Leaderboard
Scored on public signals; components with none are listed as Unranked · Formula
Component
Domain
Vertical
| Rank | Score | Component | Description | Evidence | Last commit | Install |
|---|---|---|---|---|---|---|
| 1 | 98.575 | zinja-coder-jadx-ai-mcpmcp · ai-agents | JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse… | 2,741 stars · 249 forks | No one-command install · Source | |
| 2 | 98.431 | mariocandela-beelzebubmcp · ai-agents | Beelzebub is a honeypot framework that lets you build honeypot tools using MCP. Its purpose is to detect prompt injection or malicious agent behavior… | 2,165 stars · 205 forks | No one-command install · Source | |
| 3 | 97.272 | tufantunc-ssh-mcpmcp · ai-agents | MCP server exposing SSH control for Linux and Windows servers via Model Context Protocol. Securely execute remote shell commands with password or SSH… | 680 stars · 104 forks | No one-command install · Source | |
| 4 | 97.270 | golfmcp · ai-agents | Easiest framework for building MCP servers with automatic discovery of tools, prompts, and resources, plus enterprise-grade authentication and… | 839 stars · 70 forks | No one-command install · Source | |
| 5 | 97.244 | fofamapmcp · ai-agents | A MCP-enabled asset mapping and vulnerability scanning agent with AI self-reflection, allowing natural language queries and automated scanning… | 713 stars · 95 forks | No one-command install · Source | |
| 6 | 95.949 | duriantaco-skylosmcp · ai-agents | Privacy-first SAST tool for Python, TypeScript, and Go that detects dead code, security vulnerabilities, and code quality issues with hybrid AST and… | 546 stars · 30 forks | No one-command install · Source | |
| 7 | 95.384 | sdglbl-claude-codemcp · ai-agents | Enables Claude to execute code-related tasks through direct tools for code understanding, modification, command execution, and file operations with… | 303 stars · 37 forks | No one-command install · Source | |
| 8 | 94.417 | securityfortech-secops-mcpmcp · ai-agents | All-in-one security testing toolbox that brings together popular open source tools through a single MCP interface. Connected to an AI agent, it… | 208 stars · 33 forks | No one-command install · Source | |
| 9 | 92.499 | jnmetacode-shellwardmcp · ai-agents | AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII… | 131 stars · 23 forks | No one-command install · Source | |
| 10 | 92.266 | houtini-lmmcp · ai-agents | Provides expert prompt engineering capabilities through LM Studio integration, featuring 35+ specialized functions for code analysis, generation… | 113 stars · 26 forks | No one-command install · Source | |
| 11 | 90.598 | agent-security-scanner-mcpmcp · ai-agents | A security scanner for AI coding agents and autonomous assistants that scans code for vulnerabilities, detects hallucinated packages, blocks prompt… | 121 stars · 11 forks | No one-command install · Source | |
| 12 | 90.147 | red-hat-lightspeed-mcpmcp · ai-agents | A lightweight, self-hosted MCP server that connects LLM-based agents to Red Hat Lightspeed services, enabling natural language querying of read-only… | 24 stars · 38 forks | No one-command install · Source | |
| 13 | 89.041 | frida-agentmcp · ai-agents | AI-driven Android dynamic analysis tool wrapping Frida for automated reverse engineering with device management, script injection, method hooking, and… | 69 stars · 15 forks | No one-command install · Source | |
| 14 | 88.636 | arthurpanhku-docsentinelmcp · ai-agents | MCP server for AI agent for cybersecurity: automate assessment of documents, questionnaires & reports. Multi-format parsing, RAG knowledge base,Risks… | 86 stars · 9 forks | No one-command install · Source | |
| 15 | 88.002 | frida-game-hackingmcp · ai-agents | Provides Cheat Engine-like game hacking capabilities through Frida dynamic instrumentation for memory scanning, value modification, pattern matching… | 75 stars · 9 forks | No one-command install · Source | |
| 16 | 87.910 | snyk-studio-mcpmcp · ai-agents | Embeds Snyk's security engines into agentic workflows. Secures AI-generated code in real-time and accelerates the fixing vulnerability backlogs. | 55 stars · 16 forks | No one-command install · Source | |
| 17 | 87.540 | crazyrabbitltc-code-reviewmcp · ai-agents | Enables automated code reviews through multiple LLM providers by analyzing repository structures and evaluating code for security, performance… | 34 stars · 22 forks | No one-command install · Source | |
| 18 | 87.160 | dtkmn-zapmcp · ai-agents | Exposes OWASP ZAP web security scanning capabilities to AI agents via MCP for guided security assessments. | 64 stars · 9 forks | No one-command install · Source | |
| 19 | 86.808 | 82ch-mcp-dandanmcp · ai-agents | Real-time security framework for MCP servers that detects and blocks malicious AI agent behavior by analyzing tool call patterns and intent across… | 65 stars · 8 forks | No one-command install · Source | |
| 20 | 86.451 | rfunix-tengumcp · ai-agents | Orchestrates 80 penetration testing tools from Nmap to Metasploit with built-in safety controls, audit logging, PTES methodology, and autonomous agent… | 57 stars · 9 forks | No one-command install · Source | |
| 21 | 86.349 | securityronin-docx-mcpmcp · ai-agents | Read and edit Word (.docx) documents with track changes, comments, footnotes, and structural validation. The only MCP server combining w:ins/w:del… | 44 stars · 15 forks | No one-command install · Source | |
| 22 | 86.121 | carbeneai-talonmcp · ai-agents | Connects Claude Code to a Kali Linux VM via SSH for AI-assisted penetration testing with automated recon and OSCP-style reporting. | 58 stars · 8 forks | No one-command install · Source | |
| 23 | 85.766 | zebbern-kali-mcpmcp · ai-agents | A Docker-based MCP server that grants AI agents direct access to a comprehensive Kali Linux penetration testing toolkit through an isolated container… | 44 stars · 12 forks | No one-command install · Source | |
| 24 | 85.060 | mythos-agentmcp · ai-agents | Open-source AI security agent with SAST, DAST, and policy-as-code capabilities over MCP. | 43 stars · 10 forks | No one-command install · Source | |
| 25 | 84.859 | codeinspectusmcp · ai-agents | Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and… | 44 stars · 9 forks | No one-command install · Source | |
| 26 | 84.697 | projectmemorymcp · ai-agents | A proof-of-concept MCP server for security research demonstrating a multi-phase parasitic attack that disguises itself as a legitimate project memory… | 46 stars · 8 forks | No one-command install · Source | |
| 27 | 84.481 | multi-mcpmcp · ai-agents | A multi-model AI orchestration MCP server for automated code review and LLM-powered analysis, integrating with Claude Code and OpenCode to orchestrate… | 35 stars · 13 forks | No one-command install · Source | |
| 28 | 83.292 | octsshmcp · ai-agents | Provides LLMs with safe, controllable, and stateful SSH access to shell environments, enabling remote command execution and file transfers with async… | 44 stars · 6 forks | No one-command install · Source | |
| 29 | 80.448 | chimera-protocol-csl-coremcp · ai-agents | Deterministic AI safety policy engine with Z3 formal verification. Write, verify, and enforce machine-verifiable constraints for AI agents via MCP. | 16 stars · 12 forks | No one-command install · Source | |
| 30 | 79.577 | contrastcybermcp · ai-agents | Free security intelligence tools for AI agents including CVE lookup, OSINT, threat intel, and code security. | 33 stars · 4 forks | No one-command install · Source | |
| 31 | 78.871 | evan7198-pcileechmcp · ai-agents | Direct memory access through PCILeech DMA hardware for debugging, reverse engineering, and security research | 21 stars · 8 forks | No one-command install · Source | |
| 32 | 78.079 | aidongise-cell-prism-scannermcp · ai-agents | Scans AI agent skills, plugins, and MCP servers for security vulnerabilities using 39 detection rules. | 27 stars · 4 forks | No one-command install · Source | |
| 33 | 77.568 | ya-fridamcp · ai-agents | Comprehensive Frida dynamic instrumentation toolkit with 59 tools for device management, process control, script injection, memory operations, and ADB… | 30 stars · 3 forks | No one-command install · Source | |
| 34 | 76.502 | cve-mcpmcp · ai-agents | Unifies NVD, EPSS, CISA KEV, GitHub Advisory, and OSV into a single MCP server, enabling AI agents to query vulnerability intelligence… | 20 stars · 5 forks | No one-command install · Source | |
| 35 | 76.446 | superclaude-org-superagentmcp · ai-agents | Orchestrates Codex and Gemini CLI agents with parallel execution across multiple working directories, enabling delegation of complex tasks to 16… | 14 stars · 9 forks | No one-command install · Source | |
| 36 | 75.153 | red-team-mcpmcp · ai-agents | An MCP server for red teaming that enables AI agents to perform port scanning, vulnerability scanning, SSH operations, and Metasploit exploitation… | 16 stars · 6 forks | No one-command install · Source | |
| 37 | 73.944 | toolfencemcp · ai-agents | A local, fail-closed firewall for MCP tool calls that enforces least-privilege policies and human approval between AI agents and stdio MCP servers. | 101 stars | No one-command install · Source | |
| 38 | 72.926 | github-security-mcpmcp · ai-agents | An MCP server that enables AI agents to perform comprehensive GitHub security audits across org settings, repositories, Actions workflows, secrets… | 14 stars · 5 forks | No one-command install · Source | |
| 39 | 72.060 | nmap-mcpmcp · ai-agents | A production-ready MCP server that wraps Nmap to enable AI agents to perform automated network security assessments, including port scanning, host… | 16 stars · 3 forks | No one-command install · Source | |
| 40 | 71.394 | local-supervisor-bridgemcp · ai-agents | Enables ChatGPT web to safely read and modify only explicitly allowed local project files through OpenAI Secure MCP Tunnel, including git operations… | 15 stars · 3 forks | No one-command install · Source | |
| 40 | 71.394 | jimmyracheta-ai-runtime-guardmcp · ai-agents | Runtime policy enforcement for AI agents - prevents accidental damage to your systems, unauthorized agent access and automates backup-before-write for… | 15 stars · 3 forks | No one-command install · Source | |
| 42 | 71.333 | jinning6-noospheremcp · ai-agents | Digital consciousness repository and community MCP server. Upload epiphanies, decisions, warnings, and patterns as consciousness payloads, then… | 18 stars · 2 forks | No one-command install · Source | |
| 43 | 70.795 | ashfordeou-graspmcp · ai-agents | Codebase dependency analysis, architecture mapping, and security scanning for AI agents. | 17 stars · 2 forks | No one-command install · Source | |
| 44 | 69.750 | synapse-layermcp · ai-agents | Zero-knowledge memory layer for AI agents with differential privacy and AES-256 encryption. | 13 stars · 3 forks | No one-command install · Source | |
| 45 | 69.545 | boost-securitymcp · ai-agents | Safeguards coding agents against adding vulnerable packages into projects | 15 stars · 2 forks | No one-command install · Source | |
| 46 | 69.349 | withoneai-mcpmcp · ai-agents | Connect AI agents to 250+ apps through a single MCP server with managed authentication. | 11 stars · 4 forks | No one-command install · Source | |
| 47 | 69.255 | akramiot-mcp-ai-soc-shermcp · ai-agents | MCP Server to do dynamic AI SOC Security Threat analysis for a Text2SQL AI Agent. | 10 stars · 5 forks | No one-command install · Source | |
| 48 | 66.893 | bug-bounty-intelligence-mcpmcp · ai-agents | AI-powered smart contract security analysis for AI agents and developers, enabling scanning of Solidity repos for vulnerabilities. | 10 stars · 3 forks | No one-command install · Source | |
| 49 | 66.032 | agentgraph-co-agentgraphmcp · ai-agents | Trust verification and security scanning for AI agents. Checks security posture of third-party MCP servers and tools with signed attestations… | 4 stars · 6 forks | No one-command install · Source | |
| 50 | 65.698 | mergenmcp · ai-agents | AI-Powered Red Team MCP Server enabling autonomous penetration testing via Model Context Protocol with 44+ security tools for AI agents. | 14 stars · 1 fork | No one-command install · Source | |
| 51 | 64.883 | eresussecurity-sentinelmcp · ai-agents | Security scanning platform for AI and LLM ecosystems with MCP proxy, schema validation, and 48+ security probes. | 13 stars · 1 fork | No one-command install · Source | |
| 52 | 63.155 | hs-sql-agentmcp · ai-agents | C# SQL Agent MCP server featuring raw SQL input, strict AST validation, and an embedded Admin UI. Eliminates LLM hallucinations and security risks… | 11 stars · 1 fork | No one-command install · Source | |
| 53 | 62.857 | speclock-ai-constraint-enginemcp · ai-agents | AI Constraint Engine with AI Patch Firewall. 42 MCP tools. Patch Gateway (ALLOW/WARN/BLOCK verdicts), diff-native review (10 scored signals, hard… | 3,558 installs | No commit datelisted | No one-command install · Source |
| 54 | 62.111 | jignesh-ponamwar-skillsmcp · ai-agents | Self-hostable MCP server providing a semantically-searchable agent skills registry with progressive disclosure and security scanning. | 7 stars · 3 forks | No one-command install · Source | |
| 55 | 60.684 | skillsguardmcp · ai-agents | Static security scanner for AI agent skill packages that detects malicious SKILL.md files and bundled scripts before they run. | 15 stars | No one-command install · Source | |
| 56 | 60.677 | kimwwk-repocrunchmcp · ai-agents | MCP server that gives AI agents structured, ground-truth GitHub repository intelligence. Analyze tech stack, dependencies, architecture, health… | 9 stars · 1 fork | No one-command install · Source | |
| 57 | 60.035 | mrgnss-claude-desktop-commandermcp · ai-agents | Enables Claude Desktop to execute terminal commands and manage files on the user's computer with security measures like command blacklisting and path… | 6 stars · 3 forks | No one-command install · Source | |
| 58 | 59.040 | yashash4-reef-registrymcp · ai-agents | MCP supply chain security registry with signed verification, runtime policy enforcement, and insurance artifacts for AI agent fleets. | 13 stars | No one-command install · Source | |
| 59 | 58.185 | pooriayousefi-intellistantmcp · ai-agents | Production C++23 multi-agent development framework with specialized agents for coding, DevOps, documentation, testing, data analysis, and security. | 6 stars · 2 forks | No one-command install · Source | |
| 60 | 57.311 | ente0-mcpstrikemcp · ai-agentsalso listed as mcpstrike | Autonomous penetration testing framework combining LLM analysis with 14 security tools for vulnerability discovery, exploitation, and reporting. | 11 stars | No one-command install · Source | |
| 60 | 57.311 | sabbamcp · ai-agents | MCP server for security bug-finding that proves every finding by running exploits, enabling agents to verify changes and find bugs with… | 11 stars | No one-command install · Source | |
| 63 | 55.213 | mcp-kql-servermcp · ai-agents | MCP server for executing Kusto Query Language (KQL) queries against Azure Data Explorer clusters, integrating with Claude Desktop and VS Code via… | 6 forks | No one-command install · Source | |
| 64 | 55.168 | randomparity-rusty-imapmcp · ai-agents | Security-first IMAP email MCP server written in Rust with prompt-injection defenses. | 6 stars · 1 fork | No one-command install · Source | |
| 64 | 55.168 | preclickmcp · ai-agentsalso listed as preclick-mcp-server | URL preflight scanning service that analyzes links for security threats and verifies alignment with the agent's intended browsing goal. | 6 stars · 1 fork | No one-command install · Source | |
| 64 | 55.168 | pincer-mcpmcp · ai-agents | A security-hardened MCP gateway that enables AI agents to call LLM APIs (Gemini, OpenAI, Claude, etc.) using ephemeral proxy tokens, eliminating… | 6 stars · 1 fork | No one-command install · Source | |
| 64 | 55.168 | publish-registry-helpermcp · ai-agents | Provides automated guidance for publishing MCP servers to the registry through specialized prompts that evaluate optimal publishing approaches… | 6 stars · 1 fork | No one-command install · Source | |
| 69 | 53.985 | ipgeolocation-iomcp · ai-agents | IP geolocation, security intelligence, ASN lookups, timezone conversions, astronomy data, and user-agent parsing. | 4 stars · 3 forks | No one-command install · Source | |
| 69 | 53.985 | usap-skillsmcp · ai-agents | Exposes 79 cybersecurity skills and 12 orchestrator agents over MCP, with a typed 11-field output contract, an enforced resolvable-evidence gate (no… | 4 stars · 3 forks | No one-command install · Source | |
| 69 | 53.985 | mcp-fortressmcp · ai-agents | Security scanner detecting vulnerabilities, prompt injection, and tool poisoning | 4 stars · 3 forks | No one-command install · Source | |
| 72 | 53.790 | wyre-technology-huntressmcp · ai-agents | Connects AI assistants to the Huntress cybersecurity platform for managing agents, incidents, organizations, and signals. | 1 star · 4 forks | No one-command install · Source | |
| 73 | 52.498 | armorcodexmcp · ai-agents | Intent-based security governance for OpenAI Codex and ChatGPT. Register intent plans before tool calls, apply natural-language policy rules, and get… | 5 stars · 1 fork | No one-command install · Source | |
| 73 | 52.498 | eltociear-security-auditmcp · ai-agents | Scan MCP servers, AI agent skills, and plugins for 68+ security attack signatures including credential theft and code execution patterns. | 5 stars · 1 fork | No one-command install · Source | |
| 73 | 52.498 | mitre-att-ck-mcp-servermcp · ai-agents | Enables AI-native access to the MITRE ATT\&CK framework, allowing LLMs and agents to query techniques, threat groups, software, and generate ATT\&CK… | 5 stars · 1 fork | No one-command install · Source | |
| 76 | 52.135 | dinanathdash-envaultmcp · ai-agents | Secure secrets management with Human-In-The-Loop interception for agent mutations via the Envault platform. | 4 stars · 2 forks | No one-command install · Source | |
| 76 | 52.135 | haiec-ai-agent-security-free-mcpmcp · ai-agents | Offers a control surface for AI agent security with four independent checks: source-code scanning, tenant isolation, LLM content verification, and… | 4 stars · 2 forks | No one-command install · Source | |
| 76 | 52.135 | gh-parth-unjiya-odoo-gatewaymcp · ai-agents | Security-first, version-agnostic gateway for Odoo 17/18/19 with 27 tools, 5 resources, and 7 prompts. | 4 stars · 2 forks | No one-command install · Source | |
| 76 | 52.135 | leadbroaf-agentmcp · ai-agents | Provides a foundation for building persistent agent systems with memory storage, user authentication, and n8n workflow integration designed for SaaS… | 4 stars · 2 forks | No one-command install · Source | |
| 80 | 50.895 | 1claw-mcpmcp · ai-agents | MCP server for secure, just-in-time secret retrieval from 1claw vault and malicious content inspection, enabling AI agents to access secrets and… | 2 stars · 3 forks | No one-command install · Source | |
| 81 | 49.118 | draugrmcp · ai-agents | Security scanning for AI agents: SAST, SCA, secrets, IaC, DAST, ranked by real risk. | 4 stars · 1 fork | No one-command install · Source | |
| 81 | 49.118 | claude-code-starter-kit-mcpmcp · ai-agents | Enables AI-powered automated testing, security scanning, code review, and maintenance tasks directly within Claude Code or desktop. | 4 stars · 1 fork | No one-command install · Source | |
| 81 | 49.118 | skillsync-mcpmcp · ai-agents | An MCP server for searching, security scanning, installing, and managing skills from the SkillsMP marketplace, designed for Claude Code and other… | 4 stars · 1 fork | No one-command install · Source | |
| 84 | 48.479 | wg21-wiki-mcpmcp · ai-agents | A local MCP server that gives an LLM agent read access to the WG21 (ISO C++) committee wiki as a verifiable source of truth, requiring authentication… | 1 star · 3 forks | No one-command install · Source | |
| 85 | 47.273 | agentseal-mcp-intelmcp · ai-agents | Enables users to scan MCP servers for security threats, check installed servers, and analyze config files for risks, all from AI assistants like… | 3 stars · 2 forks | No one-command install · Source | |
| 85 | 47.273 | sparkvibe-guardianshieldmcp · ai-agents | AI security layer with code scanning, PII detection, prompt injection defense, and CVE checking. | 3 stars · 2 forks | No one-command install · Source | |
| 87 | 46.654 | safe-bifrostmcp · ai-agents | A local MCP server that provides a safe plan-and-execute workflow for AI coding assistants, storing plans and tasks, and executing agent commands with… | 5 stars | No one-command install · Source | |
| 87 | 46.654 | eigen-plc-mcpmcp · ai-agents | An open-source MCP server for industrial automation that generates, debugs, and validates PLC code for Siemens S7-1200, serving as a free and… | 5 stars | No one-command install · Source | |
| 87 | 46.654 | agentic-storemcp · ai-agents | Open-source AI agent toolkit providing code analysis, security scanning, web search, and persistent memory tools. | 5 stars | No one-command install · Source | |
| 87 | 46.654 | kevin-valerio-aflppmcp · ai-agents | Integrates with AFL++ fuzzing framework for automated security testing through workspace management, instrumented binary compilation, corpus… | 5 stars | No one-command install · Source | |
| 91 | 44.256 | huntermcp · ai-agents | AI-driven penetration testing MCP server that equips Claude with 13 tools for automated reconnaissance, analysis, vulnerability validation, and… | 3 stars · 1 fork | No one-command install · Source | |
| 91 | 44.256 | fuzzmind-frida-mcpmcp · ai-agents | A Frida MCP server for authorized dynamic analysis and application security research, exposing device/session management, script injection, process… | 3 stars · 1 fork | No one-command install · Source | |
| 93 | 43.498 | goodreads-mcpmcp · ai-agents | A read-only MCP server for Goodreads that enables LLMs to search for books, retrieve detailed book info with ratings and reviews, and explore… | 2 stars · 2 forks | No one-command install · Source | |
| 93 | 43.498 | myfitnesspal-mcp-servermcp · ai-agents | Enables Claude to manage MyFitnessPal food diaries, nutrition goals, exercises, body measurements, and water intake via a remote MCP server using… | 2 stars · 2 forks | No one-command install · Source | |
| 93 | 43.498 | osidb-mcpmcp · ai-agents | MCP server for OSIDB (Red Hat Product Security's vulnerability management system). Enables read-only querying of flaws, affects, trackers, and status… | 2 stars · 2 forks | No one-command install · Source | |
| 93 | 43.498 | revsmoke-prompt-rejectormcp · ai-agents | Security gateway for AI agents: detects prompt injections, jailbreaks, and common vulnerabilities. | 2 stars · 2 forks | No one-command install · Source | |
| 97 | 43.275 | 0xmihirk-herculesmcp · ai-agentsalso listed as hercules-mcp | Penetration testing tools via containerized Kali Linux for Claude. | 4 stars | No one-command install · Source | |
| 97 | 43.275 | seraphmcp · ai-agents | Seraph is Kondux's crypto transaction firewall and risk-scoring MCP server for AI agents. It provides OAuth-secured Streamable HTTP tools for… | 4 stars | No one-command install · Source | |
| 97 | 43.275 | garagon-aguaramcp · ai-agents | Security scanner for AI agent skills and MCP server configurations. | 4 stars | No one-command install · Source |
Score colour shows how many signals stand behind it, never how good it is: amber, three or more; dimmer amber, two; grey, one. The Evidence column names them.
Stars, forks and last commit are as GitHub reported them when Armory last read each repository: for most, or later. A repository may have changed since.