</>MCP Agents Market

Security

106 listings

Open in browse

strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Skill53.4k

agents

Multi-harness agentic plugin marketplace for Claude Code, Codex CLI, Cursor, OpenCode, GitHub Copilot, and Gemini CLI

Plugin40.1k

nanoclaw

A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK

Agent30.5k

Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·

Skill29.2k

reverse-skill

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Cl

Skill26.8k

SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

MCP Server22.4k

pentagi

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

Agent21.9k

open-code-review

Fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.

Plugin21k

teleport

The easiest, and most secure way to access and protect all of your infrastructure.

MCP Server20.8k

semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Plugin16.4k

watermarks-remover

Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD

Skill16.1k

PentestGPT

Automated Penetration Testing Agentic Framework Powered by Large Language Models

Agent15k

SkillSpector

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

Skill14.9k

dirsearch

Web path scanner

MCP Server14.7k

bytebase

Database governance built for humans and agents — controlling changes and access across every major database.

MCP Server14.4k

casdoor

An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway and auth server with web UI supporting OpenClaw, MCP, OAuth, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MFA, Face ID, Google Workspace, Azure AD

MCP Server14.3k

kubescape

Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.

MCP Server11.7k

ida-pro-mcp

AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

MCP Server11.6k

hexstrike-ai

HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capa

MCP Server11.3k

iFixAi

Independent Auditing of AI Agents. Run by human or the agent itself, to answer the most crucial question in the AI Agent Economy. Is the agent doing what is supposed to do? With iFixAi you can have this answer in less than 120 seconds.

Skill11.3k

Shadowbroker

Open-source intelligence for the global theater. Track everything from the corporate/private jets of the wealthy, and spy satellites, to seismic events in one unified interface. Hook an AI agent up to have it parse through data and find previously unseen correlations. The knowledge is available to a

Skill10.9k

codex-security

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security

Agent9.9k

GhidraMCP

MCP Server for Ghidra

MCP Server9.9k

ctf-tools

Some setup scripts for security research tools.

MCP Server9.5k

lamda

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida, proxy/VPN/frp/P2P networking, MCP/Agent, 160+ APIs, designed for multi-device clusters and engineered deployments.

MCP Server8.2k

defending-code-reference-harness

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Skill7.4k

android-reverse-engineering-skill

Claude Code skill to support Android app's reverse engineering

Skill7.2k

skills

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Plugin6.8k

superagent

Superagent protects your AI applications against prompt injections, data leaks, and harmful outputs. Embed safety directly into your app and prove compliance to your customers.

MCP Server6.7k

CyberStrikeAI

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.

MCP Server6.1k

destructive_command_guard

The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.

Plugin5.8k

T3MP3ST

autonomous red teaming platform; multi-agent offensive-security meta-harness

MCP Server5.8k

Decepticon

Autonomous Hacking Agent for Red Team

Agent5.3k

dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

MCP Server5.3k

unidbg

Allows you to emulate an Android native library, and an experimental iOS emulation

MCP Server5.2k

agent-skills

The secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Cursor, Copilot and more with absolute confidence.

Skill5.1k

agentgateway

Next Generation Agentic Proxy for AI Agents and MCP servers

MCP Server4.7k

Knowledge-Base

Knowledge Base 慢雾安全团队知识库

MCP Server4.6k

Agentic-Bug-Hunter

AI-powered bug bounty hunting toolkit that works with or without subscription.

Plugin4.6k

varlock

AI-safe .env files: Schemas for agents, Secrets for humans.

MCP Server4.3k

Claude-BugHunter

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.

Skill4.2k

OpenBot

Open-source AI coworkers that each get a computer of their own: a browser, files and tools, with every action decided before it happens and recorded after. Bring any AG-UI agent.

Agent4.1k

ivre

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f,

MCP Server4.1k

claude-octopus

Surface AI blindspots before you ship. Put up to 8 AI models on every research, design or coding task.

Plugin4k

octelium

A next-gen FOSS self-hosted unified zero trust secure access platform that can operate as a remote access VPN, a ZTNA platform, API/AI/MCP gateway, a PaaS, an ngrok-alternative and a homelab infrastructure.

MCP Server4k

claude-code-hooks-mastery

Master Claude Code Hooks

Plugin3.9k

Aliens_eye

Hunt down 840+ social media accounts using AI

MCP Server3.8k

tracecat

Open-source security automation platform for teams and AI agents

MCP Server3.8k

donutbrowser

Simple Yet Powerful Anti-Detect Browser 🍩

MCP Server3.8k

ghidra-mcp

Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.

MCP Server3.7k

raptor

Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we configure the agent for adversarial thinking, and perform research or attack/defense operations.

Plugin3.7k

ipsw

iOS/macOS Research Swiss Army Knife

Skill3.7k

metorial

Connect any AI model to 1200+ integrations (MCP, CLI, API)

MCP Server3.4k

django-oauth-toolkit

OAuth2 goodies for the Djangonauts!

MCP Server3.3k

VulnClaw

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

Agent3.2k

ctf-skills

Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more

Skill3.2k

CCPlugins

Best Claude Code framework that actually save time. Built by a dev tired of typing "please act like a senior engineer" in every conversation.

Plugin2.8k

jarvis-registry

Connect any AI copilot or autonomous agent to your enterprise tools — through a single, secure MCP/Agent gateway with built-in identity, access control, and full observability.

MCP Server2.8k

jadx-ai-mcp

Plugin for JADX to integrate MCP server

MCP Server2.7k

visa-vulnerability-agentic-harness

Visa Vulnerability Agentic Harness

Agent2.7k

CyberStrike

Open-source AI-powered offensive security harness for automated penetration testing.

Agent2.6k

megalinter

🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.

Agent2.6k

Claude-OSINT

8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bo

Skill2.6k

agent-toolkit-for-aws

Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS

Plugin2.6k

jwx

Complete implementation of JWx (Javascript Object Signing and Encryption/JOSE) technologies for Go. #golang #jwt #jws #jwk #jwe

Plugin2.4k

Kunlun-M

KunLun-M — Open-source static code analysis for PHP, Nodejs/JavaScript, Python, Golang, Java and C/C++, with AST-based semantic scanning and one-click AI Agent integration (OpenClaw, Codex, Claude Code, Hermes, and more).

Skill2.4k

pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.

Agent2.2k

jar-analyzer

Jar Analyzer - 一个 JAR 包 GUI 分析工具,内置 AI 助手协助分析,支持 JAR DIFF 分析,方法调用关系搜索,方法调用链 DFS 算法分析,模拟 JVM 的污点分析验证 DFS 结果,字符串搜索,Java Web 组件入口分析,CFG 程序分析,JVM 栈帧分析,自定义表达式搜索等

MCP Server2.2k

ggshield

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.

Plugin2k

claude-code-tools

Practical productivity tools for Claude Code, Codex-CLI, and similar CLI coding agents.

Plugin2k

jshookmcp

js hook toolkit that all you need

MCP Server2k

legba

The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷

Skill1.9k

clawgod

ClawGod is a runtime patch applied to the official Claude Code. It continues to be supported with each version update.

Plugin1.9k

wooyun-legacy

wooyun-legacy skill for claude code

Plugin1.8k

agent

Ship your code, on autopilot. An open source agent that lives on your machines 24/7 and keeps your apps running. 🦀

Agent1.7k

quark-engine

Plugin1.7k

AboutSecurity

Everything for pentest. | 渗透测试知识库,以 AI Agent 可执行的格式沉淀安全方法论。

Skill1.7k

pentest-ai

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Agent1.6k

pentest-copilot

Pentest Copilot is an AI-powered browser based ethical hacking assistant tool designed to streamline pentesting workflows.

Agent1.3k

sast-skills

Collection of agent skills that turn your AI coder into a SAST scanner

Skill1.3k

claude-delegator

Delegate tasks to Codex and Gemini directly from within Claude Code.

Plugin996

powerview.py

Powerview on steroids

MCP Server995

obot

Complete AI Governance Platform from Obot AI

MCP Server991

skills

Agent Skills used by the Sentry team for development.

Skill986

opensquat

openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.

MCP Server985

VulnHunter

Agentic AI security tool that applies proactive, attacker-first analysis directly to source code.

Skill985

medusa

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an always-on AI attack-signature scanner and native Rust & PHP rules. Also: medusa scan --git to vet any repo, medusa secrets scan for leaked API keys. 40,00

Agent979

reconmap

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured

MCP Server975

wassette

Wassette: A security-oriented runtime that runs WebAssembly Components via MCP

MCP Server942

claude-code-devcontainer

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Plugin937

shellfirm

Safety guardrails for ai coding agents and human terminal commands

Plugin932

pentest-agents

Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

Agent907

trustclaw

A self-hostable personal AI agent with vector memory, Composio tools, and Telegram.

Agent894

coderunner

A local sandbox for your AI agents

MCP Server891

Claude-Skills-Governance-Risk-and-Compliance

Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, CCPA/CPRA, and others. Benchmark 93% (with skills) vs 74%

Skill891

GHOST-osint-crm

GHOST - Global Human Operations & Surveillance Tracking: Open-source investigation management platform for tracking people, connections, and intelligence data. Because Excel spreadsheets are for accountants, not investigators. Non-commercial license.

MCP Server884

vulhunt

Vulnerability detection framework by Binarly's REsearch team

MCP Server884

code-audit

Skill884

pocketpaw

Your AI agent in 30 seconds. Not 30 hours. Self-hosted, open-source personal AI with desktop installer, multi-agent Command Center(Deep Work), and 7-layer security. Anthropic, OpenAI, or Ollama.

Agent880

awesome-llvm-security

awesome llvm security [Welcome to PR]

Skill880

cain-agent

Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK

Agent878

arrakis

A fully customizable and self-hosted sandboxing solution for AI agent code execution and computer use. It features out-of-the-box support for backtracking, a simple REST API and Python SDK, automatic port forwarding, and secure MicroVM isolation. Perfect for safely running, testing, and backtracking

MCP Server873

npm-security-best-practices

[Updated for AI 🤖] Continuous updates on how to stay safe from NPM supply chain attacks

Skill857

shuru

A local-first microVM sandbox for running AI agents safely on macOS & Linux

Skill851

ThinkWatch

Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.

MCP Server814

hoop

One gateway in front of every protocol. Same policy across MCP, LLMs, databases and containers. Wire-level enforcement at under 5ms.

MCP Server812

Related searches