Skip to content

A curated list of Model Context Protocol (MCP) servers with comprehensive security validation using the mcp-scan security assessment pipeline

License

Notifications You must be signed in to change notification settings

fuzzylabs/awesome-secure-mcp-servers

Repository files navigation

Awesome Secure MCP Servers Awesome

Secure Model Context Protocol (MCP) servers with automated security validation, vulnerability scanning, and tool poisoning detection. Browse 16+ vetted MCP servers for building secure agentic AI systems.

πŸ›‘οΈ Security-First MCP Server Directory

Find secure MCP servers for your agentic AI applications with confidence. Model Context Protocol is the USB-C of building agentic systems - providing standardized, secure connections between AI agents and external tools. Each server undergoes automated security scanning including dependency vulnerability checks, static analysis, and MCP-specific threat detection (tool poisoning, cross-origin attacks).

πŸš€ Quick Start

  1. Browse servers by category below
  2. Check security status - look for πŸ›‘οΈ Verified Secure or ⚠️ Conditional ratings
  3. Review scores - higher scores indicate better security posture
  4. Follow repository links for installation instructions

πŸ“Š Security Status Legend

  • πŸ›‘οΈ Verified Secure (85-100): Comprehensive validation passed
  • ⚠️ Conditional (70-84): Secure with specific configuration requirements
  • ⏳ Awaiting Scan: Repository currently inaccessible for scanning
  • ❌ Not Recommended (0-49): Known security issues

πŸ“š Table of Contents

Security Status by Category

Last Updated: 2025-07-28 06:03 UTC
Total Servers: 16

Official Servers

Server Version Security Status Description
Everything (Reference Server) 0.5.0 ⚠️ Conditional (πŸ“Š Score: 84/100) Reference server demonstrating all MCP features
Fetch Server 0.3.2 ⚠️ Conditional (πŸ“Š Score: 84/100) Web content fetching and conversion for efficient LLM usage
Filesystem Server 0.4.1 ⚠️ Conditional (πŸ“Š Score: 84/100) Secure file operations with configurable access controls
Git Server 0.2.1 ⚠️ Conditional (πŸ“Š Score: 84/100) Tools to read, search, and manipulate Git repositories
Memory Server 0.1.3 ⚠️ Conditional (πŸ“Š Score: 84/100) Persistent memory using a local knowledge graph
Sequential Thinking Server 0.1.0 ⚠️ Conditional (πŸ“Š Score: 84/100) Dynamic and reflective problem-solving through thought sequences
Time Server 0.1.2 ⚠️ Conditional (πŸ“Š Score: 84/100) Time and timezone conversion capabilities

Enterprise Servers

Server Version Security Status Description
AWS MCP Server 1.2.0 πŸ›‘οΈ Verified Secure (πŸ“Š Score: 89/100) AWS service integration with IAM controls
Docker Server 1.5.2 πŸ›‘οΈ Verified Secure (πŸ“Š Score: 91/100) Docker container management with security controls
GitHub MCP Server 1.0.0 ⚠️ Conditional (πŸ“Š Score: 81/100) GitHub's official MCP Server for repository management
Notion MCP Server 0.3.1 ⚠️ Conditional (πŸ“Š Score: 74/100) Notion official MCP server for workspace integration
Stripe MCP Server 0.2.0 πŸ›‘οΈ Verified Secure (πŸ“Š Score: 91/100) Interact with Stripe API for payments and financial data

Security Tools

Server Version Security Status Description
Nuclei Security Scanner 0.2.0 πŸ›‘οΈ Verified Secure (πŸ“Š Score: 92/100) Template-based vulnerability scanner with extensive security checks

Community Servers

Server Version Security Status Description
PostgreSQL MCP Server 0.4.2 πŸ›‘οΈ Verified Secure (πŸ“Š Score: 86/100) PostgreSQL database operations and query execution
Slack MCP Server 1.0.3 ⚠️ Conditional (πŸ“Š Score: 77/100) Slack workspace integration for messaging and collaboration

Under Review

Server Version Security Status Description
Anthropic Computer Use 0.1.0 ⏳ Awaiting Scan Desktop automation with screen capture and input control

πŸ“Š Detailed Security Assessments

Click on server scores above to jump to detailed security breakdowns:

AWS MCP Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 100/100 βž– Scans package.json, requirements.txt, etc. for known CVEs

βž– Not applicable

  • No recognized dependency files found

πŸ› Code Security Analysis: 70/100 ⚠️ Static analysis for common security vulnerabilities in source code

⚠️ 0 potential issues found

  • Bandit completed but output could not be parsed
Docker Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 100/100 βž– Scans package.json, requirements.txt, etc. for known CVEs

βž– Not applicable

  • No recognized dependency files found

πŸ› Code Security Analysis: 85/100 ⚠️ Static analysis for common security vulnerabilities in source code

⚠️ 1 potential issues found

  • Found 1 critical security issue(s)
Everything (Reference Server) Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 60/100 ⚠️ Scans package.json, requirements.txt, etc. for known CVEs

⚠️ 4 potential issues found

  • Found 4 vulnerability/vulnerabilities in dependencies

πŸ› Code Security Analysis: 100/100 βœ… Static analysis for common security vulnerabilities in source code

βœ… No issues found

  • No critical security vulnerabilities found
Fetch Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 60/100 ⚠️ Scans package.json, requirements.txt, etc. for known CVEs

⚠️ 4 potential issues found

  • Found 4 vulnerability/vulnerabilities in dependencies

πŸ› Code Security Analysis: 100/100 βœ… Static analysis for common security vulnerabilities in source code

βœ… No issues found

  • No critical security vulnerabilities found
Filesystem Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 60/100 ⚠️ Scans package.json, requirements.txt, etc. for known CVEs

⚠️ 4 potential issues found

  • Found 4 vulnerability/vulnerabilities in dependencies

πŸ› Code Security Analysis: 100/100 βœ… Static analysis for common security vulnerabilities in source code

βœ… No issues found

  • No critical security vulnerabilities found
Git Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 60/100 ⚠️ Scans package.json, requirements.txt, etc. for known CVEs

⚠️ 4 potential issues found

  • Found 4 vulnerability/vulnerabilities in dependencies

πŸ› Code Security Analysis: 100/100 βœ… Static analysis for common security vulnerabilities in source code

βœ… No issues found

  • No critical security vulnerabilities found
GitHub MCP Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 50/100 βž– Scans package.json, requirements.txt, etc. for known CVEs

βž– Not applicable

  • Go dependency scanning not yet implemented

πŸ› Code Security Analysis: 100/100 βœ… Static analysis for common security vulnerabilities in source code

βœ… No issues found

  • No critical security vulnerabilities found
Memory Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 60/100 ⚠️ Scans package.json, requirements.txt, etc. for known CVEs

⚠️ 4 potential issues found

  • Found 4 vulnerability/vulnerabilities in dependencies

πŸ› Code Security Analysis: 100/100 βœ… Static analysis for common security vulnerabilities in source code

βœ… No issues found

  • No critical security vulnerabilities found
Notion MCP Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 40/100 ❌ Scans package.json, requirements.txt, etc. for known CVEs

❌ 4 critical issues found

  • Found 4 vulnerability/vulnerabilities in dependencies

πŸ› Code Security Analysis: 70/100 βž– Static analysis for common security vulnerabilities in source code

βž– Not applicable

  • ESLint security scanning not available
Nuclei Security Scanner Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 95/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • MCP-scan found no security issues in 2 configuration file(s)

πŸ“¦ Third-Party Dependencies: 100/100 βž– Scans package.json, requirements.txt, etc. for known CVEs

βž– Not applicable

  • No recognized dependency files found

πŸ› Code Security Analysis: 70/100 βž– Static analysis for common security vulnerabilities in source code

βž– Not applicable

  • ESLint security scanning not available
PostgreSQL MCP Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 100/100 βž– Scans package.json, requirements.txt, etc. for known CVEs

βž– Not applicable

  • No recognized dependency files found

πŸ› Code Security Analysis: 50/100 ❌ Static analysis for common security vulnerabilities in source code

❌ 9 critical issues found

  • Found 9 critical security issue(s)
Sequential Thinking Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 60/100 ⚠️ Scans package.json, requirements.txt, etc. for known CVEs

⚠️ 4 potential issues found

  • Found 4 vulnerability/vulnerabilities in dependencies

πŸ› Code Security Analysis: 100/100 βœ… Static analysis for common security vulnerabilities in source code

βœ… No issues found

  • No critical security vulnerabilities found
Slack MCP Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 50/100 βž– Scans package.json, requirements.txt, etc. for known CVEs

βž– Not applicable

  • Go dependency scanning not yet implemented

πŸ› Code Security Analysis: 70/100 βž– Static analysis for common security vulnerabilities in source code

βž– Not applicable

  • ESLint security scanning not available
Stripe MCP Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 100/100 βž– Scans package.json, requirements.txt, etc. for known CVEs

βž– Not applicable

  • No recognized dependency files found

πŸ› Code Security Analysis: 85/100 ⚠️ Static analysis for common security vulnerabilities in source code

⚠️ 1 potential issues found

  • Found 1 critical security issue(s)
Time Server Security Assessment

Security Assessment: 2025-07-28

πŸ” MCP-Specific Security: 90/100 βœ… Scans for MCP-specific threats like tool poisoning attacks

βœ… No issues found

  • No tool poisoning indicators found (basic check)

πŸ“¦ Third-Party Dependencies: 60/100 ⚠️ Scans package.json, requirements.txt, etc. for known CVEs

⚠️ 4 potential issues found

  • Found 4 vulnerability/vulnerabilities in dependencies

πŸ› Code Security Analysis: 100/100 βœ… Static analysis for common security vulnerabilities in source code

βœ… No issues found

  • No critical security vulnerabilities found

About

A curated list of Model Context Protocol (MCP) servers with comprehensive security validation using the mcp-scan security assessment pipeline

Resources

License

Code of conduct

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 3

  •  
  •  
  •