- Conduid
- Marketplace
- #owasp
MCP servers tagged owasp
29 live MCP servers tagged "owasp", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with owasp.
Zap Server
A Spring Boot application exposing OWASP ZAP as an MCP (Model Context Protocol) server. It lets any MCP‑compatible AI agent (e.g., Claude Desktop, Cursor) orchestrate ZAP actions—…
Agentmesh MCP Proxy
Public Preview — Security proxy for MCP servers: The Firewall for Model Context Protocol
Mcpscc
Security Command Center for Model Context Protocol (MCP) servers. Detect prompt injection, tool poisoning, secrets, and vulnerabilities. The Trivy of MCP security.
Agent Opfor
Open-source adversary emulation for AI agents and MCP servers.
Ship Safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
CyberStrike
AI-powered offensive security agent. Autonomous pentesting with 13+ specialized agents, 120+ OWASP test cases, 15+ LLM providers, and Bolt remote tool servers. Your AI red team.
Www Project Agent Memory Guard
OWASP Foundation web repository
Clawseccheck
🦞 Local, read-only security scanner for OpenClaw. Finds config, prompt-injection and supply-chain risks — A–F grade.
Fetch Cwe List
MCP (Model Context Protocol) server exposing fetch-cwe-list tools for LLM agents. Experimental/alpha — APIs may change.
Eslint Plugin MCP SDK Security
ESLint plugin for Model Context Protocol (MCP) SDK security — catches tools registered without an input schema, handlers reading arguments the schema never declared, model-visible…
Mcpsec
OWASP MCP Top 10 security scanner for Model Context Protocol servers
Security Scanner
55-tool MCP server for security scanning of MCP servers. Runtime inspection, AST-based SAST, config audit, dependency analysis, OWASP MCP Top 10 compliance. OAuth, TLS, fuzz testi…
Tengu
AI-powered penetration testing MCP server
Vectimus
Deterministic governance for AI coding agents. Cedar-based policy engine that intercepts every agent action and evaluates it against deterministic rules before execution.
Aegis Memory
Secure context engineering for AI agents. Content security · integrity verification · trust hierarchy · ACE patterns. Self-hosted, Apache 2.0.
Agent Mesh
[DEPRECATED] Moved to microsoft/agent-governance-toolkit
Aigis
Deterministic, zero-dependency Python firewall for AI agents — MCP rug-pull, memory poisoning, indirect injection, exfil channels. 44 compliance templates (US/CN/JP/EU).
Agent Control Standard
The open standard for runtime agent control — declarative hooks, policy enforcement, and observability across AI agent frameworks.
Karukia
KARUKIA MCP Server v3.0 — AI-powered development methodology with 26 tools, 19 skills, 1797+ checkpoints across 11 audit dimensions. Works with any AI platform via MCP protocol.
Decoy Scan
Security scanner for MCP server configurations. Finds risky tools, vulnerable packages, and suspicious servers across Claude Desktop, Cursor, VS Code, and more.
Dtrack
Model Context Protocol server for OWASP Dependency-Track.
Meritmcp
The CI quality gate for MCP servers — functional tests + official conformance + OWASP-MCP-Top-10 security in one command, with SARIF, a 0-100 safety score, and a README badge.
Ges MCP Server
GESF MCP Server - AI Compliance Assistant for GDPR, OWASP, NIST, CIS. Check compliance, generate policies, assess risks via MCP protocol.
Firebreak
Security MCP server that turns your AI into a penetration tester. 20 tools, 100 best practice guides, 47 vulnerability patterns. Connect to Claude, Cursor, or any MCP client.
Beforemerge Skills
AI-native code review rules for Claude Code, Cursor, Codex & more. 104 rules across React, Next.js, Supabase, SOLID architecture, and WordPress — each with bad/good examples, CWE/…
goklab/guardvibe
commit hook, and CVE version detection. Zero config, runs locally.
VibeGuard
Free security & privacy scanner for AI-coded apps. 766 rules, 84 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your A…
Devops Skills
Multi-tool DevOps skills for Claude Code, Cursor, and Codex — Terraform, Kubernetes, Docker, GitHub Actions, GitLab CI, AWS FinOps, OWASP security.
Kafka MCP Enterprise Server
A production-ready Model Context Protocol (MCP) server for Apache Kafka. Features Information Flow Control (IFC) sandboxing, granular namespace isolation, and strict bounded buffe…