Skip to content

Directory · topic · 2,075 servers

security

Servers whose registry description an AI model classified as security. Topics are estimates, not hand-checked. All topics.

  • ai.agentrapay/agentraIdentity oracle and trust layer for autonomous AI agents. Bidirectional KYA and trust scoring.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.agenttrust/mcp-serverAgentTrust — Identity & Trust for A2A Agentslocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • ai.ai-akari/agent-trust-receiptAIノアカリ☆ Agent Trust Receiptremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.aislabs/cveAIS CVE Priorities — daily exploit-ranked patch list for AI agentsremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.anha/resolverResolve @handles to post-quantum-signed agent identities and transact with the brands behind them.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.aqta/sealVerify Seal AI decision receipts: signed evidence anyone can check, no account needed.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.augmentev/paseoConfidential AI execution with a post-quantum receipt on every job — verifiable by anyone.remote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • ai.boundaryai/boundaryaiDeterministic runtime safety for AI agents: scan PII, gate tool actions, verify LLM output.remote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • ai.byteray/byteray-mcpByteRay AIremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.certscore/mcpCertScore MCPlocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • ai.certscore/mcp-lightCertScore.ai MCP Lightremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.complyme.mcp/mcpComplyMe.AI MCP server for legal & data protection risk analysis and audits.security · AI-classifiedNot tested
  • ai.councilof/gspc-freeCouncil of AI GSPC (free)remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.duvera/gatewayGoverned AI actions with signed, verifiable receipts: free keyless reads, human-approved writes.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.enyal/enyalENYAL by Greenland AIremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.facesign/facesign-mcpBuild and test FaceSign step-up verification flows from your AI coding toolremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • ai.fullmakt/fullmaktFullmaktremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.gateco/gatecoGatecolocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • ai.geodesiclabs/governance-platformPre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof.remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • ai.getvda/auth-token-mcp-serviceAuth Token MCP Serviceremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/auth-token-mcp-traced-serviceAuth Token MCP Traced Serviceremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/authenticated-llm-agent-bcryptAuthenticated LLM Agent (Bcrypt)remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/authenticated-llm-jwt-agentAuthenticated LLM JWT Agentremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/authenticated-mcp-agent-bcryptAuthenticated MCP Agent (Bcrypt)remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/encrypted-langchain-session-agentEncrypted LangChain Session Agentremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/encrypted-langchain-token-agentEncrypted LangChain Token Agentremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/encrypted-oauth-llm-agentEncrypted OAuth LLM Agentremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/fastapi-auth-token-jwt-serviceFastAPI Auth Token JWT Serviceremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/fastapi-auth-token-serviceFastAPI Auth Token Serviceremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/google-oauth-credential-serviceGoogle OAuth Credential Serviceremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/llm-orchestration-agent-cryptographyLLM Orchestration Agent (Cryptography)remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/password-hashing-and-jwt-servicePassword Hashing and JWT Serviceremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.getvda/structured-output-mcp-agent-cryptographyStructured Output MCP Agent (Cryptography)remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.hanria/agent-mandate-checkHANRIA agent mandate checkremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.hanria/checkCheck a proposed agent action against operator's rules: permit, deny or escalate, with the clause.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.helixar/mcpHelixar Securityremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.hiddencontent/mcpHiddenContentremote and local packagesecurity · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.intodns/scannerIntoDNS.ai DNS & Email Security Scannerremote and local packagesecurity · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • ai.justdrop/mcpLive, end-to-end encrypted, ephemeral file transfer between your AI agent and any device.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • ai.justonce/memoryJustOnceremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.kaiv/dependency-trustTrust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.kaiv/email-checkEmail posture for any domain: can it receive mail, can it be spoofed? MX, SPF and DMARC.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.kanonik/kanonikGovernance runtime for compliance: verified, human-approved writes to a tamper-evident record.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.kernora/agent-secZero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.lateos/soar-record-gatewaySOAR Record Gatewayremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • ai.limitguard.api/trust-intelligenceLimitguard Trust Intelligenceremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • ai.marchward/mcp-serverRuntime authority for AI agents: credential mediation, spend cap, approval gates, audit log.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • ai.occludra/mcp-gatewayOccludra — MCP Gateway (AI Security Gateway)remote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • ai.onedroid/synapseOneDroid Synapseremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • ai.positif/positifPositiflocal packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • ai.preclick/preclick-mcpPreClick — An MCP-native URL preflight scanning service for autonomous agents.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.proofslip/mcp-serverProofSliplocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • ai.responsibleailabs/rail-scoreResponsible-AI guardrails for agents: scoring with policy, injection & PII detection, DPDP.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.revelara/mcpRevelararemote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.scamverify/mcpScamVerify Threat Verificationremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.sealgate/gatewayMCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.skilltotal/skilltotalSkillTotallocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • ai.skuit/catalogSKUit Network & Security Catalogremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.smithery/PabloLec-keyprobe-mcpAudit certificates and keystores to surface expiry risks, weak algorithms, and misconfigurations.…remote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • ai.smithery/alex-llm-attack-mcp-serverQuery and retrieve information about various adversarial tactics and techniques used in cyber atta…remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • ai.ssid/ssid-mcpManufacturer-cited router default logins and compliance check, plus MAC/OUI vendor lookup. Free.remote and local packagesecurity · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.strix/strixStrixremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.tachyo/verifyCryptographic proof of wallet ownership in two steps, with no keys and no custody.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.thedrain/boardthe drainremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • ai.thrain/blackoutPermanent local PDF redaction: text is removed and verified gone, not covered. No uploads.local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • ai.tokenos/contract-auditTokenOS Smart Contract Auditremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.trent/trentTrentremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.trustysquire/trusty-squireTrusty Squirelocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • ai.tunnelmind/scryScryremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.turingtap/turingtapTuringTapremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • ai.tuteliq/mcpDetect grooming, bullying, fraud, and 16+ online threats across text, voice, image, and video.remote and local packagesecurity · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • ai.urlcheck/urlcheck-mcpPreClick — An MCP-native URL preflight scanning service for autonomous agents (formerly URLCheck).remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ai.vulx/watchVulX Watchremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • app.apick/identityAPICK Identityremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.asmhunter/asmhunter-mcpASMHunterlocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • app.certman/serverCreate and manage your own Certificate Authority for internal HTTPS.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • app.clearpolicy/clearpolicyClearPolicyremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • app.eurocomply/complianceEuroComply — EU Regulatory Complianceremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.joinlayer/mcpJoinLayerremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • app.katla/katlaKatlaremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • app.keyslip/keyslipKeySliplocal packagesecurity · AI-classifiedNot tested
  • app.malinois/scanMalinoisremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.merron/ai-act-checkMerronremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.openkrill/cveCVE Risk Checkremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.openkrill/packagesPackage Health Checkremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.qwady.thorns/thornguardThornGuardsecurity · AI-classifiedNot tested
  • app.rowb.auth-posture/auditAuth Posture — Email Deliverability & Spoofability Auditremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.scfcontrolsplatform/mcp-server-scfMCP server for the SCF Controls Platform — 187 tools for controls, evidence, risk, and TPRM.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • app.vercel.cloakcheck-wheat/cloakcheckScan a page for hidden prompt-injection payloads targeting AI agents.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.vercel.exploitwatch-kappa/exploitwatchCheck dependencies against CISA's real Known Exploited Vulnerabilities feed.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.vercel.renewalmatrix/renewalmatrixScore a subscription flow against US click-to-cancel / auto-renewal laws.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • app.vercel.triageshield/triageshieldVerify a vuln report's file/line/function claims against a real GitHub repo.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • au.com.aiframework/australian-ai-governance-frameworkAustralian AI governance framework mapped to the Privacy Act and sector laws your AI use triggers.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • au.com.alpineai/factstampFactStampremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • au.com.appgenie/compliance-mcpAppGenie Compliance MCPremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • bar.alerts/alertsbarAlertsBarremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ca.airiskmanagement/shadow-ai-listShadow AI Listremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ca.movahedi/privacymovahedi.ca Privacy Dataremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • ca.structureclerk/mcpStructureClerkremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • cc.captcha/captchacccaptcha.cc Human Verificationremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • cheap.doc/mcpPassport, ID and MRZ recognition via doc.cheap – Free: 100 documents every month, then $0.01 eachremote and local packagesecurity · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • cloud.nttzen.secdb/zen-secdbZEN SecDBremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • cn.savantcat/ai-compliance中国 AI 合规与备案(条文级自查)remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • co.cookie-compliance/cookie-consentCookie Complianceremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • co.fingersai/fingersThe honest trust index for x402: check who you're paying before your agent pays.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • co.launchtrust/launchtrustLaunchTrustremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • co.macrocyber/attack-surfaceMacroCyberremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • co.pentatrail/ctemPentaTrail CTEMremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • co.policyforge/mcpGenerate, audit, and maintain legal policies that match what your code actually does.remote and local packagesecurity · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • co.promptguard/securityPromptGuardlocal packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • co.ship-safe/scannerShipSafe — Independent security verificationremote and local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.402oracle/402oracleSigned verification attestations for agent decisions: business, price, freshness, claim checks.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.808bits/fips-cmvpFIPS 140 certificate trackerremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.a2awire/benchmark-access-change-request-recertify-2026-09-15-b578285fIT Security — Access Change Request Recertify — Alder Court Partners (b578285f)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/benchmark-access-request-review-2026-09-10-81479355Employee Operations — Access Request Review — Larkspur Partners (81479355)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/benchmark-moderation-case-review-2026-09-19-ba3b90e4Trust & Safety — Moderation Case Review — Kestrel Services Group (ba3b90e4)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-cert-fr-advisory-national-cert-alertCERT-FR Security Advisories — buy per-query in-session (certfrwatch)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-cisa-advisory-ics-security-alertCISA Cybersecurity & ICS Advisories — buy per-query in-session (cisaalerts)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-cisa-known-exploited-vulnerability-catalogCISA Known Exploited Vulnerabilities (kevwatch)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-cve-security-advisory-vulnerability-databaseCVE Security Advisories (NVD High & Critical) — buy per-query in-session (cvewatch)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-cybersecurity-news-breach-alertCybersecurity News & Breach Alerts — buy per-query in-session (bleepingwatch)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-debian-security-advisory-dsa-linuxDebian Security Advisories — buy per-query in-session (debianwatch)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-dependency-vulnerability-malicious-package-securityDependency Vulnerability Tracker — package security advisories ($0.01/query)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-exploit-db-exploit-database-proof-of-conceptExploit-DB New Exploits & Proof-of-Concepts — buy per-query in-session (exploitdb)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-go-vulnerability-golang-securityGo Vulnerability Database Tracker — buy per-query in-session (govulnwatch)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-rust-security-crate-vulnerabilityRust Crate Security Advisories — buy per-query in-session (rustsecwatch)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-ubuntu-security-linux-vulnerabilityUbuntu Security Notices / USN (usnwatch) — buy per-query in-sessionremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.a2awire/data-windows-security-update-microsoft-cvrfMicrosoft Windows Security Updates (MSRC CVRF) — buy per-query in-session (msrcwatch)remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.agentavow/agentavow-trustAgentAvow Trustremote and local packagesecurity · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.agentlefs/agentlefsagentleFSremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.aleeth/authority-mcpALEETH Authority MCPremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.anteproof/anteproofAnteproofremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.apished/hash-digest-toolHash Digest Toolremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.apished/random-number-generatorRandom Number Generatorremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.arcjet/mcpArcjetremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.arcself/arc-securityScan AI agent skills for 25 attack classes + runtime monitoring. 1,316+ findings.local packagesecurity · AI-classifiedPackage does not starttested 2026-10-09
  • com.astraverify/domain-trustAstraVerify Domain Trust Checkremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.auth0/mcpAuth0 MCP Serverlocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.axiorank/axiorankAxioRank: Zero-Trust for AI Agentsremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.ayurak/aribot-mcpThreat modeling, code, API & cloud security, shadow-AI & compliance governance.remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.azurecarbon/kodiakVerifiable fact-checking: verdict, confidence, sources, and a tamper-evident certificate.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.babyblueviper/invinoveritasSecond opinion before an irreversible agent action; signed proofs, free verify, public ledger.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.balmasai/balmas-mcpAgents read cleaned copies of your files: PII replaced with local consistent tokens. Read-only.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.bidda/bidda-compliance10,065 source-verified compliance nodes, 39 pillars, 25 MCP tools (EU AI Act, GDPR, NIST, MITRE).remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.blackduck/mcp-serverBlack Duck Security Scannerlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.blackveilsecurity/dnsBlackVeil DNS & Email Security Scannerremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.blackwalltier/blackwallAPI-key pre-action risk gate: any irreversible agent action (money, SQL, delete, email).local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.bluecloudcyber/guestbookAgent Guestbooklocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.bmcxiv/breach402-owner-protectionBreach402 Owner Protectionremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.bonissystems/compliance-batchCompliance Batch Alignmentremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.bonissystems/content-provenanceContent Provenanceremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.bonissystems/knox-anchorKnox Anchorremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.braxos/maestrobraXos Maestroremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.brianbooms/quiet-mendersQuiet Mendersremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.brightsec/mcpBright Securityremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.buyukesim/mcpNo-logs VPN, real UK +44 number eSIMs and travel-data eSIMs, bought with crypto. No KYC, no account.remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.bynn/bynnBynnremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.cautellus/scam-detectionScam and phishing detection for AI agents: safe/warn/danger verdicts for URLs and messages.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.chaingrantor/grantor-mcpWrap any MCP server with enforced, bounded, revocable permissions — grant, narrow, check, revoke.local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.checkmarx/checkmarxOfficial Checkmarx MCP Serverremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.civic/nexusZero-setup MCP gateway securely connecting AI to your tools with authentication and workflowsremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.a2aidentitytoll/a2aidentitytoll-mcpRemote MCP for A2A caller identity, scope policy, verdict receipts, and audit history.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.agentdataboundary/agentdataboundary-mcpPermission boundary receipts for ChatGPT agents.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.c2padisclosure/c2padisclosure-mcpRemote MCP for C2PA disclosure policy MCP, structured receipts, audit logs, and reviewer-ready evideremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.c2paintake/c2paintake-mcpRemote MCP for C2PA intake verifier MCP, structured receipts, audit logs, and reviewer-ready evidencremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.copilotconnectorledger/copilotconnectorledger-mcpCopilot connector permission audits with owner signoff receipts.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.mcpoauthscopegate/mcpoauthscopegate-mcpOAuth scope approvals and consent receipts for remote MCP servers.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.mcpriskledger/mcpriskledger-mcpMCP Risk Ledger MCPremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.clauxel.mcpscopeconsent/mcpscopeconsent-mcpRemote MCP for MCP consent scope receipt, structured receipts, audit logs, and reviewer-ready evidenremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.safetyreplay/safetyreplay-mcpPaid remote MCP for safety replays, policy gates, eval receipts, and release evidence.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.statewrightgate/statewrightgate-mcpA paid remote MCP for Statewright, built to return verdicts, receipts, usage logs, and audit-ready Jremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.tracepiishield/tracepiishield-mcpPII scanning and redaction receipts for LLM traces and tool payloads.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.clauxel.zeroidagent/zeroidagent-mcpA paid remote MCP for ZeroID, built to return verdicts, receipts, usage logs, and audit-ready JSON.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.cnrcode/corroboratemeCorroborateMeremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.cognivators/mcp-safeguardMCP server security scanner: detects prompt injection, credential leaks, SSRF, tool poisoning.local packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • com.complianceautomator/public-mcpComplianceAutomator Public MCPremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.compliapi/screeningOFAC and global sanctions screening: crypto addresses, emails, websites, IDs, countries, VPN, georemote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.complylayer/complylayerComplyLayerremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.consentlayer/mcpConsentLayerremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.continueops/continueops-publicContinueOps Public MCPremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.contrastcyber/apiContrastAPIremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-09
  • com.controldrill/mcpControlDrillremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.correctover/mcp-serverMCP runtime security. 22µs validation, 97% self-healing. Detects RCE, SSRF, credential hijacking.local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.craftedtrust/mcp-shieldTrust verification for MCP servers. Check scores, scan for security issues, search 4,200+ servers.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.crimsoncrawler/mcp-serverCrimson Crawlerremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.croviatrust/croviaCrovia — verifiable silence (TACET) and Crovia Sealremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.csidia/notesCSIDIA — operational notes and capabilitiesremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.custosa/toolsCustosa Toolsremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.cve-security/cve-intelligenceCVE intelligence: exploitation (KEV/EPSS), detection coverage, fixed versions. All tools keyless.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.cvelens/cvelensCVElens Vulnerability Intelligenceremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.cyberspf/mcpCyberSPFlocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.datakoot/cve-vulnerability-lookupSecurity Intel MCPremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.davisvillelabs/exitproofExitProofremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dechonet/mcp20 domain recon tools for AI agents: DNS, SSL, headers, email, subdomains, lookalikes, changes.remote and local packagesecurity · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.decionis/mcpAuthorize consequential AI agent actions before executionremote and local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.decision-anchor/daDecision Anchorremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.disclosedby/recorddisclosedby, the subprocessor recordremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dmarkoff/mcpDMARKOFF — DMARC, SPF & DKIM Analyticsremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.domain-sentinel/domain-sentinelDomain Sentinelremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.domaincanary/mcpDomainCanaryremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.domainposture/mcpRemote MCP server: 19 domain-hygiene and email-auth tools (DNS, SPF, DMARC, DKIM, TLS).remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dominionobservatory/observatoryDominion Observatoryremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.dregs/dregs-mcpDregsremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.dropwatchhq/agent-receiptsAgent Receiptsremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dropwatchhq/compliance-evidenceDated, signed compliance-evidence packs: gov-fact-grounded claims + exclusion screens + trap-facts.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dropwatchhq/entity-screenScreen a business or person for exclusions, debarment, and sanctions (SAM.gov, OFAC).remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dropwatchhq/exclude-feedScreen a business for federal exclusions & sanctions: OFAC SDN, HHS-OIG LEIE, SAM.gov debarment.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dropwatchhq/phoenix-screenPhoenix/rebrand relink detection: links a debarred principal to a newly-formed business entity.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dropwatchhq/safe-checkSafe-Check (recall + counterfeit)remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.dustforge/demipassCredential custody for agents: use secrets blind (ssh/http/smtp/git/db), never in context.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.dyndns-server.noon-ai/privacy-object-anonymize-mcpAutomatic Privacy Object Anonymize & Face Masking MCP — NoonAI DISremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.ecocitizenz/trust-mcpECZ-ID Trust MCPremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.edgethirteen.www/ai-disclosure-kitEU AI Act Article 50 transparency kit: disclosure text, embeddable banner, compliance record. $59.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.edgethirteen.www/cloakcheckScan a page for content planted to hijack an AI browsing/shopping agent before it acts on the page.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.edgethirteen.www/drop-compliance-kitCheck a California data broker's next DROP 45-day deletion-request check-in deadline.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.edgethirteen.www/exploitwatchCheck a dependency list against CISA's live Known Exploited Vulnerabilities catalog.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.edgethirteen.www/killcordDead-man's switch for Anthropic API spend: kills the key the instant it crosses a limit you set.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.edgethirteen.www/lite36 SEC, WCAG and entity-diligence tools behind 2 low-context ones: discover_tools, call_tool.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.edgethirteen.www/renewal-matrixScore a subscription cancellation flow against federal, CA, CO, VT, and OR click-to-cancel laws.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.edgethirteen.www/triageshieldVerify a vuln report's file/line/function claims against a real GitHub repo.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.eformogi/records-vaultConsent-scoped vault access and free verification of family-issued learning records.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.eleyed/redactRedact PII from text before it reaches a model. Nothing stored, no third-party AI.remote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.elucora/evidenceElucora Evidence APIremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.encompassconfirm/ec360KYC automation from authoritative public sources. Requires an Encompass licence.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.everlange/mcpEverlange: audit AEO on 67 criteria across 10 answer engines, apply fixes, prove the gain.remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.exploit-intel/eip-mcpExploit Intelligence Platform — CVE, Vulnerability and Exploit Databaseremote and local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.fablerlabs/x402-toolsFabler x402 Toolsremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.fedlin/fedlin-mcp-serverFEDLIN Scannersremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.feranor/resilienceFeranor Resilienceremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.fidacy/ai-agent-firewallEvery agent action watched, every money-moving one gated, every verdict independently verifiable.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.filltrust/questionsFillTrust security questionnaire corpusremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.forgeorbital/agent-gateLocal mandate gate and proof trail for AI agents that take consequential actions.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.framekeep/publicFramekeep Public Discoveryremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.fronesislabs/dcl-trust-oracleDCL Trust Oracle — AI/LLM Output Audit (x402 MCP)remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.frontiercrown.signer/nostr-signerNostr Signerremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.geiant/mcp-agentcoreAI governance MCP server for EU AI Act compliance and jurisdiction verificationremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.gentkey/mcpGentkeyremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.getacqpath/acqpathAcqPath — content rights before RAG, AI and trainingremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.getskarn/skarnSkarnlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.goedvps.app.wodan-posture/wodan-postureWodan Postureremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.grafomem/cgr-readGRAFOMEM CGR Readremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.grcmigrate/directorySearch a directory of SOC 2 audit and compliance firms; read GRC migration guides. Read-only.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.hirosecure/agentsProgrammatic control of the Hiro security platform: scans, tasks, plans, and approvals.remote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.hirosecure/architectSecurity reviews for coding agents: diffs checked against your org policy and live infrastructure.remote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.htmlvault/htmlvaultHTMLvaultremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.infosecjobboard/jobsInfoSec Job Boardremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.ip99/ip99IP99 IP risk & geolocationremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.ismalicious/mcp-serverisMalicious threat intelligence for AI agentslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • com.ispyconnect/agentdvrAgent DVRremote and local packagesecurity · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.jithox/eu-sanctions-preflightJithox EU Counterparty Sanctions Preflightremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.jojapi/verify-the-email-instantlyVerify the email instantly: Identify the spam email while authenticating your users.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.kenwea.www/marketplaceKenwea — Sandbox Attestation & Agent Marketplaceremote and local packagesecurity · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.kenwea.www/notaryKenwea Notaryremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.keyboardcrumbs/mcpLive threat intel for Claude — CVE, KEV predictions, IP lookup, malware hashes. Free, no API key.local packagesecurity · AI-classifiedPackage does not starttested 2026-10-09
  • com.keyhalve/verifyKeyHalve - verify sealed documentsremote and local packagesecurity · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.khotem/khotem-witnessKHOTEM — Cryptographic Witnessremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.layercall/trust-apiLayerCallremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.loopholetape/solana-token-safetyloophole tape: Solana token safetylocal packagesecurity · AI-classifiedNot tested
  • com.mactechsolutionsllc.www/cmmcMacTech CMMC / NIST 800-171remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.mactechsolutionsllc.www/stigMacTech STIGremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.mailvakt/mailvaktMailVaktremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.malgorath.scrub-mcp/scrub-mcpScrub MCPremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.malwagon/malwagonMalwagonremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.mambabuilt/mcp-domain-deliverability-checkerAudit a domain email deliverability via Apify: SPF, DKIM, DMARC, MX, blacklist, catch-all, age.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.mandarelabs/mandareMandarelocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.maskbreak/mcpMaskbreaklocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.mcplocker/mcplockerMCP Lockerremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.mcplookup/mcpMCPLookupremote and local packagesecurity · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.mcpscores/webhook-signature-fixture-labWebhook Signature Fixture Labremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-09
  • com.metricprovenance/odgs-mcp-serverODGS governance enforcement — validation, regulation compilation, drift detection, signed S-Certs.local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.microsoft.esrp/esrp-oss-mcp-testThe ESRP OSS MCP server exposes tools to discover & validate trusted Microsoft OSS Packages.remote and local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.microsoft/esrp-oss-mcp-testThe ESRP OSS MCP server exposes tools to discover & validate trusted Microsoft OSS Packages.remote and local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.microsoft/sentinel-data-explorationMicrosoft Sentinel Data Explorationremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.mnemopay/gridstampCryptographic spatial proof-of-presence for AV fleets, logistics, AR. 91% spoof detection.local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.moltlinestudio/governMoltline Agent Governanceremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.moltlinestudio/regclockMoltline RegClockremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.mxverdict/mxverdictMX Verdictremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.myprivacyagent/publicRead-only opt-out guides, removal routes for 950+ data brokers, and privacy library search.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.nautaai/holster-mcpHolster MCPlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • com.nizh/nizhNizhremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.obeliskgate/trust-toolsWebsite security ratings, token verification, and tamper-evident ledger heads from Obelisk Gate.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.obligationsign.mcp/agts-mcpAGTS MCP Serverremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.obsmetrics.paygent/agentsPay-per-call safety guards for AI agents: injection, tool-call, signing, secret, x402-trust.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.ofacscreen/screeningOFACScreen Sanctions Screeningremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.oksigenia/checker-mcpDomain security & privacy checker as an MCP server. 17 live checks, 0-100 score, local-first.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.olane/copass-localLocal encryption and project setup plugin for Copass. Keys never leave your machine.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.olane/cosync-localLocal encryption and project setup plugin for CoSync. Keys never leave your machine.local packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • com.ontarioprotocol/ontario-protocolOntario Protocolremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.ontoramp/governance-assessmentOntoRamp Governance Assessmentremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.opzyai/mcpOpzyai Security Checklocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.opzyai/proOpzyai Proremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.opzyai/scanOpzyai Vibe Checkremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.pcblt/pcbltPCBLT — Live Checksremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.pcrzero/mcpIssue signed receipts for AI agent actions; verify any receipt offline - free, no account.remote and local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.pdf-redaction/pdf-redaction-mcpPDF Redaction MCPremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.pentest-tools/mcp-serverMCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.phronesisintel/phronesis-hermesDecision-assurance for AI agents: an auditable action boundary + receipt before it acts.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.pinareldem/hukukPınar Eldem Hukuk & Danışmanlıkremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.policylayer/policylayerPolicyLayerremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.policylayer/registryThe MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.portscan/port-scannerPort Scanner APIremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.powerdmarc/mcpPowerDMARC MCPremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.powmcp/ssl-certificate-checkSSL Certificate Checkremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.professorsausages/sausage-trustProfessor Sausages — Trust & Verificationremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.project-feldspar/scanFeldspar free repository security scanremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.pulsemcp/onepasswordMCP server for interacting with 1Password via the CLI to read and manage credentials.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.quietfailures/quiet-failuresQuiet Failuresremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.rangercheck/security-toolsFree front-end security check for any website: a grade plus the secrets and keys it exposes.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.recognitium/recognitiumRecognitiumremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.reglyze/mcpNIS2 tools: scope check, EU transposition, incident deadlines, and your own org's status (token).remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.relentlessidentity/relentless-identityRelentless Identityremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.repogates/repogatesRepoGatesremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.returnonsecurity/signalCybersecurity market intelligence: funding rounds, M&A, investors, valuations, corporate lineage.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.robtex/mcpDNS, IP, AS, domain reputation, and Lightning Network intelligence (44 tools)remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.royalplugins/royal-mcpSecurity-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.royashbrook/hushhushremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.rulemesh/complianceEngineered GDPR compliance for engineers and AI agents: pull rules, implement, submit evidence.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.saasdossier/evidence-ledgerRead-only MCP: free OpenAI security evidence ledger (55 fields) + SaaSDossier release register.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.scanlabsai/scannerScanLabsAI Security Scannerremote and local packagesecurity · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.scanmalware.mcp/scanmalware-mcpScanMalware.com URL Scannerremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.scannd/scanndScanndlocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.scopeblind/passportPortable cryptographic identity for AI agents. Ed25519 keypairs and signed manifests.local packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • com.scopeblind/protect-mcpFail-closed Cedar policy gate + Ed25519 signed receipts for agent tool calls. Denies on any error.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.scopeblind/verify-mcpOffline Ed25519 verification of signed receipts, bundles, and trust artifacts.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.scriptmasterlabs/provider-trustProvider Trust — Verify a Source or Providerremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.sebastienrousseau/passmcp-serverpassmcplocal packagesecurity · AI-classifiedNot tested
  • com.secdim/mcpPersonalised developer security learning pathways from SecDim's challenges and courses.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.seoapi/claudeValidate ClaudeBot and Claude-SearchBot IP addresses. Remote MCP validate_ip tool.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.skillssafe/scannerSkillsSafe Security Scannerremote and local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.stackhawk/stackhawkAn MCP server that provides interaction with StackHawk's security scanning platform.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.steledger/gatewaySteledgerremote and local packagesecurity · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.synapseconnexion.www/confirmeConfirme, by Synapseremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.tamperlens/mcpWas this document edited, did its redactions hold, is it safe for a model to read — Tamperlens API.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • com.theartofservice/compliance-intelligenceWhat one compliance standard already evidences of another, with the reasoning and the rejections.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.thenextgennexus/domain-intelligence-mcp-serverWHOIS, DNS, SSL, IP geo for security forensics and OSINT — separate from SEO.remote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.thetempleofdoom.argus/argusAgent rental platform: web-vuln scanning, OSINT and red-team tools via subscription.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.thetempleofdoom.lynx/lynxInspection, steganography and forensics API for files and images. Bitcoin pay-per-use.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.thetempleofdoom.osint-mcp/osint-terminal454 OSINT recon tools + server-side entity correlation & person sweeps. Keyless.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.threadlinqs/intelthreadlinqs-mcpThreadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEslocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.timzinin.api/compliance-toolsCompliance Toolsremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.tlsradar/tlsradarTLS Radarremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.trestlescan/trestleTrestlelocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • com.truealter/identity~Alter Identityremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.truss-security/truss-mcpTruss Threat Intelligenceremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.trustnotch/trustnotch-mcpTrustNotchlocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • com.trycloudflare.candy-josh-writers-balance/yultrace-auditEVM Slither audit (zero-arg demo + live) + Blockscout source + security.txt lookup + MCP probe.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.trycloudflare.urgent-clean-occupied-catalogs/yultrace-auditEVM audit (Slither + source + security.txt + MCP-probe + wallet-exposure). 6 tools + /trace.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.unflagdomain/website-blacklist-removalunflagdomain: website blacklist removalremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • com.verifyum/mcpPrivacy-preserving file proofs on Solana. Files are hashed locally. Currently free, no API key.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.verirouteintel/lookupIs this number safe to call or text right now? Live carrier, CNAM, spam and SMS checks for agents.remote and local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • com.verixid/verifierVerixID Verifierremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.vibgrate/mcpQuery your team's drift, vulnerability, and upgrade data from any AI assistant. OAuth 2.1, 51 tools.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.vigilnotary/vigilVigil — an outside witness for AI agentsremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.virus-alert/agent-observatoryAgent Observatory Digital Twinremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.vouchtrail/vouchtrailEvidence-first trust verdicts for AI-agent services — query one before you transact.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.wallet-connectors/wallet-verifier-mcpMCP server for verifying EUDI/Talao wallet data via OIDC4VP (pull) for AI agents.remote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.watchtower-api/sanctions-screeningSanctions screening, KYB, identifier validation, jurisdiction risk & secret scanning for AI agentsremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • com.wellknownhq/wellknownWellknownremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.withdoorman/doormanDoormanremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • com.workos/mcpWorkOSremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.wphealthkit/mcp-serverWP HealthKitremote and local packagesecurity · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • com.wyrdmcp/wyrdExposes one granted folder to any AI client, read-only, behind a path-containment fence.local packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • com.x-ego/x-egoX-EGOremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.x402supply/endpoint-diligenceLive x402 endpoint trust/diligence check before you pay it. $0.02/call via x402.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.x402supply/pii-redactDetects and redacts PII (emails, phones, SSNs, names, addresses) from text. $0.02/call via x402.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.xposedornot/xposedornotXposedOrNot Breach Intelligenceremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • com.xtrinel/vaastRead-only access to VAAST vulnerability scan findings, workspaces, and targets for AI agentslocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • com.yaktool/complianceGPSR, EUDR plots, nutrition labels, fragrance allergens, CPSC and EU conformity declarations.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • com.zeltser/website-searchImprove security writing, score it against rubrics, plan IR, CTI, vuln, and product strategy.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • cv.touchstone/touchstoneTouchstoneremote and local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • cx.bsv/bsv-cxbsv.cxremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.1pass/logilogi (1pass) IdP — manage your OAuth apps, redirect URIs, passkeys, login history and docs.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • dev.1pass/logi-approvallogi Agent Approval Gate — human approval on the phone before high-risk agent actions.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • dev.agent-module/mcpAgent Moduleremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.agentsim/mcpControl plane for agent auth walls. Connector 0 handles SMS OTP with US test numbers.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • dev.certdesk/certdeskcertdeskremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.corsproxy/mcpcorsproxy.devremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • dev.draugr/draugrDraugrlocal packagesecurity · AI-classifiedNot tested
  • dev.ecoa/ecoaVerificação de segurança e conformidade de sites: cabeçalhos, TLS, DNS, e-mail, LGPD e pentest.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • dev.fentz.envcp/envcpEncrypted environment variable vault with AI access policies, keeping secrets safe from AI agents.local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • dev.flarehq/securityFlarelocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • dev.forestrie/verifyVerify SCITT receipts from Forestrie transparency logs, offlinelocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • dev.freysa.economic-agent-369/freysa-intelligenceFreysa Securityremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • dev.gtfo/mcp-killchain-stage1-weatherMCP Kill-Chain Research — Stage 1 (Identity ≠ Behavior)remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.hatchloop/compliance-checkCompliance Checkremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.instruxi.enforcer/v3Enforcerremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • dev.kaneky/depcheckDepcheckremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.kgninja.agent-economy/agent-verification-utilityAgent Verification Utilityremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.lastseen/scorelastseen scoreremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.madtaco/mcpMadTacolocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • dev.mcpcomp/diagnosticsMCPComp Diagnosticslocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • dev.mcpgrade/mcpSecurity grades (A-F) for MCP servers. Check one before you install or trust it. mcpgrade.devlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • dev.safeprompt/mcpDetect prompt injection, jailbreaks, and code injection in untrusted text before it reaches an LLM.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • dev.satrank/mcpSatRank — Lightning trust + audit oraclelocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • dev.seekrit/mcpseekrit (local crypto plane)local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • dev.seekrit/remote-mcpseekrit — secrets for agentsremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • dev.tatastu/proofStamp content with permanent, verifiable provenance. Hash locally, verify free forever.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • dev.verimand/mcp-authority-serverVerimand MCP Authority Serverlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • dev.workers.3labsio.policy-gate/policy-gateDeterministic allow/require_approval/deny verdicts for agent actions, before they happen.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.workers.bhazarstudio.datoka-agent/agentDatoka Agentremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.workers.cybermax-tools.cybermax/domaindna-apiDomainDNAremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.workers.cybermax-tools.cybermax/kevscope-apiKevscoperemote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.workers.fhi-llc-1118.polished-truth-c514/fhi-x402-security-toolsFHI MCP Server Security Auditremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.workers.manhliemcn4euwlu.llmrt-companion/llm-red-team-scannerLLM Red-Team Scannerremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.workers.mattskowronis.skowron-compliance-gateway/complianceSkowron Compliance Gatewayremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.workers.rjhsignaltech.ai/dkim-selector-checkAI-operated. DKIM key reader: free, no key, finds unknown selectors.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • dev.workers.rjhsignaltech.ai/spf-dmarcAI-operated. Email authentication reader: six free tools, no key, no signup.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • dev.workers.source-80.source-80/source-80SOURCE/80 Discoveryremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • dev.zambo/zamboZamboremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • dk.humanified/values-firewallEU AI Act Art-14 runtime oversight: allow / flag / gate-to-human on an agent action, with receipt.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • email.palisade/palisadePalisaderemote and local packagesecurity · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • eu.ansvar/eu-regulationsAnsvar: EU Regulationsremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • eu.ansvar/gatewayAnsvar: EU Compliance & Legal Intelligenceremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • eu.ansvar/threat-intelAnsvar: Threat Intelligenceremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • eu.ansvar/us-law-mcpUS federal and state cybersecurity/privacy law MCP server with cross-state comparisonremote and local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • eu.ansvar/us-regulations-mcpUS compliance: HIPAA, CCPA, SOX, GLBA, FERPA, COPPA, FDA, EPA, FFIEC, NYDFS + 4 state privacy lawslocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • eu.qeaas/qeaas-mcpQRNG-seeded random bytes, seeds, and ML-KEM-768 keys with signed provenance receipts.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • eu.quantumreadiness/qrp-mcpQuantum Readiness Scanlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • eu.regulatoryai/sovereign-ai-act-mcpSovereign AI Act MCPremote and local packagesecurity · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • eu.riskrouter/evidence-logTamper-evident evidence log: signed heads, proofs, and recording salted digests of your records.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • fr.humanmirror/outcomeHumanMirror Outcomeremote (hosted by the publisher)security · AI-classifiedNot tested · needs a credential or setting
  • fyi.mess/messInventory of your service accounts, kept current by your coding agents. Metadata only, no secrets.remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • holdings.proof/mcp-serverProof Holdingsremote and local packagesecurity · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • id.bardo/bardoBardoremote (hosted by the publisher)security · AI-classifiedOpen without sign-in · its tools were not calledtested 2026-10-08
  • info.agentrank/agentrankIs this AI agent or x402 service real and settlement-backed before you pay it? Trust check.remote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • io.1lookup/1lookup1Lookupremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • io.arcaeon/arcaeonArcaeonlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.arcaeon/ledgerArcaeon Ledgerlocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • io.averta/mcp-gatewayAverta MCP Gatewayremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • io.consentstack/cookie-consentConsentStackremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • io.echelongraph/echelongraph-mcpEchelonGraph CVE & Exposurelocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.fairseal/mcp-serverVerifiable entropy, provably-fair games, and receipt verification for AI agents (FairSeal API).local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.fallax/fallaxFallaxremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • io.fidro/fidroFidroremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • io.flaresignal/intelligenceFlareSignal Intelligenceremote (hosted by the publisher)security · AI-classifiedNo sessiontested 2026-10-09
  • io.fusionauth/mcp-apiPreview release of FusionAuth API MCP serverlocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • io.genesisre/proofrelay-mcp-verifierGENESIS ProofRelay MCP Verifierremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • io.github.0x1Adi/klarionKlarionlocal packagesecurity · AI-classifiedNot tested
  • io.github.0xDanielLopez/phishuntPhishuntremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • io.github.0xDanielLopez/tweetfeedTweetFeedremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • io.github.0xbrainkid/agentfolio-mcp-serverAI agent identity verification via SATP on Solana. Trust scores and on-chain attestations.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.0xddneto/ai-proof-of-usAI Proof of Uslocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • io.github.0xsims/rubric-mcp-serverAttest agent decisions and verify records on a public ledger. Evidence, not just data.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.0xsims/rubric-protocolAI compliance attestation for EU AI Act, SR 11-7, HIPAA. Free local tier, no key required.local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • io.github.0xvibly/hackmyip-mcpHackMyIP — no-key IP intelligenceremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • io.github.100xPercent/pop-payRuntime security for AI agent commerce. CLI + MCP server blocks hallucinated purchases.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.15998194110/delta-witnessPaid Capture and Guard tools for public-source observations before autonomous actions.local packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • io.github.1clawAI/1claw-mcp1Claw Vaultlocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • io.github.26zl/cybersec-toolkitAuthorization-gated MCP server to discover and run 670+ security tools for CTF, pentest, and DFIR.local packagesecurity · AI-classifiedNot tested
  • io.github.4hmetuyar/a2a-auditorScans Agent2Agent (A2A) protocol code for webhook SSRF, missing auth, and credential exposurelocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/agent-graph-auditorFinds transitive excessive agency across LangGraph/CrewAI/AutoGen orchestration graphslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/ai-code-scannerScans code for insecure LLM/AI integration: exposed keys, unsafe output, prompt injectionlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/compliance-checkerKVKK/GDPR/CCPA compliance checks for codebaseslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.4hmetuyar/dependency-auditorCVE scanning for npm/pip/cargo dependencies via OSVlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/dns-intelligenceDNS record enumeration, misconfiguration and dangling-subdomain detectionlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/elicitation-auditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.4hmetuyar/llm-redteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpointslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/mcp-config-auditorScans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquatslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/mcp-server-auditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secretslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/memory-poisoning-scannerScans agent code for untrusted input poisoning persistent cross-session memorylocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.4hmetuyar/model-scannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain riskslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.4hmetuyar/oauth-auditorScans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audiencelocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.4hmetuyar/prompt-injection-scannerScans RAG content/scraped pages for indirect prompt injectionlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.4hmetuyar/prompt-leak-scannerCatches leaked credentials and PII in outbound LLM promptslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/secret-scannerScans files for leaked secrets and API keyslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/security-proxyMCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit loglocal packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • io.github.4hmetuyar/security-suiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligencelocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • io.github.4hmetuyar/slopsquat-scannerChecks declared npm/PyPI dependencies against real registries to catch slopsquattinglocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/ssl-inspectorTLS certificate/cipher/protocol inspectionlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/tool-poisoning-scannerScans MCP tool definitions for hidden instructions and confused-deputy sinkslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/toxic-flow-auditorFinds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egresslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.4hmetuyar/unbounded-consumption-auditorScans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6)local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/vector-store-scannerProbes vector-database endpoints for unauthenticated exposure of embeddings/RAG datalocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.4hmetuyar/vulnerability-scannerTriggers GuardBee scans, queries findings, AI-assisted remediation guidancelocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.78degrees/ghosthuntFind every leaked secret on your machine — API keys in .env files, shell history, and configs.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • io.github.AAAA-Nexus/aaaa-nexus-mcpAAAA-Nexus MCPlocal packagesecurity · AI-classifiedPackage does not starttested 2026-10-08
  • io.github.AAH20/agent-action-gateAgent Action Gatelocal packagesecurity · AI-classifiedNot tested
  • io.github.ABTdomain/ctlogsCTlogs.ioremote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • io.github.AIWerk/mcp-server-vaultBitwarden/Vaultwarden for agents: list tagged items, TOTP codes, one-time Sends, save new secrets.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • io.github.AInoAKARI/keymaster-mcpRead-only runtime secret retrieval from HashiCorp Vault via Keymaster for autonomous AI agents.local packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • io.github.AIops-tools/compliance-aiopsCompliance AIopslocal packagesecurity · AI-classifiedNo sessiontested 2026-10-09
  • io.github.AIops-tools/identity-aiopsIdentity AIopslocal packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • io.github.AJ888/promptbrake-free-toolsPromptBrake Free Toolsremote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • io.github.API-Disk-Integrations/agent-mandateAgent Mandate Verificationlocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • io.github.APMC1/xapsXAPS MCP Serverlocal packagesecurity · AI-classifiedNot tested · needs a credential or setting
  • io.github.Aakashbhardwaj27/ai-scannerAI Scannerlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.AbduljabbarBXR/grim-mcpgrim-mcplocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.Abidit/phi-guard-mcpLocal-first PHI detection for source code, LLM prompts, logs, and analyticslocal packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • io.github.Abracadabrastartup/deusproof-mcpIdentity for AI agents that arrive on their own: a certificate of birth, number and date. Free.remote and local packagesecurity · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • io.github.Acacian/aegisAegis — AI Agent Governancelocal packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • io.github.Achilles1089/pentagonal-mcpAI smart contract forge — 8-agent security audits, generation, and compilation across 8 chainslocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-09
  • io.github.Actenon/kernelActenon Kernellocal packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • io.github.AddyCuber/ybe-checkYbe Checklocal packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • io.github.Agaveis/easy2257-mcpEasy2257remote (hosted by the publisher)security · AI-classifiedNeeds the operator's credentialtested 2026-10-08
  • io.github.Agent360dk/computer-mcpmacOS computer use with the guardrails on: passwords blacked out, writes need consent, all logged.local packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.AgentSafe-AI/tooltrust-scannerToolTrust Scannerlocal packagesecurity · AI-classifiedNot probed (read-only run)tested 2026-10-08
  • io.github.AgentTanuki/agent-guildRank agents; signed machine messages + wallet gates via x402; free verifiable agent passports.remote (hosted by the publisher)security · AI-classifiedNot probed (no operator authorization)tested 2026-10-08
  • io.github.Aggrete/aggreteMCP policy proxy: enforces a code of conduct across connectors before the upstream is called.local packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • io.github.Agnuxo1/enigmagent-mcpLocal AES-256-GCM vault for AI agents. Secrets stay local, LLMs never see real API keys.local packagesecurity · AI-classifiedNo sessiontested 2026-10-08
  • io.github.Aguantar/vibescan-mcp-serverMCP server for VibeScan — scan projects for leaked secrets and security issueslocal packagesecurity · AI-classifiedPackage does not starttested 2026-10-09