Skip to content

Best-of MCP topic

Best MCP Servers for Security

Top MCP servers for security scanning, secrets management, and audit tools. Keep your AI agent workflows secure.

20 servers · Updated 2026 · From 2805 reviewed

Top Picks

#1 Excalidraw Scan found nothing
3 stars

Security-hardened Excalidraw MCP server with auth, rate limiting, and 14 tools

Compatibility

Claude CodeFull support
Tested
CursorFull support
Tested
VS CodeFull support via Copilot
Tested
WindsurfFull support
Tested
Claude DesktopFull support
Tested

Install

Claude Code

claude mcp add excalidraw-mcp-server -- npx -y excalidraw
#2 Aegis Scan found nothing
2 stars

Credential isolation for AI agents. Inject secrets at the network boundary.

Compatibility

Claude CodeFull support
Tested
CursorFull support
Tested
VS CodeFull support via Copilot
Tested
WindsurfFull support
Tested
Claude DesktopFull support
Tested

Install

Claude Code

claude mcp add aegis -- npx -y aegis
#3 Mund — MCP Security Scanner Scan found nothing
0

Scan for prompt injection, secrets, PII, and vet MCP servers before installation

Compatibility

Claude CodeFull support
Tested
CursorFull support
Tested
VS CodeFull support via Copilot
Tested
WindsurfFull support
Tested
Claude DesktopFull support
Tested

Install

Claude Code

claude mcp add weave-protocol -- npx -y mund

All Security Servers

Beelzebub

Scan found nothing
by mariocandela

Beelzebub is a honeypot framework that lets you build honeypot tools using MCP. Its purpose is to detect prompt injection or malicious agent behavior. The underlying idea is to provide the agent with tools it would never use in its normal work.

security Go stdio
1.9k
View

Safedep MCP Server

Scan found nothing
by safedep Official

vet-mcp checks open source packages—like those suggested by AI coding tools—for vulnerabilities and malicious code. It supports npm and PyPI, and runs locally via Docker or as a standalone binary for fast, automated vetting.

security Go stdio
976
View

Skylos

Scan found nothing
by duriantaco

Dead code detection, security scanning, and code quality analysis for Python, TypeScript, and Go. 98% recall with fewer false positives than Vulture. Includes AI-powered remediation.

security Python stdio
claude mcp add skylos -- uvx skylos
336
View

MCP Ts Template

Scan found nothing
by cyanheads

TypeScript template for building MCP servers with declarative tooling, observability, and auth.

security TypeScript stdio
claude mcp add mcp-ts-template -- npx -y mcp-ts-template
119
View

MCP Shodan

Scan found nothing
by BurtTheCoder

MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.

security TypeScript stdio
claude mcp add mcp-shodan -- npx -y shodan
115
View

MCP Virustotal

Scan found nothing
by BurtTheCoder

MCP server for querying the VirusTotal API. This server provides tools for scanning URLs, analyzing file hashes, and retrieving IP address reports.

security TypeScript stdio
claude mcp add mcp-virustotal -- npx -y virustotal
113
View

Snyk MCP Server

Scan found nothing
by snyk

Easily find and fix security issues in your applications leveraging Snyk platform capabilities.

security Go stdio
75
View

MCP Dandan

Scan found nothing
by 82ch

Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across multiple threat detection engines.

security Python stdio
59
View

MCP Panther

Scan found nothing
by panther-labs Official

MCP server that enables security professionals to interact with Panther's SIEM platform using natural language for writing detections, querying logs, and managing alerts.

security Python stdio
42
View

Studio MCP

Scan found nothing
by snyk Official

Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs.

security Go stdio
26
View

AIM Guard MCP

Scan found nothing
by AIM-Intelligence

Security-focused MCP server that provides safety guidelines and content analysis for AI agents.

security TypeScript stdio
20
View

Repository Intelligence

Scan found nothing
by nirholas

Analyze repos of any size - security scanning code analysis monorepo support

security Python stdio
claude mcp add lyra-intel -- uvx repo-intel
19
View

Redmine MCP Server

Scan found nothing
by jztan

Production-ready MCP server for Redmine with security, pagination, and enterprise features

security Python stdio
claude mcp add redmine-mcp-server -- uvx redmine-mcp-server
16
View

MCP Server Thehive

Scan found nothing
by gbrigandi

A Rust-based MCP server to integrate TheHive, facilitating collaborative security incident response and case management via AI.

security Rust stdio
11
View

Agent Bom

Scan found nothing
by msaad00

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

security Python stdio
claude mcp add agent-bom -- uvx agent-bom
10
View

Prodlint

Scan found nothing
by prodlint

Production readiness for vibe-coded apps. 52 checks for security, reliability, and performance.

security TypeScript stdio
claude mcp add prodlint -- npx -y prodlint
10
View

Vulnicheck

Scan found nothing
by andrasfe

HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.

security Python stdio
claude mcp add vulnicheck -- uvx vulnicheck
9
View

FAQ

What are the best MCP servers for Security?

These are the 20 highest-signal Security servers from a directory of 2805, ranked by stars, maintenance recency and what our automated scan returned. Nobody here has used them: this is a sort, not a review. Excalidraw is top of the list.

How do I install these MCP servers?

Each server page includes one-click install commands for Claude Code, Cursor, and VS Code. Click on any server above to see its install instructions.

Are these MCP servers safe to use?

No. 2,316 of the 2,805 servers here were shallow-cloned and put through five keyword searches in March 2026; 489 were never scanned at all. A green badge means those five searches matched nothing, which is not the same as safe — a grep cannot follow a variable or tell you what a server does once it is running. Read what the scan actually checks at /mcp/security, and read the source before you run anything.

Use the shortlist, then open a concrete workflow

Best-of pages are useful for narrowing options. The next practical move is a specific server detail page or a focused browser-first tool route.