Penetration Testing
Tools and frameworks for security testing, vulnerability scanning, and penetration testing. Enables security professionals to identify and exploit security weaknesses in applications and networks.
MCP ServersBrowse all →
AlicenseAqualityAmaintenanceEnables agents to inspect web pages for Cloudflare Turnstile challenges without an API key, and clear Turnstile or WAF challenges using a SolveGate API key.633221MIT
Appknox MCP Serverofficial
AlicenseAqualityDmaintenanceA Model Context Protocol server that wraps the Appknox CLI for mobile application security testing.1318MIT
MCP Hub Securityofficial
AlicenseAqualityDmaintenanceSecurity gate that scans MCP servers and Claude Code Skills for vulnerabilities before execution.72MIT- AlicenseAqualityAmaintenanceEnables an LLM to author, validate, and test Wirefilter WAF and Smart Firewall rules using live schema and real CVE exploit templates.71MIT

agentminds-mcpofficial
AlicenseAqualityCmaintenanceMCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.716MIT- AlicenseAqualityBmaintenanceEnables AI assistants to run Offensive360 SAST scans on local codebases, returning security findings with file/line, severity, and fixes, plus scan status tracking.270MIT

PatrowlIntelMCPofficial
AlicenseAqualityCmaintenanceExposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.32MIT- AlicenseAqualityBmaintenanceEnables MCP-native multi-agent security audits for Google Antigravity, orchestrating subagents for 0day research, static analysis, PoC verification, exploit chaining, reporting, and code remediation.2153MIT

AgentAuditofficial
AlicenseAqualityDmaintenanceEnables AI agents to scan MCP servers and AI packages for vulnerabilities, prompt injection, and supply chain attacks.729AGPL 3.0
SiteLint Auditor MCPofficial
AlicenseAqualityAmaintenanceRuns WCAG accessibility, SEO, performance, and security audits on URLs or raw HTML via SiteLint Auditor. Enables LLM agents to audit web pages and check WCAG criteria through MCP tools.3795Mozilla Public 2.0
@konsulto/mcpofficial
AlicenseAqualityBmaintenanceMCP server that enables Claude Code to drive the Konsulto cybersecurity audit platform from the CLI, including reading and writing findings, managing evidence, and handling scope and assets.19171MIT- AlicenseAqualityBmaintenanceThis local MCP server keeps vulnerability intelligence, research scope, scanner results, evidence receipts, Bugcrowd VRT assessments, and report drafts in one SQLite ledger. It is built for authorized defensive research and does not scan, exploit, or submit reports.191MIT

Polygraphofficial
AlicenseAqualityAmaintenanceOpen behavioral litmus for MCP servers — grades A–F across tool-output injection, egress, sensitive-data, and adversarial-input, with reproducible, content-addressed evidence. Tools: run_litmus, verify_attestation.41208Apache 2.0
operant-mcpofficial
AlicenseAqualityFmaintenanceA comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.517123MIT- AlicenseAqualityAmaintenanceMCP server that provides AI-native access to BeVigil's OSINT API, enabling mobile app security research and asset discovery through tools for hosts, subdomains, S3 buckets, URLs, wordlists, and multi-step investigations.67631MIT
- AlicenseBqualityCmaintenanceConnects Claude Code to a Latent Defense deployment to map GitHub repositories into an infrastructure graph, discover attack paths using the JEPA energy model, and triage findings from the terminal.85Apache 2.0

Grype MCP Serverofficial
AlicenseAqualityFmaintenanceEnables AI assistants to perform vulnerability scanning using Grype, supporting scans of directories, container images, and packages via the Model Context Protocol.99Apache 2.0- AlicenseAqualityDmaintenanceA Model Context Protocol (MCP) server for the Ghost Security API, providing secure access to security findings and repository data through standardized tools.7623MIT

Symbiotic MCP Serverofficial
AlicenseAqualityDmaintenanceEnables security analysis of code and infrastructure files via MCP, using Symbiotic CLI for scanning vulnerabilities.4MIT
MCP Security Scannerofficial
AlicenseAqualityDmaintenanceIntegrates Checkov, Semgrep, Bandit, and ASH to provide comprehensive code security analysis for AI coding assistants.1515MIT No Attribution- AlicenseBqualityDmaintenanceEnables integration with Beagle Security API for managing security testing projects, applications, domain verification, and automated penetration tests. Provides 18 tools for creating, monitoring, and retrieving results from security assessments.171MIT
- AlicenseBqualityCmaintenanceMCP server for iOS reverse engineering, enabling static analysis of IPA/Mach-O binaries and dynamic instrumentation via Frida for tasks like IAP interception and FairPlay decryption.322MIT
- AlicenseBqualityBmaintenanceA professional-grade network analysis MCP server that integrates Wireshark/TShark, Nmap, and threat intelligence to enable packet capture, network scanning, threat detection, and credential extraction through natural language.412MIT
- AlicenseBqualityFmaintenanceA security testing tool that enables automated vulnerability detection including XSS and SQL injection, along with comprehensive browser interaction capabilities for web application penetration testing.1227722MIT
- AlicenseAqualityCmaintenanceA comprehensive MCP server for Frida dynamic instrumentation, enabling AI agents to manage devices, processes, scripts, memory, and ADB operations.3929MIT
- AlicenseAqualityCmaintenanceA production-grade security auditing MCP server that wraps semgrep (SAST) and gitleaks (secret detection) to enable one-click code security scanning via MCP stdio protocol.114MIT
- AlicenseAqualityFmaintenanceEnables dynamic management and execution of proxy chains on a remote Linux host via SSH, allowing AI assistants to route network traffic through proxies for privacy and security testing.10MIT
- AlicenseAqualityCmaintenanceA comprehensive reconnaissance toolset that provides AI agents with 37 tools across 12 data sources like Shodan and VirusTotal for automated intelligence gathering. It enables agents to perform domain reconnaissance, attack surface mapping, and cross-platform data correlation within a single conversational interface.373872MIT
- AlicenseAqualityCmaintenanceProvides security audit primitives for MCP servers, agent tool schemas, and system prompts, along with pentest utilities like JWT inspection and HTTP diffing.14MIT
- AlicenseAqualityBmaintenanceMCP server for querying CVE and package vulnerability data from NVD and OSV.dev, allowing CVE lookups and dependency scanning.41MIT
MCP ConnectorsBrowse all →
Production-safety audits for AI-generated code, with a fix for every finding. Scan for committed secrets and known vulnerable dependencies free with no key; a full audit returns a verdict with security, privacy, reliability and architecture findings, priced per audit and quoted before it runs.
Hosted, no-auth endpoint of feldspar-scan: free deterministic security scan of a public git repository (OSV.dev vulnerable dependencies, secret patterns, config lint) as structured JSON. Tools: scan_repository(url), audit_pricing(). Stateless streamable-HTTP JSON-RPC, rate-limited. Source: https://github.com/project-feldspar-resources/feldspar-scan (MIT). Operated by Feldspar, an autonomous AI agent (Project Feldspar).
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Explain a regex in plain English and detect catastrophic backtracking risk.
Free website privacy scanner for pre-consent cookies, trackers, consent, policy, and HTTPS/TLS.
Experimental MCP server for current empirical verification of explicit public HTTPS endpoint claims.
Honeypot probe data: IP reputation, scanners, CVE probing, TLS and SSH fingerprints.
Free, read-only security scanner for remote MCP servers, before you connect them.
Free lockfile malware check plus paid behavioral scan of packages, agent skills and MCP tools.
Free front-end security check for any website: a grade plus the secrets and keys it exposes.
ドメインの設定を調べる MCP サーバー。SPF / DKIM / DMARC・DNS・SSL 証明書・セキュリティヘッダ・サブドメイン・類似ドメインを、公開情報だけで確認します。登録不要・無料。
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Daily CVE priorities ranked by real exploitation (KEV+EPSS) for AI agents; free teaser, paid full
A skeptical senior-engineer code reviewer over MCP: risk-scans unified diffs, flags AI-generated-code tells, reports complexity hotspots, scans for leaked secrets, and runs an OWASP security pass — real analyzers, no external APIs. Free tier, no signup.
Offline methodology engine for authorized penetration testing, CTF, and security research.
MITRE Common Weakness Enumeration (CWE) API
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
urlscan.io URL scanner — search/result keyless, submit needs key
Scan agent skills and MCP servers for malicious patterns before you load them
Verificação de segurança e conformidade de sites: cabeçalhos, TLS, DNS, e-mail, LGPD e pentest.