mcp-security-toolkit
Related Servers
Alternatives to mcp-security-toolkit
- AlicenseNot gradedqualityAmaintenanceEnables AI coding assistants to control and inspect a live Chrome browser through Chrome DevTools. Provides browser automation, performance analysis, debugging capabilities, and network request monitoring.1,010,088 npm52,375Apache 2.0
Related Servers
- AlicenseAqualityCmaintenanceProvides security audit primitives for MCP servers, agent tool schemas, and system prompts, along with pentest utilities like JWT inspection and HTTP diffing.14MIT
- AlicenseAqualityAmaintenanceMCP security server for AI coding agents. 12 tools: pre-install guardian, vulnerability audit, supply-chain attack detection via static code analysis, and CycloneDX 1.6 SBOM generation. Zero runtime dependencies.149 npm15Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables enterprise MCP security auditing through 12 deterministic no-LLM tools for evidence-gated claims, skill/prompt supply-chain audits, token profiling, and server auth-mode checks.MIT
- AlicenseNot gradedqualityAmaintenanceAI-orchestrated security testing via 6 Python tools (recon, port scan, subdomain hunting, frontend scanning, API fuzzing, and nemesis orchestrator) exposed as MCP tools for use by AI agents.MIT
- AlicenseAqualityDmaintenanceSecurity scanning for AI coding tools (Claude Code, Cursor, Windsurf) including secrets detection, MCP config vulnerabilities, agent instruction checks, threat modeling, prompt injection testing, pre-commit security checks, and dependency vulnerability scanning.719 npm1MIT
- AlicenseAqualityDmaintenanceMCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions. 5 MCP tools, no API key required.847 npm1MIT
TDQS
Scored across 14 tools
Each tool has a clearly distinct purpose, covering different security tasks like auditing, credential lookup, introspection, diffing, OOB interaction, JWT inspection, and wordlist generation. There is no overlap that would cause confusion.
Naming conventions are mixed: some use verb_noun (graphql_introspect), noun_verb (agent_tool_risk_audit), or prefix-based (interactsh_register). While readable, the inconsistency can lead to agent confusion about the expected pattern.
With 14 tools, the server provides a comprehensive toolkit without being overwhelming. Each tool appears necessary for the domain, and the count is well within the typical range.
The toolset covers major security assessment areas (static analysis, dynamic testing, credential checks, OOB, JWT, wordlist generation). Minor gaps exist (e.g., lack of network scanning or CVE lookup), but it fulfills its stated purpose well.