Security MCP servers
Scanners, advisory feeds, and analysis tools an agent can drive. Security work is checklist-heavy, and agents are relentless about checklists. Ironically, this is also the category where you should read the permissions panel twice.
What engineers use them for
- Scan dependencies and summarize what's actually exploitable
- Watch advisories relevant to your stack
- Audit configurations against a baseline
- Draft the remediation ticket with evidence attached
Highest-graded right now
Graded on maintenance, completeness, and reliability. The formula is public →squirrelscan
Website QA for your coding agent: audit SEO, performance, security, accessibility over MCP.

Agent Security Scanner
Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
GitHits
Search public open-source code, documentation, metadata, vulnerabilities, changelogs, and examples.
mcp
Easily find and fix security issues in your applications leveraging Snyk platform capabilities.
Spotdb
Ephemeral data sandbox for AI workflows with guardrails and security
Nekzus Npm Sentinel
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
Server
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.