Security MCP Servers
5 security MCP servers are cataloged, 0 with verified current-spec support.
MCP servers for security work: vulnerability scanning, network and traffic analysis, secrets and identity tooling, and security research utilities.
- Auth0 MCP Server
- Earlier Revision
Distributed as npm:@auth0/auth0-mcp-server. Resolved from the published package: @auth0/auth0-mcp-server 0.1.0-beta.19 depends on @modelcontextprotocol/sdk@1.30.0, whose artifact implements 2025-11-25. This records what the artifact implements, not what a deployment negotiates.
- Decionis MCP
- Spec Support Unverified
Decionis' own MCP server, distributed as npm:@decionis/mcp and documented on decionis.com/docs/protocol-mcp as "a local stdio MCP server that lets Claude Code, Codex, Cursor, and any MCP client... asks permission before it executes," which grounds first-party authority on a domain-verified vendor surface. The registry record's repository field cites https://github.com/decionis/agent-safe-pipeline, a real and active Decionis repository that does not contain this server's code anywhere in its tree; the repository that actually documents @decionis/mcp is a separate one, https://github.com/decionis/mcp, whose own README states the published npm package's source of truth lives in a private Decionis platform monorepo and that this public repo exists only to host setup guides, samples, and issue reports. repo_url below points at the latter, since it is where the server is actually documented. Probed 2026-09-15: a POST server/discover at protocol revision 2026-07-28 and a legacy POST initialize at 2025-11-25 against the documented remote endpoint both returned HTTP 401 with WWW-Authenticate: Bearer resource_metadata pointing at the endpoint's own oauth-protected-resource document, error invalid_token, and a JSON-RPC {-32001, "Unauthorized MCP request"} body. A separate plain GET against the same endpoint, sent without a JSON-RPC body, returned a self-descriptive JSON document advertising supported_protocol_versions up through 2025-11-25 at https://protocol.decionis.com/mcp; that document is advertised metadata, not a negotiated session, so spec_status stays unknown.
- jshookmcp
- Earlier Revision
Distributed as npm:@jshookmcp/jshook. Resolved from the published package: @jshookmcp/jshook 0.3.5 depends on @modelcontextprotocol/sdk@1.30.0, whose artifact implements 2025-11-25. This records what the artifact implements, not what a deployment negotiates.
- Snyk MCP Server
- Earlier Revision
Snyk's MCP server ships inside the Snyk CLI and runs via the snyk mcp command, exposing Snyk security scans (open source, code, IaC, container, SBOM, secrets) to agentic tools. Checked 2026-08-25: the studio-mcp repository ships MCP specification conformance tests stating they "verify compliance with the Model Context Protocol specification" for versions 2025-11-25 and 2025-06-18 (internal/mcp/mcp_spec_conformance_test.go). The server is a Go binary inside the Snyk CLI, invoked as snyk mcp and built on mark3labs/mcp-go v0.31.0; the npm snyk package itself declares no MCP SDK dependency.
- WebCrypt MCP Server
- Earlier Revision
A self-contained cryptography toolkit and MCP server offering AES-256-GCM, RSA-4096, ECDH, ECDSA/HMAC and post-quantum Kyber/Dilithium operations, all executed locally through the native Web Crypto API with zero runtime dependencies. It is distributed as the npm package webcrypt, invoked over stdio via npx, and documents no MCP-level authentication since every operation runs in-process with no network calls. The server implements its own hand-rolled JSON-RPC 2.0 stdio framing rather than wrapping an SDK. Its own docs/ARCHITECTURE.md states that WebCrypt "introduces a zero-dependency Model Context Protocol (MCP) stdio server conforming to JSON-RPC 2.0 and specification 2024-11-05," a vendor-authored statement naming an early spec revision, so spec_status is legacy with latest_spec 2024-11-05, several revisions behind the current 2026-07-28.