner and MCP server that catches dangerous patterns in MCP servers and AI agent projects, such as leaked secrets, shell execution, and prompt-injection text. Runs as both a CLI and MCP server with CI-friendly severity gates.21MIT
- AlicenseAqualityCmaintenanceSecurity scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.55160 npm6MIT
- AlicenseNot gradedqualityBmaintenanceSecurity scanner and runtime proxy for MCP servers. Catches tool poisoning, prompt injection, and rug-pull attacks (silent tool description changes) before they reach your AI agent. Includes a static scanner and a runtime stdio proxy.51 npmMIT
- AlicenseAqualityAmaintenanceMCP security server for AI coding agents. 12 tools: pre-install guardian, vulnerability audit, supply-chain attack detection via static code analysis, and CycloneDX 1.6 SBOM generation. Zero runtime dependencies.1456 npm15Apache 2.0
- AlicenseAqualityDmaintenanceMCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions. 5 MCP tools, no API key required.877 npm1MIT
TDQS
Scored across 11 tools
Most tools target clearly different objects: config files (audit_mcp_config), live server tools (audit_server_tools), passed-in definitions (analyze_tool_definitions), packages (check_supply_chain), and active probing (adversarial_test). The mild overlap between audit_server_tools and analyze_tool_definitions (both run poisoning checks) and between security_dashboard and query_audit_log is well clarified by descriptions. An agent can reliably pick the right tool.
Strong verb_noun convention throughout (audit_mcp_config, list_mcp_servers, apply_fixes, generate_policy, pin_tools, check_supply_chain, query_audit_log). A couple of noun-only names (security_dashboard, adversarial_test) break the pattern slightly but remain readable and unambiguous.
11 tools is well within the ideal 3-15 range and each maps to a distinct security function (audit, fix, policy, pin, log, supply chain, adversarial, dashboard). No obvious redundancy or padding.
Covers the full security lifecycle: discovery, static/live auditing, remediation, policy generation, pinning, supply-chain checks, adversarial probing, and reporting. Minor gaps exist (no unpin/remove-server operation and no exportable report artifact), but agents can work around these.