io.github.KryptosAI/mcp-observatory
Regression testing for MCP servers. Checks capabilities, invokes tools, detects schema drift.
1,203 servers in this category
MCPpedia tracks 1,203 security MCP servers. 265 of them score at least 50 out of 100, and 114 clear 70 — about 9% of what has been published in this space. The remaining 938 are thinner: registry entries with no description, no published tool schema, or no commit in the last year. They are all still listed here, because knowing a server exists and is unmaintained is worth as much as knowing a good one exists.
io.github.KryptosAI/mcp-observatory leads the list at 94/100. io.github.jasonxkensei/xproof (92) and Ida Pro MCP (92) follow. Every score is the same five weighted inputs: security (CVE scanning, tool-poisoning detection, and whether the server authenticates at all), maintenance (commit recency, release cadence, and download trend), documentation, client compatibility, and token efficiency — how much of your context window the tool definitions consume before you have asked anything.
13 of these servers are published by the vendor behind the underlying API rather than by a third party, which is usually the difference between an integration that tracks upstream changes and one that quietly stops working. 5 currently carry an open CVE; those are flagged on the server's own page with the advisory and its severity.
Also see: Best Security MCP servers, Productivity, Developer Tools, Data, Finance
Last updated
Regression testing for MCP servers. Checks capabilities, invokes tools, detects schema drift.
Proof primitive for AI agents on MultiversX. Anchor file hashes on-chain as verifiable proofs.
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
MCP server for RocketCyber Managed SOC — incidents, alerts, agents, and customer telemetry.
Model Context Protocol for WinDBG
mcpki-server is the backend infrastructure for https://www.mcpki.org, enabling secure public key management and autonomous certificate handling for large language models (LLMs).
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
MCP server for Enpass vaults: entries, passwords and TOTP/2FA codes, keychain-backed.
Plugin for JADX to integrate MCP server
MCP server for Atomic Red Team
Read-only MCP server: verify credentials and browse escrows on the Stellar testnet contract.
A collection of tools and helpers for creating MCP servers and clients
Secure secret management with a Human-In-The-Loop (HITL) interceptor for agent mutations.
Manage Proxmox VE via Cursor: QEMU, LXC, storage, HA, firewall, access.
Signed receipts for agent, API, and MCP interactions. Portable and offline-verifiable.
Lean Gmail MCP server with auto authentication support
Educational dermatology knowledge and lesion tooling. No credentials needed. Not a medical device.
Security middleware for MCP. Blocks prompt injection, PII leakage, and resource exhaustion.
AI smart contract forge — 8-agent security audits, generation, and compilation across 8 chains
MCP server for ScanMalware.com URL scanning, malware detection, and analysis.