Security MCP servers

Which security MCP servers actually answer?

Of 561 servers in the official MCP registry that mention Security, we checked 220 remote endpoints on 2026-10-04: 124 answered the MCP handshake, 57 answered but asked for sign-in or payment first, and 39 did not complete it. 326 run on your own machine and cannot be checked from outside.

What this does not tell you: whether a server is safe, or whether its tools do what they say. An answer to the handshake proves the endpoint is up, nothing more.

Ranked by our checks and repository activity, not by votes. How we check.

  1. BlackVeil DNS & Email Security Scanner

    com.blackveilsecurity/dns

    DNS and email security scanner with 81 MCP tools for SPF, DMARC, DNSSEC, SSL, and brand audits.

    Answers the MCP handshake and lists its tools★ 9
  2. Vibes-Coded Agent Security and Commerce Tools

    io.github.doteyeso-ops/mcp-server-vibes-coded

    Agent supply-chain security, scanner consensus, x402 reliability, and commerce MCP tools.

    Answers the MCP handshake and lists its tools★ 3
  3. IntoDNS.ai DNS & Email Security Scanner

    ai.intodns/scanner

    DNS and email security: check SPF, DKIM, DMARC, DNSSEC, DANE and build the records. 45 tools.

    Answers the MCP handshake and lists its tools★ 2
  4. Android Security Analyzer

    io.github.ako2345/android-security-analyzer

    MCP server for static security analysis of Android source code

    Answers the MCP handshake and lists its tools★ 2
  5. agent-security-scanner-mcp

    io.github.sinewaveai/agent-security-scanner-mcp

    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

    runs locally★ 122
  6. FHI MCP Server Security Audit

    dev.workers.fhi-llc-1118.polished-truth-c514/fhi-x402-security-tools

    Free payment guide and Base-USDC x402 MCP security, package, domain, and SEC tools.

    Answers the MCP handshake and lists its tools
  7. SKUit Network & Security Catalog

    ai.skuit/catalog

    AI helper for choosing and speccing network & security products from Cisco, Arista, Juniper and more

    Answers the MCP handshake and lists its tools
  8. Bug Bounty Finder - HackerOne + Bugcrowd + security.txt

    io.github.AnshumanAtrey/bug-bounty-finder

    Bug Bounty Finder - HackerOne + Bugcrowd + security.txt

    Answers the MCP handshake; tool list not available without sign-in
  9. Feldspar free repository security scan

    com.project-feldspar/scan

    Free deterministic security scan of public git repos: OSV.dev vulnerable deps, secrets, config lint.

    Answers the MCP handshake and lists its tools
  10. FillTrust security questionnaire corpus

    com.filltrust/questions

    Guidance for answering vendor security questionnaires. Every result carries the page it came from.

    Answers the MCP handshake and lists its tools
  11. security-tools

    com.rangercheck/security-tools

    Free front-end security check for any website: a grade plus the secrets and keys it exposes.

    Answers the MCP handshake and lists its tools
  12. Aevum Security

    sg.com.aevumsecurity/agent-surface

    Browse Aevum Security's Singapore cybersecurity services and submit a business enquiry.

    Answers the MCP handshake and lists its tools
  13. Compuute MCP Security Scanner

    io.github.Compuute/compuute-scan-api

    Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.

    Answers the MCP handshake and lists its tools
  14. Helixar Security

    ai.helixar/mcp

    Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.

    Answers the MCP handshake and lists its tools
  15. Kloudle Cloud Security Scanner

    io.github.Kloudle/cloud-security-scanner

    AWS cloud security scanners for AI agents — S3, IAM, EC2, EKS, RDS, CloudTrail, CloudWatch Logs

    Answers the MCP handshake and lists its tools
  16. notebooklm-mcp-secure

    io.github.Pantheon-Security/notebooklm-mcp-secure

    Security-hardened NotebookLM MCP with post-quantum encryption

    runs locally★ 85
  17. Security Recipes

    io.github.stevologic/security-recipes

    Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.

    Answers the MCP handshake and lists its tools★ 2
  18. Abnormal Security MCP

    io.github.Servosity/abnormal-mcp

    Abnormal Security email threats, cases, and reporting in your terminal and your AI agents.

    runs locally★ 47
  19. cisa-cybersecurity-mcp-server

    io.github.cyanheads/cisa-cybersecurity-mcp-server

    CISA KEV with BOD 26-04 deadlines, SSVC prioritization, and the ICS advisory corpus (CSAF). Keyless.

    Answers the MCP handshake and lists its tools★ 1
  20. Solana Security Standard

    io.github.Copenhagen0x/solana-security-mcp

    Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.

    runs locally★ 38
  21. connect

    io.github.husk-security/connect

    Find tools ranked by measured behaviour, read agent reviews, and talk to other people's agents.

    Answers the MCP handshake and lists its tools
  22. ShipSafe — Independent security verification

    co.ship-safe/scanner

    Independent security review for AI-built apps: exposed secrets, broken auth, unsafe data access.

    Answers, but requires sign-in before the handshake
  23. Patronus Security

    studio.patronus/control-plane

    Scan text, documents, websites, and MCP metadata for prompt injection and sensitive-data risks.

    Answers the MCP handshake and lists its tools
  24. security-preflight

    io.github.jdhart81/security-preflight

    Static MCP, source-code and injection-indicator checks with redacted signed receipts.

    Answers the MCP handshake and lists its tools
  25. ScanLabsAI Security Scanner

    com.scanlabsai/scanner

    Scan a website for vulnerabilities: OWASP Top 10, CVEs, SSL, headers - with plain-English fixes

    Answers the MCP handshake and lists its tools
  26. HexScan Token Security

    xyz.hexscan/token-security

    Honeypot detection & token risk scan for ERC-20s. Risk score 0-100, tax, source verification.

    Answers the MCP handshake and lists its tools
  27. Security Intel MCP

    com.datakoot/cve-vulnerability-lookup

    CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

    Answers the MCP handshake and lists its tools
  28. signal

    com.returnonsecurity/signal

    Cybersecurity market intelligence: funding rounds, M&A, investors, valuations, corporate lineage.

    Answers, but requires sign-in before the handshake
  29. cve-intelligence

    com.cve-security/cve-intelligence

    CVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.

    Answers the MCP handshake and lists its tools
  30. Security Mcp

    io.github.varvararatta/security_mcp

    MCP server for Security

    Answers, but requires sign-in before the handshake

Showing the top 30 of 561. Search all.