Security & Identity MCP servers
Vulnerability scanning, auth, secrets, compliance, and threat intel.
forkflux-mcp
Self-hosted multi-agent collaboration and audit layer for AI-assisted engineering teams
Identity AIops
Governed Keycloak + authentik identity ops: users, events, clients, MFA, RCA. 29 tools.
imagedimensions-mcp
Audit a web page's images: natural vs rendered sizes, oversized detection, and formats.
interactive-leetcode-mcp
Interactive LeetCode MCP server with authorization and solution submission capabilities
lithtrix
Identity, memory, trust, and swarm MCP tools for AI agents. Spark trial at lithtrix.ai.
mcp
RemoteSearch and read the public Applivery docs (MDM & app distribution). Read-only, no auth.
MikroMCP
MCP server for MikroTik RouterOS: typed tools, dry-run, RBAC, audit logs, and rollback.
Moltline Agent Governance
RemoteAudit MCP configs and skill files for over-broad scope and injection risk. 6 of 8 free.
nel-veil
Free passive security scanning - check any domain's DMARC, TLS, headers, and exposures.
Neon Zero-Trust MCP Gateway
RemoteAI security firewall & DLP proxy protecting API keys and blocking destructive commands.
netintel-mcp
MCP server for NetIntel — DNS, SSL, WHOIS, email security, OSINT via x402 micropayments
Phishunt
RemotePublic phishing feed: suspicious/confirmed phishing URLs detected hourly. No auth, CC0.
PropFácil
RemoteSearch authorized real estate in Mexico and manage favorites and publishing with OAuth.
Veeam AIops
Governed Veeam Backup & Replication ops — 27 MCP tools with audit, budget, undo guards.
voyager-net
A safe, read-only, authorized audit of one host you own: DNS, ports, TLS, HTTP hygiene.
webanalyzer
RemoteFree website analyzer: score any public URL 0-100 across 8 quality dimensions. No auth.
Wraps
RemoteSearch the Wraps docs and estimate AWS SES costs. Public, read-only, no authentication.
xfa
RemoteXFA's remote MCP server — query device posture, compliance, policies & CVEs. Read-only.
AgentTrust — Identity & Trust for A2A Agents
Identity, trust, and A2A orchestration for autonomous AI agents. Official A2A partner.
Compliance Check
RemotePreview a TCPA/GDPR/CASL/10DLC gate result before spending a paid send. No key needed.
DugganUSA CLI — Local STDIO MCP
Local STDIO MCP for DugganUSA threat intel. 1.13M IOCs. Read-only. npm: dugganusa-cli.
Eleion Scanner
Register/verify your domains, queue security scans, and read findings (CVE, severity).
Hail
RemotePhone, SMS & email for AI agents — one remote MCP endpoint, OAuth login, zero install.
harmony-mcp
AI copilot for WeChat Mini Program - compile-fix, size analysis, compliance. 20 tools.
mbox-mcp
Search local email archives (.mbox/.eml) entirely on your machine. No OAuth, no cloud.
mcp-observatory
MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
mcp-seatbelt
MCP runtime security proxy. Blocks dangerous AI agent tool calls with a policy engine.
Nexus Finance
Nexus Finance API — compliance audit, VaR/RWA risk, market quotes and case management.
pdata Prediction Markets
RemoteLive prediction-market odds, volume and movers across 8 platforms. Read-only, no auth.
raven-nest-mcp
AI-driven penetration testing - 22 security tools behind safety-hardened MCP endpoints
SpineFrame
Governance runtime for AI agents with signed provenance, compliance audits, and OSINT.
The Service Marketing Guys Audit
RemoteRead-only audit of any local service business, Open Service Profile conformance first.
tradememory-protocol
Tamper-evident decision audit trail and outcome-weighted memory for AI trading agents.
4da-mcp-server
Dependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.
agent-sec
RemoteZero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
cloud-audit
AWS security scanner with attack chain detection, IAM privilege escalation, and fixes
gha-intel
Workflow timing analysis, configuration audit and billing insight for GitHub Actions.
iso20022-evidence-pack-mcp
MCP server: seal & sign ISO 20022 readiness evidence into tamper-evident audit packs.
Norma by Quality Clouds
RemoteDeterministic AI code review, with an audit record. Governance inside the agent loop.
NotFair
RemoteOAuth MCP for Google, Meta, X, LinkedIn, Reddit, TikTok, GSC, GA4, WordPress and GHL.
PCI DSS v4.0.1 Compliance Checker
PCI DSS v4.0.1 compliance scanner for Go payment services, delivered as an MCP server
PostgreSQL CVE & Release Intelligence
PostgreSQL security for AI agents: CVEs, yanked releases, exploits, and upgrade paths
prodcheck
4,372 pre-production checks: security, performance, scale, integrations, post-launch.
RCO-A2A - Regulatory Compliance Objects
RemoteSigned, deterministic compliance state per object per jurisdiction, resolved upstream
SentinelGate
Open-source MCP proxy for AI agent access control with CEL policies, RBAC, and audit.
sign-cli
Agent-first e-signature MCP server with offline PAdES signing and hash-chained audit.
sophos-central-mcp
MCP server for Sophos Central — endpoint security, XDR/MDR, and MSSP multi-tenant ops
SpendShield
Authorization layer between AI agents and money: ALLOW/APPROVAL/DENY, budgets, audit.