— · no license
MCPCAN is a centralized management platform for MCP services. It deploys each MCP service using a container deployment method. The platform supports container monitoring and MCP service token verification, solving security risks and enabling rapid deployment of MCP services. It uses SSE, STDIO, and STREAMABLEHTTP access protocols to deploy MCP。
— · MIT
This open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cross-language examples in .NET, Java, TypeScript, JavaScript, Rust and Python. Designed for developers, it focuses on practical techniques for building modular, scalable, and secure AI workflows from session setup to service orchestration.
— · MIT
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
— · MIT
MCP configuration to connect AI agent to a Linux machine.
— · MIT
A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.
v4.9.1 · Elastic-2.0
The most comprehensive ServiceNow AI toolkit, including a full ServiceNow MCP server: 450+ MCP tools plus 26 AI capabilities (scan, review, build, ops, docs) and a direct BYOK mode. Works with Claude, ChatGPT, Gemini, Cursor, GitHub Copilot and any LLM.
v8.13.0 · MIT
SAP ABAP ADT MCP server with full CRUD for on-prem and ABAP Cloud (BTP), plus JWT/XSUAA and service-key destination auth
v4.4.9 · MIT
AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.
v1.25.0 · no license
Official SonarQube MCP Server for code quality and security in AI agents
— · Apache-2.0
MCP server for JADX-AI Plugin
— · MIT
Expose your FastAPI endpoints as Model Context Protocol (MCP) tools, with Auth!
— · no license
Enables hands-on exploration of common MCP security vulnerabilities through locally runnable vulnerable and fixed servers with accompanying exploits and a dashboard.
— · no license
🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️
— · no license
BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language instead of complex Cypher queries.
v0.1.3 · AGPL-3.0
Rust MCP server and CLI for Tailscale devices, users, keys, policies, and auth.
— · Apache-2.0
Production-Ready MCP Server Framework • Build, deploy & scale secure AI agent infrastructure • Includes Auth, Observability, Debugger, Telemetry & Runtime • Run real-world MCPs powering AI Agents
— · MIT
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
— · MIT
Wassette: A security-oriented runtime that runs WebAssembly Components via MCP
— · Apache-2.0
IAM Policy Autopilot is an open source static code analysis tool that helps you quickly create baseline AWS IAM policies that you can refine as your application evolves. This tool is available as a command-line utility and MCP server for use within AI coding assistants for quickly building IAM policies.
— · MIT
lunar.dev: Agent native MCP Gateway for governance and security
— · no license
Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.
— · MIT
MCP server that connects AI assistants to HackerOne for bug bounty hunting
v0.2.2 · no license
Score agent manifests, generate CI workflows, and pull Clarx scan findings into your IDE.
— · GPL-3.0
All-in-One malware analysis tool.