v4.4.9 · MIT
AI agent security scanner and npm audit for MCP servers, Claude Code, Cursor, and Windsurf. Find prompt injection, hallucinated packages, secrets, unsafe tools, and vulnerable code.
— · MIT
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
— · no license
🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️
v0.0.1 · Apache-2.0
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
— · no license
Enables hands-on exploration of common MCP security vulnerabilities through locally runnable vulnerable and fixed servers with accompanying exploits and a dashboard.
— · MIT
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
v1.25.0 · no license
Official SonarQube MCP Server for code quality and security in AI agents
— · MIT
lunar.dev: Agent native MCP Gateway for governance and security
— · Apache-2.0
A security scanner for your LLM agentic workflows
— · MIT
A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.
— · MIT
This open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cross-language examples in .NET, Java, TypeScript, JavaScript, Rust and Python. Designed for developers, it focuses on practical techniques for building modular, scalable, and secure AI workflows from session setup to service orchestration.
— · GPL-3.0
All-in-One malware analysis tool.
— · Apache-2.0
IAM Policy Autopilot is an open source static code analysis tool that helps you quickly create baseline AWS IAM policies that you can refine as your application evolves. This tool is available as a command-line utility and MCP server for use within AI coding assistants for quickly building IAM policies.
— · Apache-2.0
MCP server for JADX-AI Plugin
— · MIT
Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)
— · no license
Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.
— · MIT
MCP configuration to connect AI agent to a Linux machine.
— · MIT
MCP server that connects AI assistants to HackerOne for bug bounty hunting
v0.1.0 · MIT
Ephemeral data sandbox for AI workflows with guardrails and security
— · MIT
Wassette: A security-oriented runtime that runs WebAssembly Components via MCP
v0.1.3 · MIT License
Enables AI agents to perform passive security scans on domains, checking email spoofing (DMARC/SPF/DKIM), TLS weaknesses, security headers, exposed files, and subdomain-takeover risk without needing an API key.
— · no license
MCPCAN is a centralized management platform for MCP services. It deploys each MCP service using a container deployment method. The platform supports container monitoring and MCP service token verification, solving security risks and enabling rapid deployment of MCP services. It uses SSE, STDIO, and STREAMABLEHTTP access protocols to deploy MCP。
— · no license
BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language instead of complex Cypher queries.
v1.0.0 · no license
Draw your app's architecture on a live canvas and flag the bottlenecks and security gaps.