security-framework-mcp
Related Servers
Alternatives to security-framework-mcp
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityBmaintenanceAn MCP server that automates vulnerability correlation across security tools like Checkmarx and Tenable, using LLMs to determine reachability, map compliance controls (SOC2, ISO27001), and generate remediation and regression testing patterns.MIT
- AlicenseCqualityDmaintenanceEnterprise-grade MCP server for static application security testing with multi-tool integration, compliance verification, AI-powered remediation, and multi-tenant management.2310MIT

operant-mcpofficial
AlicenseAqualityFmaintenanceA comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.5136 npm23MIT- FlicenseNot gradedqualityDmaintenanceMCP server for automated architectural mapping, security vulnerability detection, ML asset tracking, and code metrics in local repositories.-
- AlicenseBqualityCmaintenanceA comprehensive MCP server for structured threat modeling using STRIDE methodology, with automatic code validation and report generation.100103Apache 2.0
- FlicenseNot gradedqualityBmaintenanceMCP server for ConnectSecure vulnerability management, exposing 285 read-only tools to query assets, vulnerabilities, Active Directory, and more via natural language.-
TDQS
Scored across 41 tools
Each tool has a clearly distinct purpose, targeting specific data sources (e.g., OWASP, NIST, CVE) or actions (e.g., assess, search, map). Even with many similar 'get_' tools, the target differs explicitly (e.g., get_top10 vs get_api_top10 vs get_llm_top10). No two tools appear to do the same thing.
The majority of tools follow a verb_noun pattern (e.g., get_asvs, search_cve, assess_mcp_security). However, a few tools like 'database_status' (noun_noun) break the pattern. The inconsistency is minor but present.
With 41 tools, the server is well beyond the typical 3-15 range. While the comprehensive coverage of multiple security frameworks justifies the count, the number is high and could be streamlined. Some tools are very similar (e.g., multiple 'get_top10' variants), making the set feel oversized.
The tool set covers an exhaustive range of security frameworks and data sources: OWASP (Top 10, API, LLM, MCP, ASVS, MASVS, WSTG, CheatSheets, Proactive Controls, Projects), NIST (CSF, SP 800-53, RMF, PF, Glossary, Publications, CMVP, NICE), CVE/KEV, compliance mappings, threat modeling, and triage. No obvious gaps for its stated purpose.