1. Conduid
  2. Marketplace
  3. #owasp
Tag

MCP servers tagged owasp

29 live MCP servers tagged "owasp", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with owasp.

29
live servers
43
avg trust
35
most stars
1

Zap Server

dtkmn

A Spring Boot application exposing OWASP ZAP as an MCP (Model Context Protocol) server. It lets any MCP‑compatible AI agent (e.g., Claude Desktop, Cursor) orchestrate ZAP actions—…

★ 35updated 6 months agoMIT
69
2

Agentmesh MCP Proxy

Public Preview — Security proxy for MCP servers: The Firewall for Model Context Protocol

62
3

Mcpscc

gensecaihq

Security Command Center for Model Context Protocol (MCP) servers. Detect prompt injection, tool poisoning, secrets, and vulnerabilities. The Trivy of MCP security.

★ 5updated 9 months agoApache-2.0
61
4

Agent Opfor

Open-source adversary emulation for AI agents and MCP servers.

59
5

Ship Safe

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.

59
6

CyberStrike

AI-powered offensive security agent. Autonomous pentesting with 13+ specialized agents, 120+ OWASP test cases, 15+ LLM providers, and Bolt remote tool servers. Your AI red team.

52
7

Www Project Agent Memory Guard

OWASP Foundation web repository

52
8

Clawseccheck

🦞 Local, read-only security scanner for OpenClaw. Finds config, prompt-injection and supply-chain risks — A–F grade.

44
9

Fetch Cwe List

MCP (Model Context Protocol) server exposing fetch-cwe-list tools for LLM agents. Experimental/alpha — APIs may change.

42
10

Eslint Plugin MCP SDK Security

ESLint plugin for Model Context Protocol (MCP) SDK security — catches tools registered without an input schema, handlers reading arguments the schema never declared, model-visible…

42
11

Mcpsec

OWASP MCP Top 10 security scanner for Model Context Protocol servers

39
12

Security Scanner

55-tool MCP server for security scanning of MCP servers. Runtime inspection, AST-based SAST, config audit, dependency analysis, OWASP MCP Top 10 compliance. OAuth, TLS, fuzz testi…

39
13

Tengu

AI-powered penetration testing MCP server

39
14

Vectimus

Deterministic governance for AI coding agents. Cedar-based policy engine that intercepts every agent action and evaluates it against deterministic rules before execution.

39
15

Aegis Memory

Secure context engineering for AI agents. Content security · integrity verification · trust hierarchy · ACE patterns. Self-hosted, Apache 2.0.

39
16

Agent Mesh

[DEPRECATED] Moved to microsoft/agent-governance-toolkit

39
17

Aigis

Deterministic, zero-dependency Python firewall for AI agents — MCP rug-pull, memory poisoning, indirect injection, exfil channels. 44 compliance templates (US/CN/JP/EU).

39
18

Agent Control Standard

The open standard for runtime agent control — declarative hooks, policy enforcement, and observability across AI agent frameworks.

39
19

Karukia

KARUKIA MCP Server v3.0 — AI-powered development methodology with 26 tools, 19 skills, 1797+ checkpoints across 11 audit dimensions. Works with any AI platform via MCP protocol.

37
20

Decoy Scan

Security scanner for MCP server configurations. Finds risky tools, vulnerable packages, and suspicious servers across Claude Desktop, Cursor, VS Code, and more.

37
21

Dtrack

Model Context Protocol server for OWASP Dependency-Track.

37
22

Meritmcp

The CI quality gate for MCP servers — functional tests + official conformance + OWASP-MCP-Top-10 security in one command, with SARIF, a 0-100 safety score, and a README badge.

37
23

Ges MCP Server

GESF MCP Server - AI Compliance Assistant for GDPR, OWASP, NIST, CIS. Check compliance, generate policies, assess risks via MCP protocol.

37
24

Firebreak

Security MCP server that turns your AI into a penetration tester. 20 tools, 100 best practice guides, 47 vulnerability patterns. Connect to Claude, Cursor, or any MCP client.

34
25

Beforemerge Skills

AI-native code review rules for Claude Code, Cursor, Codex & more. 104 rules across React, Next.js, Supabase, SOLID architecture, and WordPress — each with bad/good examples, CWE/…

34
26

goklab/guardvibe

commit hook, and CVE version detection. Zero config, runs locally.

34
27

VibeGuard

Free security & privacy scanner for AI-coded apps. 766 rules, 84 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your A…

34
28

Devops Skills

Multi-tool DevOps skills for Claude Code, Cursor, and Codex — Terraform, Kubernetes, Docker, GitHub Actions, GitLab CI, AWS FinOps, OWASP security.

34
29

Kafka MCP Enterprise Server

A production-ready Model Context Protocol (MCP) server for Apache Kafka. Features Information Flow Control (IFC) sandboxing, granular namespace isolation, and strict bounded buffe…

34
← Previous Page 1 of 1 Next →