π₯π Awesome MCP (Model Context Protocol) Security π₯οΈ
MCP servers for Google SecOps, GTI, SOAR, and SCC.
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
MCP Server Security Standard (MSSS): an open, testable security control standard for certifying MCP servers, with levels, evidence requirements, and reporting schemas.
Local-first MCP security scanner for AI-generated apps. Scan β fix β rescan from Claude Code, Cursor, Codex, and other agents.
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.
Mantis Hack
lunar.dev: Agent native MCP Gateway for governance and security

Build Secure and Compliant AI agents and MCP Servers. YC W23
A set of MCP security checklists and guides for agents and MCP servers.
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST β powered by Radare2, YARA, LIEF, Capstone, and more.
Desktop app that automatically scans and blocks malicious MCP traffic in AI apps like Cursor, Claude, VS Code and Windsurf.
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.
A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.
MCP server for VirusTotal API β analyze URLs, files, IPs, and domains with comprehensive security reports, relationship analysis, and pagination support.
Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.
A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.
Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.
Reticle intercepts, visualizes, and profiles JSON-RPC traffic between your LLM and MCP servers in real-time, with zero latency overhead. Stop debugging blind. Start seeing everything.
A practical governance framework for organizations adopting the Model Context Protocol (MCP), the open standard that lets AI agents connect to external tools, data sources, and systems.
π€ Curated AI OSINT resources β Google dorks, Shodan queries, GitHub dorks, and techniques to discover exposed LLM endpoints, leaked AI API keys, misconfigured vector databases, and unprotected AI agents
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
This open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cross-language examples in .NET, Java, TypeScript, JavaScript, Rust and Python. Designed for developers, it focuses on practical techniques for building modular, scalable, and secure AI workflows from session setup to service orchestration.