1. Conduid
  2. Marketplace
  3. #appsec
Tag

MCP servers tagged appsec

16 live MCP servers tagged "appsec", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with appsec.

16
live servers
50
avg trust
21K
most stars
1

Burp AI Agent

six2dez

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

★ 723updated 6 months agoMIT
87
2

SafeLine

chaitin

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

★ 21Kupdated 10 months agoGPL-3.0
84
3

Copilot Security Instructions

Robotti-io

✨ A customizable copilot-instructions.md ruleset & prompts to guide GitHub Copilot toward secure coding defaults in Java, Node.js, C# and Python. Blocks risky patterns, teaches sa…

★ 36updated 6 months ago
61
4

Numasec

FrancescoStabile

Fully autonomous AI Pentester, finds actual vulnerabilities & writes reports. Defining Vibe Security.

★ 18updated 6 months agoNOASSERTION
61
5

Fuzzforge AI

AI-powered workflow automation and AI Agents platform for AppSec, Fuzzing & Offensive Security. Automate vulnerability discovery with intelligent fuzzing, AI-driven analysis, and…

59
6

Secpipe

MCP server for AI-driven security pipelines

59
7

Defectdojo MCP

jamiesonio

An experimental ModelContextProtocol server connecting LLMs to DefectDojo for AI-powered security workflows. Enables natural language interaction with vulnerability data, simplifi…

★ 11updated a year agoMIT
54
8

Hacker Bob

A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/…

44
9

Fetch Cwe List

MCP (Model Context Protocol) server exposing fetch-cwe-list tools for LLM agents. Experimental/alpha — APIs may change.

42
10

Bluerock

Runtime visibility for Python MCP servers. Captures tool calls, session lifecycle, module imports (SHA-256), and subprocess execution as structured NDJSON. No code changes. Apache…

39
11

Pentest

MCP server for authorized pentest workflows: Nmap/Gobuster orchestration, context aggregation, AI-assisted triage, and reporting.

39
12

Oauthlint

Model Context Protocol server for OAuthLint. Lets AI coding tools scan their own generated OAuth/OIDC/JWT/session/CORS code for the anti-patterns OAuthLint catches, in-loop.

37
13

Mcpie

Security scanner for MCP servers. Think `npm audit` for the Model Context Protocol.

37
14

Firebreak

Security MCP server that turns your AI into a penetration tester. 20 tools, 100 best practice guides, 47 vulnerability patterns. Connect to Claude, Cursor, or any MCP client.

34
15

Zeropath MCP Server

Open-source MCP server for querying ZeroPath security issues, patches, and scans using Claude, Cursor, Windsurf, or any AI assistant.

34
16

Beforeship

Open-source launch gate for vibe-coded apps: CLI + MCP pre-deploy checks for auth, payments, secrets, Supabase, and production readiness.

34
← Previous Page 1 of 1 Next →