Security & Pentesting MCP Servers

482 servers for security & pentesting — ranked by real GitHub stars, refreshed continuously, never faked.

# MCP Server Stars
1 MindsDB mindsdb/mindshub MindsDB allows applications to answer questions over large-scale federated data—spanning databases, data warehouses, and SaaS appl 39k ★ 2 Kubeshark kubeshark/kubeshark Real-time Kubernetes network traffic visibility and API analysis for HTTP, gRPC, Redis, Kafka, and DNS. 12k ★ 3 Snyk snyk/cli Security scanner that tests applications and infrastructure for vulnerabilities, generates SBOMs, and monitors projects using Type 5.6k ★ 4 ACI.dev aipotheosis-labs/aci Connects your AI agents to 600+ tool integrations with multi-tenant auth and granular permissions. 4.8k ★ 5 Playwriter remorses/playwriter Browser automation through Chrome extension with single Playwright API execution tool, enabling collaborative automation alongside 3.7k ★ 6 Superglue superglue-ai/superglue Drop-in proxy between applications and REST/GraphQL/SQL/file endpoints that automatically handles schema drift detection, data tra 2k ★ 7 Read MySQL benborla/mcp-server-mysql Secure read-only MySQL database access to execute queries and analyze data patterns. 2k ★ 8 JSHook vmoranv/jshookmcp JavaScript analysis, security auditing, browser automation, and hook injection via MCP. 1.8k ★ 9 NuGet nuget/home Real-time NuGet package management with vulnerability detection and intelligent version updates 1.6k ★ 10 DevDB damms005/devdb-vscode Exposes database tables and schemas via HTTP endpoints, allowing tools to query database structure without direct database access 1.4k ★ 11 MySQL designcomputer/mysql_mcp_server Explore schemas and execute read-only SQL queries on MySQL databases. 1.3k ★ 12 Pentest AI 0xsteph/pentest-ai Provides penetration testing tools for reconnaissance, vulnerability scanning, and exploit assistance. 1.2k ★ 13 SafeDep Vet safedep/vet Protect against malicious open source packages 1.1k ★ 14 CVE Security Intelligence mukul975/cve-mcp-server Security intelligence with 27 tools across 21 sources including NVD, EPSS, VirusTotal, and Shodan. 1.1k ★ 15 OpenOSINT openosint/openosint AI-powered OSINT framework with 16 tools for email, breach, IP, WHOIS, DNS, and domain reconnaissance. 1k ★ 16 Burp Suite portswigger/mcp-server Integrates with Burp Suite for web security testing, enabling HTTP request manipulation, proxy history analysis, and security test 975 ★ 17 Memory Bank alioshr/memory-bank-mcp Transforms file-based memory banks into a centralized, remotely accessible service for multi-project management with consistent st 913 ★ 18 CodeGraph jakedismo/codegraph-rust Provides high-performance code intelligence and semantic search capabilities through RocksDB graph storage, FAISS vector indexing, 845 ★ 19 Aderyn cyfrin/aderyn Provides intelligent Solidity smart contract analysis through the Aderyn static analyzer, scanning codebases to identify security 784 ★ 20 Kali Linux Penetration Testing Tools wh0am123/mcp-kali-server Provides a bridge to Kali Linux penetration testing tools including nmap, gobuster, and metasploit for security scanning, vulnerab 777 ★ 21 Pipelock luckypipewrench/pipelock Security harness that wraps MCP servers as stdio proxies with credential exfiltration prevention, DLP pattern matching, and SSRF p 777 ★ 22 Elasticsearch elastic/mcp-server-elasticsearch Enables natural language interaction with Elasticsearch clusters for listing indices, inspecting field mappings, and executing Que 687 ★ 23 Metasploit Framework gh05tcrew/metasploitmcp Provides a secure interface to Metasploit Framework's penetration testing capabilities, enabling exploit execution, payload genera 687 ★ 24 Semgrep semgrep/mcp Integrates with Semgrep's static analysis engine to scan code for security vulnerabilities and coding issues, enabling developers 681 ★ 25 Filesystem mark3labs/mcp-filesystem-server Read, write, and manipulate local files through a controlled API. 670 ★ 26 Security Tools Bridge cyproxio/mcp-for-security Bridges popular security tools (Nmap, Masscan, SQLMap, FFUF) with external systems for network scanning, port discovery, SQL injec 622 ★ 27 WireMCP (Wireshark) 0xkoda/wiremcp Empowers network analysis with real-time traffic monitoring capabilities through Wireshark's tshark utility, providing tools for p 548 ★ 28 Centralmind (Database Gateway) centralmind/gateway Database integration with security and compliance. Supports: PostgreSQL, MySQL, ClickHouse, Snowflake, MSSQL, BigQuery, Oracle Dat 536 ★ 29 VNC Remote Control for macOS baryhuang/mcp-remote-macos-use Provides secure remote control of macOS machines through VNC protocol, enabling screenshot capture and desktop interaction with mo 487 ★ 30 Skylos duriantaco/skylos Privacy-first SAST tool for Python, TypeScript, and Go that detects dead code, security vulnerabilities, and code quality issues w 471 ★ 31 Security Detections mhaggis/security-detections-mcp Aggregates security detection rules from Sigma, Splunk ESCU, Elastic, and KQL into a unified searchable SQLite database with MITRE 462 ★ 32 DroidMind hyperb1iss/droidmind Enables control and interaction with Android devices through secure tools for device management, app installation, UI automation, 421 ★ 33 Skillz intellectronica/skillz Executes local Anthropic-style skills through directory-based discovery where each skill contains YAML metadata and Markdown instr 397 ★ 34 Frida dnakov/frida-mcp Enables dynamic instrumentation of mobile and desktop applications through Frida toolkit, providing capabilities for process manag 389 ★ 35 VS Code juehang/vscode-mcp-server Exposes VS Code's filesystem, editing capabilities, symbol search, diagnostics, and terminal access as tools for AI-assisted codin 380 ★ 36 Microsoft SQL Server (MSSQL) richardhan/mssql_mcp_server Securely integrates with Microsoft SQL Server databases for data analysis, reporting, and management. 376 ★ 37 BloodHound mordavid/bloodhound-mcp-ai Integrates with BloodHound security tool to analyze Active Directory and Azure environments for attack paths, privilege escalation 366 ★ 38 SSH Manager bvisible/mcp-ssh-manager Enables secure SSH command execution, file transfers, and automated deployments across multiple remote servers with connection poo 359 ★ 39 Code Execution Mode elusznik/mcp-server-code-execution-mode Execute Python in isolated containers while bridging access to other MCP servers through auto-discovered proxies 337 ★ 40 MoLing gojue/moling Enables AI to interact with local system resources through a secure, configurable server that provides browser automation, file op 334 ★ 41 Code Sandbox automata-labs-team/code-sandbox-mcp Provides a sandboxed code execution environment for secure, multi-language code running with resource limits and network restricti 325 ★ 42 Claude Code sdglbl/mcp-claude-code Enables Claude to execute code-related tasks through direct tools for code understanding, modification, command execution, and fil 304 ★ 43 Lokka (Microsoft Graph) merill/lokka Provides a bridge between Microsoft Graph API and natural language interaction, enabling conversational management of Microsoft 36 277 ★ 44 Windows CLI simon-ami/win-cli-mcp-server Control Windows command-line interfaces securely. 268 ★ 45 Maigret OSINT w0h1v/mcp-maigret OSINT Maigret integration to gather user info across social networks. 250 ★ 46 Gemini Collaboration raiansar/claude_code-gemini-mcp Enables Claude to collaborate with Google's Gemini AI through question answering, configurable code review, and brainstorming sess 244 ★ 47 Knowledge RAG lyonzin/knowledge-rag Local knowledge retrieval system that combines semantic search with keyword-based routing for document analysis across security, d 236 ★ 48 Gemini CLI cmdaltctr/claude-gemini-mcp-slim Integrates with Google's Gemini models through API and CLI to provide intelligent code analysis, security auditing, and large-scal 234 ★ 49 CLI g0t4/mcp-server-commands Execute system commands and scripts on the host machine. 230 ★ 50 Razorpay razorpay/razorpay-mcp-server Provides a bridge between natural language commands and Razorpay's payment processing APIs, enabling seamless integration for paym 227 ★ 51 CrowdStrike Falcon crowdstrike/falcon-mcp Connect with the CrowdStrike Falcon platform for intelligent security analysis, providing programmatic access to detections, incid 224 ★ 52 Figma UI tranhoaihung/figma-ui-mcp Bidirectional Figma integration that enables drawing UI with code and reading designs as structured data. 219 ★ 53 Discord v-3/discordmcp Integrates with the Discord API to enable direct interaction with channels, supporting automated messaging and conversation manage 219 ★ 54 AI Infrastructure Agent (AWS) versuscontrol/ai-infrastructure-agent Provides autonomous AWS infrastructure management through natural language processing, combining real-time resource discovery with 216 ★ 55 Conda Executor bazinga012/mcp_code_executor Executes Python code within isolated Conda environments, enabling secure and flexible code generation and execution for tasks like 212 ★ 56 OpenStreetMap jagan-shanmugam/open-streetmap-mcp Enhances LLM capabilities with location-based services and geospatial data from OpenStreetMap. 205 ★ 57 CrowdSentinel thomasxm/crowdsentinels-ai-mcp AI-powered threat hunting and incident response framework for Elasticsearch and OpenSearch with detection rules, EVTX analysis, an 203 ★ 58 Portainer Container Management portainer/portainer-mcp Provides a bridge between AI and Portainer container management platform, enabling environment monitoring, access control manageme 200 ★ 59 AutoPentest AI bhavsec/autopentest-ai Automated web application penetration testing framework implementing OWASP WSTG methodology. 199 ★ 60 Code Sandbox philschmid/code-sandbox-mcp Provides secure code execution capabilities through containerized sandbox environments, supporting Python and JavaScript with pre- 199 ★ 61 Wazuh gensecaihq/wazuh-mcp-server Integrates with Wazuh security platform to provide real-time security alerts and event data from Elasticsearch indices for securit 198 ★ 62 PostgreSQL Database Manager henkdz/postgresql-mcp-server Integrates with PostgreSQL databases to enable schema management, data migration, performance monitoring, and security configurati 197 ★ 63 Android Proxy zhizhuodemao/android_proxy_mcp Captures and analyzes Android device network traffic through mitmproxy integration for HTTP/HTTPS interception and mobile app debu 193 ★ 64 Python Code Execution pydantic/mcp-run-python Provides secure Python code execution in a sandboxed Pyodide environment with automatic dependency installation, stdout/stderr cap 191 ★ 65 Mermaid veelenga/claude-mermaid Renders Mermaid diagrams in real-time with live preview capabilities, automatic browser refresh, and WebSocket-based updates, supp 184 ★ 66 Shell Command tumf/mcp-shell-server Execute whitelisted shell commands on the host system via asyncio. 183 ★ 67 DuckDB ktanaka101/mcp-server-duckdb Execute SQL queries and analyze data in DuckDB databases. 177 ★ 68 Gru Sandbox babelcloud/gbox Secure, self-hostable sandbox for running Python, TypeScript, and Bash code in isolated Docker containers with automatic resource 177 ★ 69 Narsil postrv/narsil-mcp Deep code intelligence with tree-sitter parsing, call graphs, and security vulnerability scanning 177 ★ 70 CLI Secure mladensu/cli-mcp-server Execute shell commands with strict security policies. 173 ★ 71 Filesystem rust-mcp-stack/rust-mcp-filesystem Provides secure, high-performance access to local filesystem operations with strict path validation, enabling read/write file mani 164 ★ 72 BloodHound stevenyu113228/bloodhound-mcp Enables security professionals to analyze Active Directory and Azure AD environments through natural language queries by connectin 160 ★ 73 Windows Remote Control dddabtc/winremote-mcp Remote control and automation for Windows desktops with tiered security, supporting screenshots, input control, file operations, P 158 ★ 74 Bitbucket matanyemini/bitbucket-mcp Integrates with Bitbucket Cloud and Server APIs for repository and pull request management 157 ★ 75 Node Code Sandbox alfonsograziano/node-code-sandbox-mcp Provides a secure Docker-based sandbox for executing JavaScript code with npm dependencies, offering both persistent and ephemeral 154 ★ 76 Zabbix initmax/zabbix-mcp-server Exposes the complete Zabbix monitoring API as 220+ callable tools covering all 57 API groups. 152 ★ 77 BurpMCP Ultra cy-s3c/burpmcp-ultra Burp Suite extension with embedded MCP server exposing 137 tools for web security testing via SSE transport. 151 ★ 78 CodeQL jordyzomer/codeql-mcp Bridges to the CodeQL static analysis engine for identifying security vulnerabilities and quality issues in codebases through stru 150 ★ 79 Solodit marchev/claudit Searches Solodit's 20,000+ smart contract security audit findings from Claude Code and Codex CLI. 148 ★ 80 Kubernetes silenceper/mcp-k8s Enables natural language interaction with Kubernetes clusters for resource querying and CRUD operations with configurable write pe 147 ★ 81 BigQuery ergut/mcp-bigquery-server Securely query and analyze Google BigQuery datasets via natural language. 145 ★ 82 Shodan w0h1v/mcp-shodan Access Shodan API and CVEDB to query IoT device data and vulnerability information. 145 ★ 83 Gemini Image Generator shinpr/mcp-image Integrates with Google's Gemini 2.5 Flash model to generate images with automatic prompt enhancement and file-based output, featur 139 ★ 84 Code Pathfinder shivasurya/code-pathfinder AI-native static code analysis with call graphs, data flow tracing, type inference, and symbol search for Python and Go. 139 ★ 85 VirusTotal w0h1v/mcp-virustotal This VirusTotal MCP server enables AI assistants to programmatically access VirusTotal's threat intelligence for security analysis 138 ★ 86 Joern lekssays/codebadger Provides static code analysis capabilities using Joern's Code Property Graph technology in Docker environments, automatically dete 138 ★ 87 Fartrun chuprinadaria/vibecode-cleaner-fartrun Local code scanner with 29 tools for security vulnerability detection, health analysis, and dead code identification without cloud 136 ★ 88 Dynatrace dynatrace-oss/dynatrace-mcp Integrates with Dynatrace to provide real-time observability data, enabling developers to monitor problems, security vulnerabiliti 132 ★ 89 Code Executor aberemia24/code-executor-mcp Secure sandboxed TypeScript/Python execution with Docker isolation and token-efficient wrapper generation 129 ★ 90 BYOB wxtsky/byob Control your real Chrome browser through AI using the Chrome DevTools Protocol. 128 ★ 91 Alibaba Cloud aliyun/alibaba-cloud-ops-mcp-server Provides a bridge to Alibaba Cloud services for managing ECS instances, viewing resources, monitoring metrics, and configuring VPC 124 ★ 92 ShellWard jnmetacode/shellward Security middleware that protects agents from prompt injection, data exfiltration, and dangerous command execution with 8-layer de 123 ★ 93 Package Version Checker sammcj/mcp-package-version Get package version data from npm and PyPI registries to assist with dependency management. 122 ★ 94 n8n illuminaresolutions/n8n-mcp-server Bridges Claude with n8n automation workflows, enabling direct creation, execution, and management of workflows, credentials, and e 119 ★ 95 JFrog jfrog/mcp-jfrog Bridges to the JFrog Platform, enabling interaction with Artifactory repositories, builds, security scanning, and release manageme 119 ★ 96 Socket Security socketdev/socket-mcp Integrates with Socket's dependency security API to analyze npm and PyPI packages, returning detailed security and quality metrics 118 ★ 97 SineWave Agent Security Scanner sinewaveai/agent-security-scanner-mcp Scans code for vulnerabilities, detects hallucinated packages, and blocks prompt injection attacks in real-time. 117 ★ 98 Java Sink Tracer zacarx/javasinktracer_mcp Analyzes Java applications for security vulnerabilities by tracing data flow through parsed code to identify potential SQL injecti 116 ★ 99 Tailscale hexsleeves/tailscale-mcp Integrates with Tailscale's CLI and REST API to provide network management capabilities including device authorization, route conf 112 ★ 100 DINO-X idea-research/dino-x-mcp Empower LLMs with fine-grained visual understanding — detect, localize, and describe anything in images with natural language prom 109 ★

Showing the top 100 of 482 — browse and filter all mcp servers.

The best new security & pentesting servers, weekly

One email every week with the tools worth your time — plus Agentic Toolbelt: 100 Worth Stealing free when you join.

Frequently asked questions

What are the best security & pentesting servers for coding agents?

Ranked by GitHub stars, the current top security & pentesting servers are: MindsDB (39k ★), Kubeshark (12k ★), Snyk (5.6k ★), ACI.dev (4.8k ★), Playwriter (3.7k ★).

How do I install a security & pentesting mcp server?

Add the server to your MCP client (Claude Code: `claude mcp add <name> -- <command>`). Every server page shows its exact command.

How many security & pentesting servers are listed here?

482 security & pentesting servers are currently tracked, with metrics (stars, downloads, last-update dates) sourced from GitHub and package registries and refreshed continuously.

Related categories