A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks
Agent Skill for PHP security audits - OWASP patterns, vulnerability detection | Claude Code compatible
A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.

Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management, compliance (PCI DSS, GDPR, HIPAA, NIST CSF, ISO 27001) and active response. Connect Claude or any LLM to your SOC. OAuth 2.1, RBAC, multi-cluster, air-gap ready.
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
The AI security agent guards your code.

A security scanner for your LLM agentic workflows
Evidence-grounded repository audit CLI - deterministic scanner, MCP server, live dashboard, and a GitHub Action that posts PR diffs.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Security testing that runs inside the coding agent you already use. Source-available, not open source.