Skip to main content
Glama
x0base

mcp-security-toolkit

by x0base

Related Servers

Alternatives to mcp-security-toolkit

Related Servers

  • A
    license
    A
    quality
    A
    maintenance
    MCP security server for AI coding agents. 12 tools: pre-install guardian, vulnerability audit, supply-chain attack detection via static code analysis, and CycloneDX 1.6 SBOM generation. Zero runtime dependencies.
    14
    9 npm
    15
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables enterprise MCP security auditing through 12 deterministic no-LLM tools for evidence-gated claims, skill/prompt supply-chain audits, token profiling, and server auth-mode checks.
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Security scanning for AI coding tools (Claude Code, Cursor, Windsurf) including secrets detection, MCP config vulnerabilities, agent instruction checks, threat modeling, prompt injection testing, pre-commit security checks, and dependency vulnerability scanning.
    7
    19 npm
    1
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    MCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions. 5 MCP tools, no API key required.
    8
    47 npm
    1
    MIT

TDQS

A4.3/5.0

Scored across 14 tools

Disambiguation5/5

Each tool has a clearly distinct purpose, covering different security tasks like auditing, credential lookup, introspection, diffing, OOB interaction, JWT inspection, and wordlist generation. There is no overlap that would cause confusion.

Naming Consistency3/5

Naming conventions are mixed: some use verb_noun (graphql_introspect), noun_verb (agent_tool_risk_audit), or prefix-based (interactsh_register). While readable, the inconsistency can lead to agent confusion about the expected pattern.

Tool Count5/5

With 14 tools, the server provides a comprehensive toolkit without being overwhelming. Each tool appears necessary for the domain, and the count is well within the typical range.

Completeness4/5

The toolset covers major security assessment areas (static analysis, dynamic testing, credential checks, OOB, JWT, wordlist generation). Minor gaps exist (e.g., lack of network scanning or CVE lookup), but it fulfills its stated purpose well.

Maintenance

ActivityInactive
ResponsivenessNo issues