io.github.KryptosAI/mcp-observatory
Regression testing for MCP servers. Checks capabilities, invokes tools, detects schema drift.
MCP servers for vulnerability scanning, secrets management, compliance, and security tooling.
MCPpedia tracks 1,203 security MCP servers. 265 of them score at least 50 out of 100, and 114 clear 70 — about 9% of what has been published in this space. The remaining 938 are thinner: registry entries with no description, no published tool schema, or no commit in the last year. They are all still listed here, because knowing a server exists and is unmaintained is worth as much as knowing a good one exists.
io.github.KryptosAI/mcp-observatory leads the list at 94/100. Ida Pro MCP (92) and io.github.jasonxkensei/xproof (92) follow. Every score is the same five weighted inputs: security (CVE scanning, tool-poisoning detection, and whether the server authenticates at all), maintenance (commit recency, release cadence, and download trend), documentation, client compatibility, and token efficiency — how much of your context window the tool definitions consume before you have asked anything.
13 of these servers are published by the vendor behind the underlying API rather than by a third party, which is usually the difference between an integration that tracks upstream changes and one that quietly stops working. 5 currently carry an open CVE; those are flagged on the server's own page with the advisory and its severity.
Also see: All Security servers, Best Productivity, Best Developer Tools, Best Data, Best Finance
Last updated
Regression testing for MCP servers. Checks capabilities, invokes tools, detects schema drift.
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
Proof primitive for AI agents on MultiversX. Anchor file hashes on-chain as verifiable proofs.
MCP server for RocketCyber Managed SOC — incidents, alerts, agents, and customer telemetry.
MCP server for Enpass vaults: entries, passwords and TOTP/2FA codes, keychain-backed.
mcpki-server is the backend infrastructure for https://www.mcpki.org, enabling secure public key management and autonomous certificate handling for large language models (LLMs).
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Plugin for JADX to integrate MCP server
Read-only MCP server: verify credentials and browse escrows on the Stellar testnet contract.