Sandbox
25 repos for β€œmcp-security” Β· SecurityClear
Puliczek/
awesome-mcp-security

πŸ”₯πŸ”’ Awesome MCP (Model Context Protocol) Security πŸ–₯️

734
google/
mcp-security

MCP servers for Google SecOps, GTI, SOAR, and SCC.

524
FuzzingLabs/
mcp-security-hub

A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.

784
mcp-security-standard/
mcp-server-security-standard

MCP Server Security Standard (MSSS): an open, testable security control standard for certifying MCP servers, with levels, evidence requirements, and reporting schemas.

74
Synvoya/
codeinspectus

Local-first MCP security scanner for AI-generated apps. Scan β†’ fix β†’ rescan from Claude Code, Cursor, Codex, and other agents.

45
sinewaveai/
agent-security-scanner-mcp

Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.

121
TheLunarCompany/
lunar

lunar.dev: Agent native MCP Gateway for governance and security

491
MCP-Manager/
MCP-Checklists
MCP-Manager/MCP-ChecklistsTutorials & Guides

A set of MCP security checklists and guides for agents and MCP servers.

196
sjkim1127/
Reversecore_MCP

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST β€” powered by Radare2, YARA, LIEF, Capstone, and more.

201
MCP-Defender/
MCP-Defender

Desktop app that automatically scans and blocks malicious MCP traffic in AI apps like Cursor, Claude, VS Code and Windsurf.

257

Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.

46

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

4k
lasso-security/
mcp-gateway

A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.

385
w0h1v/
mcp-virustotal

MCP server for VirusTotal API β€” analyze URLs, files, IPs, and domains with comprehensive security reports, relationship analysis, and pagination support.

149
appsecco/
pentesting-mcp-servers-checklist

A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.

40

Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.

814

Reticle intercepts, visualizes, and profiles JSON-RPC traffic between your LLM and MCP servers in real-time, with zero latency overhead. Stop debugging blind. Start seeing everything.

118
OWASP/
OWASP-MCP-Governance-and-Risk-Project

A practical governance framework for organizations adopting the Model Context Protocol (MCP), the open standard that lets AI agents connect to external tools, data sources, and systems.

77

πŸ€– Curated AI OSINT resources β€” Google dorks, Shodan queries, GitHub dorks, and techniques to discover exposed LLM endpoints, leaked AI API keys, misconfigured vector databases, and unprotected AI agents

164
KryptosAI/
mcp-observatory

CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.

146
microsoft/
mcp-for-beginners
microsoft/mcp-for-beginnersTutorials & Guides

This open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cross-language examples in .NET, Java, TypeScript, JavaScript, Rust and Python. Designed for developers, it focuses on practical techniques for building modular, scalable, and secure AI workflows from session setup to service orchestration.

17k