- Conduid
- Marketplace
- #sast
MCP servers tagged sast
21 live MCP servers tagged "sast", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with sast.
Automated Security Helper
ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.
Snyk
Language Server used by IDEs as Snyk Backend for Frontends
Fuzzforge AI
AI-powered workflow automation and AI Agents platform for AppSec, Fuzzing & Offensive Security. Automate vulnerability discovery with intelligent fuzzing, AI-driven analysis, and…
Secpipe
MCP server for AI-driven security pipelines
Lucidshark
Ship AI-generated code without the fear
fr0gger/MCP_Security
AICLUDE Security Vulnerability Scanner - MCP Server for querying vulnerability scan results
Cycode CLI
Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning
Eslint Plugin MCP SDK Security
ESLint plugin for Model Context Protocol (MCP) SDK security — catches tools registered without an input schema, handlers reading arguments the schema never declared, model-visible…
Security Scanner
55-tool MCP server for security scanning of MCP servers. Runtime inspection, AST-based SAST, config audit, dependency analysis, OWASP MCP Top 10 compliance. OAuth, TLS, fuzz testi…
Codescan
Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.
Codeslick MCP Server
CodeSlick Security Analysis MCP Server - 323 security checks across 5 languages + 17 MCP-specific behavioral checks + AI code detection
Mcpguard
Security scanner for MCP servers — detect tool poisoning, malicious code patterns, and supply-chain risks before your AI agents execute them.
Mcpeek
Source-code-level security scanner for MCP (Model Context Protocol) server implementations
Oauthlint
Model Context Protocol server for OAuthLint. Lets AI coding tools scan their own generated OAuth/OIDC/JWT/session/CORS code for the anti-patterns OAuthLint catches, in-loop.
Repomri
A zero-dependency MRI scan for your AI coding agent attack surface.
Github Security MCP
GitHub security posture analysis for AI agents — 39 MCP tools, 45 checks across org, repos, Actions, secrets, supply chain, and access control
goklab/guardvibe
commit hook, and CVE version detection. Zero config, runs locally.
VibeGuard
Free security & privacy scanner for AI-coded apps. 766 rules, 84 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your A…
srinivasan-sundaresan95/orihime
reading baseline. `pip install orihime`
Honeybadger
Security scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gat…
Pledgeguard
Rust-native secret scanner with MCP server, AST refinement, and WASM plugins