Security & Testing MCP Servers

738 Security & Testing MCP servers on Mcprush.

738 servers · 738 listings

Ranked by readers of the listing, not by downloads
Security & Testing

MCP axe-core audit server for Claude Code — WCAG A/AA/AAA compliance audits with compressed results optimized for Claude's context window

5 tools
from $10/mo

MCP server for real-time dependency security — checks packages against CVE databases before your AI coding agent installs them. Works with

7 tools
from $15/mo

Real-time MCP security proxy - intercepts, scans, and gates AI agent tool calls. Now with WARD.md policy enforcement.

28 tools
from $14/mo

Sanctions screening for KYC/AML — check Czech companies and individuals against EU Financial Sanctions (FSF) and US OFAC SDN lists

5 tools
from $19/mo

Supply chain security for AI-generated code - scans packages, Docker images, and IDE extensions (VS Code, Cursor, JetBrains) before install

28 tools
from $19/mo

MarketNow MCP Server v1.7.0 — Trust layer for agent commerce. 11 MCP tools: search_skills, get_skill, list_categories, get_manifest

8 tools
from $15/mo

Security scanner for MCP (Model Context Protocol) servers. Detect vulnerabilities, secrets, injection risks, and misconfigurations before

4 tools
from $19/mo

Model Context Protocol server for AcuityScan — run website security, accessibility, performance, and SEO scans from Claude Desktop, Cursor

Free

Security & Testing MCP servers on mcprush stand in front of everything else an agent does: allow, deny or ask, per tool; short-lived credentials instead of keys in the context window; findings ranked by whether they are reachable rather than by how many there are.

What to look at before installing one is where the credential lives and whether it ever enters the model’s context. That single answer separates most of this category into two halves. Every server here names the publisher behind it and whether that publisher has been verified, the runtime it uses, how it authenticates, the tool surface it exposes and the price model it is sold under — and where a security scan has been run against it, what the scan found. The filters on the left narrow it further and the sort at the top decides what comes first.

A server that runs on its publisher’s infrastructure is reached through the mcprush gateway, so one key covers everything installed against your account, the calls are metered where you can see them and the ceiling on what they may cost is yours to set. Installing one is a line of the mcprush CLI — npx mcprush@latest add, followed by the server’s id — and a --client flag writes another client’s config instead of the default one. A server that runs on your own machine carries its publisher’s own instructions instead, and the listing says which of the two it is before you install anything.

Compare
tick one more
Side-by-side