Security
Vulnerability scanning, secrets management, and security tooling. 1,151 matching entries in the Forge registry — showing the top 150.
- microsoft/mcp-for-beginnersThis open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cr
- 0x4m4/hexstrike-aiHexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomousl
- firerpa/lamda The most powerful Android RPA agent framework, next generation mobile automation.
- wgpsec/ENScan_GO一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。支持MCP接入
- snyk/agent-scanSecurity scanner for AI agents, MCP servers and agent skills.
- elementalsouls/Claude-BugHunterA Claude Code skill bundle for bug hunting and external red-team work — 71 skills, 15 slash commands, 681 disc
- cyberagiinc/DevDocsCompletely free, private, UI based Tech Documentation MCP server. Designed for coders and software developers
- stacklok/toolhiveToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.
- @aikidosec/mcpAikido MCP server
- mukul975/cve-mcp-serverProduction-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS sco
- cisco-ai-defense/mcp-scannerScan MCP servers for potential threats & security findings.
- utkusen/sast-skillsCollection of agent skills that turn your AI coder into a SAST scanner
- node9-aiAccess control for AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do
- delimit-cliKeep the state. Change the model. Shared context and a multi-model panel across Claude Code, Codex, Cursor, An
- ghostsecurity/skillsGhost Security's collection of AppSec skills for AI coding agents
- @rigour-labs/mcpMCP server + live dashboard for AI code governance — OWASP LLM Top 10 (10/10), real-time MCP App UI, 25+ secur
- semgrep/skillsA collection of skills for AI coding agents from Semgrep
- supply-chain-guardOpen-source supply-chain security scanner, local and offline. Matches known-malicious packages, extensions, pl
- @trusty-squire/mcpTrusty Squire gives coding agents the ability to provision, ship, and pay — without your keys or card ever lea
- grim-mcpSecurity audit for AI agents. Finds code, dependency, exposure, secrets, and active-compromise gaps across any
- mcp-slim-guardMCP proxy for schema compression, tool access control, SSRF protection, injection detection, rate limiting and
- chat-recallShared team knowledge, leaked-secret alerts, ranked code findings and tracked tasks, across every AI coding to
- cisco-ai-defense/a2a-scannerScan A2A agents for potential threats and security issues
- @getmcpm/cliMCP security guard and package manager: block prompt injection, tool poisoning and rug-pulls in Model Context
- Houseofmvps/ultraship"ULTRASHIP" Claude Code plugin — 39 skills, 33 tools, 11 agents for ship-ready workflows: planning, review, pe
- AndrewAltimit/template-repoAgent orchestration & security template featuring MCP tool building, agent2agent workflows, mechanistic interp
- @yawlabs/mcpMCP gateway and orchestrator: one local install fronts every MCP server for Claude Code, Cursor, and VS Code,
- io.github.sinewaveai/agent-security-scanner-mcpSecurity layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
- cogmemai-mcpCogmemAi is a thinking, live memory for everything Ai. It remembers what matters across every session, enforce
- @kryptosai/mcp-observatoryMCP security scanner and CI gate. Test, secure, and monitor MCP servers with attack simulation, schema drift d
- nel-veil-mcpFree passive security scanning for AI agents. Check any domain for email spoofing (DMARC/SPF/DKIM), TLS, secur
- @pan-sec/notebooklm-mcpSecurity-hardened MCP server for NotebookLM API with compliance-ready architecture (GDPR, SOC2, CSSF controls
- @ship-safe/mcpShipSafe MCP server — the independent verifier for AI-built apps: your AI coding agent checks the code it writ
- @microtoll/pqc-scanAn inventory of the cryptography a JavaScript or TypeScript codebase uses, and which of it a large quantum com
- codemoreThe static analyzer your AI agent reads — finds production-blocking bugs in vibe-coded apps (CLI, GitHub Actio
- @grantor/mcpGrantor permission broker for multi-agent frameworks — grant, delegate, check, revoke bounded capabilities ove
- @zebbern/hacktricks-mcpMCP server giving AI agents fast full-text search and section-level retrieval over the HackTricks security wik
- safeinstall-cliLocal-first CLI that blocks risky npm, pnpm, and bun installs before they run. Open source.
- @devlensio/cliDevLens CLI — turn any TypeScript, JavaScript, Python, Go, Rust, or Java codebase into a queryable graph of no
- @j0hanz/filesystem-mcpSecure filesystem MCP server for reading, writing, searching, diffing, and patching files.
- @vantasdk/vanta-mcp-serverModel Context Protocol server for Vanta's security compliance platform
- @yawlabs/mcp-complianceMCP compliance testing: spec suites for MCP 2025-11-25 (88 tests) and 2026-07-28 (103 tests), auto-detected pe
- mcp-bastionReliability + security proxy for the Model Context Protocol (MCP): self-healing connections, runtime tool-secu
- mnki-mcpmnki-mcp — a local MCP proxy that verifies every tools/call against Agent Trust before it reaches the server (
- @takescake/1password-mcpMCP server for 1Password service accounts — tools, prompts, and resources for vault and credential management
- import-guardian-mcpCatch AI-hallucinated (slopsquatted) npm imports in generated code BEFORE npm install. Scans a code block, fla
- savesavesavesaveCheck messages, npm packages and crypto addresses before acting. The engine behind savesavesavesave.xyz, for s
- @atlasent/mcp-serverAtlaSent stops risky changes to production unless someone approved them, and gives you proof for your auditor.
- @celorodrigues/token-safety-mcpMCP server for Base L2 token safety: bytecode scans, swap simulations, approval and liquidity risk, and the li
- marketnow-mcpMarketNow MCP Server v1.15.0 — SECURITY: fail-closed ATC trust verification (trusted CA required, revocation e
- @omarei/hushEnvelope-encrypted team secrets your AI agent can use but never read. Zero dependencies, zero servers — your g
- @4da/mcp-serverDependency intelligence for AI coding agents. Live CVE scanning, dependency health, upgrade planning, ecosyste
- onepassword-mcp-serverMCP server for interacting with 1Password via the CLI
- taskbounty-checkPre-launch safety check for AI-built apps (Lovable, Bolt, Replit, Cursor, v0). Scans your GitHub Actions + CI
- dsh-cert-mcpRead-only MCP server exposing the dsh-plugin-certification registry: certification grades, snapshots and five-
- @getaegis/cliCredential isolation for AI agents. Store, guard, and record — your agent never sees your API keys.
- intodns-mcpMCP server for IntoDNS.ai — complete DNS, email security, scan, BIMI, API, and citation tools for AI assistant
- @aimarket/wardenMCP security firewall: vet tool definitions before they reach the model.
- @slidingbox/hydrate-dehydrate-mcpMCP server for Slidingbox: hand a secret from one agent to another as an encrypted, pay-per-read, delivered-on
- @ostico/bruno-mcpAn MCP server that turns an agent's API testing into files you keep: it authors and edits Bruno collections in
- claude-skill-security-auditorClaude Code skill for running structured security audits with actionable remediation plans
- correctover-mcp-serverCompatibility package for Correctover runtime security. The legacy standalone MCP server has been replaced by
- mcp-server-scfMCP server for the SCF Controls Platform — security compliance controls, frameworks, evidence, and risk manage
- dechonet-mcpDomain security reconnaissance MCP server — 20 tools for AI agents. DNS, SSL, HTTP headers, email auth, port s
- @jarroba/mcpMCP server (stdio, local) exposing 120 deterministic tools from Jarroba Tools, reusing the same code as the we
- claude-pentest-skillsStructured web application penetration testing with OWASP methodology, curated payload references, 6-gate vali
- @skarn-security/skarnSkarn - AI coding session security scanner. Single static binary; this launcher resolves and runs the prebuilt
- owasp-mcp-scanSecurity scanner for Model Context Protocol (MCP) servers. Audits running servers against the OWASP MCP Top 10
- @trustlists/mcptrustlists MCP server: find public vendor trust centers, analyze SOC 2 reports, and request trust-center acces
- ModelContextProtocol-Security/modelcontextprotocol-security.ioOfficial website and documentation hub for the Model Context Protocol Security initiative. Provides security g
- flutter-apk-securityReview Flutter Android APK/AAB release artifacts for manifest, permission, cleartext traffic, exported compone
- @black-duck/mcp-serverBlack Duck MCP brings Signal's AI-powered security analysis directly into your development environment. Provid
- capiscio/a2a-demosDemo agents showcasing CapiscIO Agent Guard and MCP Guard — trust badges, identity verification, and tool-leve
- @abyssbugg/sourcerySourcery security findings for AI coding agents: MCP server, findings CLI, and remediation prompt builder over
- @domainintel/mcpMCP server for domain intelligence: WHOIS, DNS, SSL/TLS, security headers, reputation, and subdomain analysis
- visus-mcpSecurity-first MCP server. Sanitizes web content before it reaches your LLM — strips prompt injection, redacts
- @sidclaw/sdkGovernance SDK for AI agents — identity, policy, approval, and audit
- federal-compass-mcpYour AI compass from private sector to federal career — MCP server for USAJobs API
- api-key-caseKeep API keys out of AI coding sessions with local scanning, OS secret storage, and guarded CLI deployment.
- io.github.ashlrai/phantom-secrets-mcpStop AI coding agents from leaking API keys. Local proxy swaps real secrets for phm_ tokens.
- @yawlabs/electron-mcpElectron MCP server: IPC scaffolding, security audits, CSP and fuses config, build-error diagnosis, and versio
- gadrielGadriel - Code-security CLI for AI-assisted development
- reputa-mcpMCP server exposing Reputa on-chain wallet risk & security analysis and neutral DeFi cover (insurance) analyse
- @yawlabs/npmjs-mcpnpm MCP server: registry tools for package metadata, security audits, dependency trees, and write ops (depreca
- @backbond/agent-scanLocal deterministic pre-attachment security scanner for MCP and AI-agent tool manifests.
- shrike-mcpMCP server for action governance on AI agents — 14 tools that govern tool calls, SQL queries, file writes, she
- @mcplookup/mcpOfficial stdio compatibility wrapper for the MCPLookup remote MCP server.
- @digicatalyst/dep-diff-mcpMCP server that translates a lockfile diff into a human-readable upgrade plan.
- com.blackveilsecurity/dnsDNS and email security scanner with 80 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.
- ipgeolocation-io-mcpOfficial MCP server for IP geolocation, IP security, abuse contacts, ASN, timezone, astronomy, and user-agent
- phi-guard-mcpLocal-first MCP server that detects PHI flowing into LLM prompts, logs, and analytics calls in source code
- mcp-stdio-shellguardDefense-in-depth bundle for MCP stdio servers: drop-in guard for child_process.exec/spawn, AST audit CLI for u
- @cyanheads/attack-surface-mcp-serverPassive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan via MCP. ST
- @mukundakatta/shellquote-mcpMCP server for safe shell argument escaping (bash, sh, cmd.exe, PowerShell). Stops LLM-generated shell command
- ia-security-skillAuditoria de segurança defensiva pré-entrega para projetos Claude Code. Cobre web, mobile (MASVS), cloud/IaC,
- guardvibeSecurity infrastructure your AI can't be — deterministic, current past your model's training cutoff, whole-rep
- ledd-mcp-audit-serverMCP server interface for AI agent and MCP security auditing — config analysis, trust audits, prompt injection
- @clavisagent/mcp-serverMCP server for secure credential management. Handles encrypted storage, auto token refresh, and rate limiting
- dingdawg-shieldGovernance receipts for AI agents — AI-driven security scanning with a stack-specific threat model, signed aud
- io.github.zw008/vmware-nsx-securityVMware NSX security: DFW policies, security groups, tags, Traceflow, IDPS — 21 MCP tools.
- vmware-nsx-securityVMware NSX security: DFW policies, security groups, tags, Traceflow, IDPS — 21 MCP tools.
- lazaretto-mcpFree lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
- demipassSecrets management for LLM sessions. Keep credentials out of context windows.
- quantumguard-mcpQuantumGuard MCP Server - Post-quantum cryptography security tools for AI coding agents. Scan for quantum vuln
- vaultboxEncrypted secrets for Next.js. No vault needed.
- @promptguard/mcp-serverPromptGuard MCP server — scan prompts, redact PII, and audit LLM SDK usage from any MCP client
- defiguard-mcpDeFiGuard MCP Server - DeFi protocol risk analysis tools for AI coding agents. Analyze token contracts, detect
- smartguard-mcpSmartGuard MCP Server - AI-powered smart contract security audit tools for Claude Code, Cursor, and AI coding
- PiQrypt/piqryptAI agent governance layer — sign, monitor and control every agent action. EU AI Act · ANSSI · NIST ready.
- vitonique/a2a-secureEnd-to-end encrypted communication for AI agents. The security layer that Google A2A forgot.
- io.github.MCPower-Security/mcpower-proxySecurity proxy that automatically wraps MCP servers with real-time monitoring and policy enforcement
- sabline-langRun code an AI wrote without handing it everything you can reach. Each function declares what it may touch. Yo
- solidity-security-auditComprehensive Solidity smart contract security auditing and vulnerability analysis skill. Based on methodologi
- @palisadeemail/mcpLocal stdio bridge to the Palisade MCP server (email authentication: SPF, DKIM, DMARC, MTA-STS, BIMI).
- @aiwerk/mcp-server-vaultBitwarden/Vaultwarden MCP server — BYOK vault access with 6 tools, Send-based reveal, TOTP, and safe agent-wri
- @sitecurl/mcpMCP server for SiteCurl website governance and audit platform. Run website audits, check scores, track regress
- io.github.Shrike-Security/shrike-mcpAI agent security scanner — prompt injection detection, SQL injection, PII isolation, threat intel.
- io.github.ako2345/android-security-analyzerMCP server for static security analysis of Android source code
- io.github.diemoeve/mcpampelScan installed MCP servers for security vulnerabilities with 16 detection engines.
- @cyanheads/faostat-mcp-serverGlobal food & agriculture statistics from the UN FAOSTAT bulk-download corpus, served from a local SQLite mirr
- io.github.Kurok1/mcp-server-mysqlSecurity-first MySQL MCP server with AST validation, table whitelist, schema resources, and audit.
- @scanlabsai/mcp-serverScanLabsAI security scanner MCP server — scan websites for vulnerabilities and get fixes directly inside Claud
- @jelleo/solana-security-mcpMCP server for the Solana Security Standard (SOL-0XX): scan Solana/Anchor Rust and serve the rules to any MCP
- @getvetai/mcpAn MCP server that discovers MCP servers — search 200K+ AI tools with verification, security data, RAG chat, a
- @gera-services/mcp-geraguardMCP server for PrivacyGuard — privacy scanning, tracker detection, data broker opt-outs, and personal data pro
- io.github.eltociear/secrets-audit-mcpDetects leaked secrets & API keys: 32+ provider rules (AWS, GitHub, Stripe, OpenAI…), zero deps.
- io.github.lordbasilaiassistant-sudo/base-security-scanner-mcpMCP server to scan smart contracts on Base for honeypots, rug pulls, and vulnerabilities.
- io.github.rom-baro/arcwall-securitySecurity scanning for AI coding tools. Detects secrets, threat models, and runs pre-commit checks.
- @cyanheads/pentest-mcp-serverOffline methodology engine for authorized penetration testing, CTF, and security research.
- @opzyai/mcpLocal-first security check MCP server for AI coding agents — finds hardcoded secrets, exposed .env files, secr
- secrets-le-mcpDetect hardcoded secrets in source and config, reporting masked previews and never the values themselves.
- io.github.ECD5A/tkach-securityFail-closed MCP adapter for untrusted model output over a local Tkach runtime.
- io.github.gaurav-kumar-sinha-060705/singularityFind, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
- rubrik-mcpConnect AI assistants to the Rubrik Security Cloud GraphQL API to discover, query, and automate.
- raven-verify-mcpLocal developer-preview MCP tool (raven_verify_token): run Raven's deterministic Solana token-launch verifier
- QWED-AI/qwed-a2aFail-closed Agent-to-Agent verification, provenance, and attestation infrastructure for AI systems.
- ai.helixar/mcpSecurity tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
- com.arcself/arc-securityScan AI agent skills for 25 attack classes + runtime monitoring. 1,316+ findings.
- com.olyport/cdc-sviSVI scores and theme breakdowns by county and tract
- io.github.Ansvar-Systems/ot-security-mcpOT security standards: IEC 62443, NIST 800-82/53, MITRE ATT&CK for ICS
- io.github.Compuute/compuute-scan-apiScan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
- io.github.DevInder1/tridentchain-securityLocal supply-chain CVE scanner via OSV/NVD. Scans deps and IDE extensions. No upload.
- io.github.Kloudle/cloud-security-scannerAWS cloud security scanners for AI agents — S3, IAM, EC2, EKS, RDS, CloudTrail, CloudWatch Logs
- io.github.NeuraLegion/mcpAI-powered application security testing — scan APIs, discover endpoints, and find vulnerabilities.
- io.github.Nomadu27/insaitsRuntime AI-to-AI security monitor. 23 anomaly types, OWASP MCP Top 10 coverage.
- io.github.RobotFleet-HQ/security-orchestraMulti-agent MCP platform for data centers and critical power.
- io.github.Servosity/abnormal-mcpAbnormal Security email threats, cases, and reporting in your terminal and your AI agents.
- io.github.Tyox-all/mundScan for prompt injection, secrets, PII, and vet MCP servers before installation
- io.github.dalisecurity/frayWAF security testing: 5,500+ payloads, 25 WAF fingerprints, 21 recon checks, bypass AI
- io.github.fino-oss/contract-scannerScans Base L2 smart contracts for security risks. Risk score 0-100, detects backdoors & proxies.
Other topics