stepsecurity-mcp
OfficialRelated Servers
Alternatives to stepsecurity-mcp
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityBmaintenanceStandalone MCP server that provides security scanning, project mapping, and vulnerability fix generation to AI coding assistants.27 npm2MIT
- AlicenseAqualityAmaintenanceMCP server for Cursor that scans codebases for security issues including hardcoded secrets, SAST, vulnerable dependencies, and IaC misconfigurations.7MIT
- AlicenseCqualityDmaintenanceMCP server for ArmorCode security platform enabling finding triage, scans, exceptions, risk scores, and release gate checks via natural language.3713 npmMIT
- FlicenseNot gradedqualityCmaintenanceMCP server for Legit Security that answers questions about security issues, Actions, inventory, posture, and platform usage across one or multiple tenants.-
- FlicenseNot gradedqualityDmaintenanceMCP server that enables generating SBOMs, scanning for CVEs, and checking license compliance in VS Code via natural language with GitHub Copilot.-
- AlicenseNot gradedqualityCmaintenanceMCP server that provides AI coding assistants with access to call graphs, data flows, and security analysis for multi-file vulnerability detection.139Apache 2.0
TDQS
Scored across 30 tools
Tools are generally distinct but the many detection listing tools (e.g., list_anomalous_network_calls, list_blocked_domain_calls, list_https_outbound_calls, list_suspicious_process_events) could cause confusion despite descriptive names. Overlap is minimal due to specific filters.
All tool names follow a consistent verb_noun snake_case pattern (e.g., list_anomalous_network_calls, create_suppression_rule). No mixing of conventions or abbreviations, making the pattern predictable.
30 tools is high but justified for a security monitoring server covering incident response, suppression rules, detection listing, and package exposure. The scope is broad, but each tool has a clear purpose and the count is not excessive given the domain.
The tool surface covers detection management, threat incident analysis, package exposure (CI and dev machines), and suppression rules. Minor gaps exist, such as a generic 'list all detections' tool or user management, but core workflows are well-covered.