- Conduid
- Marketplace
- #appsec
MCP servers tagged appsec
16 live MCP servers tagged "appsec", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with appsec.
Burp AI Agent
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more
SafeLine
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
Copilot Security Instructions
✨ A customizable copilot-instructions.md ruleset & prompts to guide GitHub Copilot toward secure coding defaults in Java, Node.js, C# and Python. Blocks risky patterns, teaches sa…
Numasec
Fully autonomous AI Pentester, finds actual vulnerabilities & writes reports. Defining Vibe Security.
Fuzzforge AI
AI-powered workflow automation and AI Agents platform for AppSec, Fuzzing & Offensive Security. Automate vulnerability discovery with intelligent fuzzing, AI-driven analysis, and…
Secpipe
MCP server for AI-driven security pipelines
Defectdojo MCP
An experimental ModelContextProtocol server connecting LLMs to DefectDojo for AI-powered security workflows. Enables natural language interaction with vulnerability data, simplifi…
Hacker Bob
A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/…
Fetch Cwe List
MCP (Model Context Protocol) server exposing fetch-cwe-list tools for LLM agents. Experimental/alpha — APIs may change.
Bluerock
Runtime visibility for Python MCP servers. Captures tool calls, session lifecycle, module imports (SHA-256), and subprocess execution as structured NDJSON. No code changes. Apache…
Pentest
MCP server for authorized pentest workflows: Nmap/Gobuster orchestration, context aggregation, AI-assisted triage, and reporting.
Oauthlint
Model Context Protocol server for OAuthLint. Lets AI coding tools scan their own generated OAuth/OIDC/JWT/session/CORS code for the anti-patterns OAuthLint catches, in-loop.
Mcpie
Security scanner for MCP servers. Think `npm audit` for the Model Context Protocol.
Firebreak
Security MCP server that turns your AI into a penetration tester. 20 tools, 100 best practice guides, 47 vulnerability patterns. Connect to Claude, Cursor, or any MCP client.
Zeropath MCP Server
Open-source MCP server for querying ZeroPath security issues, patches, and scans using Claude, Cursor, Windsurf, or any AI assistant.
Beforeship
Open-source launch gate for vibe-coded apps: CLI + MCP pre-deploy checks for auth, payments, secrets, Supabase, and production readiness.