9,081 servers ยท Security
Security servers from the Lulu MCPs index, aggregated from every major registry, trust-ranked, and ready to install.
Integration for AWS Cloud Development Kit (CDK) best practices, infrastructure as code patterns, and security compliance with CDK Nag.
Local knowledge retrieval system that combines semantic search with keyword-based routing for document analysis across security, development, and general knowledge domains using ChromaDB for vector storage and hybrid search through Reciprocal Rank Fusion.
Privacy-first SAST tool for Python, TypeScript, and Go that detects dead code, security vulnerabilities, and code quality issues with hybrid AST and optional LLM analysis.
Provides penetration testing tools for reconnaissance, vulnerability scanning, and exploit assistance.
Execute shell commands with strict security policies.
Secure read-only MySQL database access to execute queries and analyze data patterns.
Provides secure Python code execution in a sandboxed Pyodide environment with automatic dependency installation, stdout/stderr capture, and complete isolation from the host system for data analysis and mathematical computations.
Integrates with Semgrep's static analysis engine to scan code for security vulnerabilities and coding issues, enabling developers to identify and fix potential problems directly within their coding workflow.
Integrates with Cycode's security platform to perform automated SAST, SCA, IaC, and secrets scanning on local files, Git repositories, and commit ranges with detailed vulnerability reports and remediation guidance.
Provides a bridge to Facebook's Marketing API for analyzing ad campaigns, reviewing creatives, and monitoring metrics through secure OAuth authentication
Integrates with npm-audit-report and npm-registry-fetch to analyze and report potential vulnerabilities in Node.js project dependencies, offering actionable security insights for development teams.
Aggregates security detection rules from Sigma, Splunk ESCU, Elastic, and KQL into a unified searchable SQLite database with MITRE ATT&CK mappings and CVE tracking for security analysts and threat hunters.
Provides Android/Kotlin development capabilities through 31+ specialized tools covering code generation, build management, architecture setup, Gradle operations, ktlint formatting, Android Lint analysis, Room database configuration, Retrofit API setup, MVVM scaffolding, Jetpack Compose creation, and security utilities with encryption and compliance support.
Centralizes management of multiple AI services, providing secure API key handling and unified access for streamlined interactions across diverse platforms.
Provides intelligent Solidity smart contract analysis through the Aderyn static analyzer, scanning codebases to identify security vulnerabilities, code quality issues, and potential exploits across multiple severity levels with support for Foundry and Hardhat projects.
Access hosted MCP servers or deploy your own for 2,500+ APIs like Slack, GitHub, Notion, Google Drive, and more, all with built-in auth and 10k tools.
Enables secure terminal command execution, directory navigation, and file system operations across Windows and UNIX-based systems, with built-in security measures to prevent dangerous operations.
Enables control and interaction with Android devices through secure tools for device management, app installation, UI automation, file operations, and system diagnostics.
Enables LLMs to interact with GraphQL APIs through schema introspection and query execution, with security measures like disabled mutations by default.
Lean Gmail server with automatic authentication support.
Provides zero-configuration end-to-end testing for web applications by creating secure tunnels to local development servers and spawning testing agents that interact with web interfaces through natural language descriptions, returning detailed test results with execution recordings and screenshots.
Scans codebases for AI framework usage and checks compliance against EU AI Act requirements with risk classification and remediation guidance.
Integrates with Dynatrace to provide real-time observability data, enabling developers to monitor problems, security vulnerabilities, logs, and metrics directly in their development workflows.
Provides expert prompt engineering capabilities through LM Studio integration, featuring 35+ specialized functions for code analysis, generation, security audits, documentation creation, and creative tasks with intelligent context window management and caching optimization.
Integrates with Panther Labs' cybersecurity platform to enable security alert triage, data lake querying, detection rule management, and log source analysis for incident response and threat hunting workflows.
Secure, self-hostable sandbox for running Python, TypeScript, and Bash code in isolated Docker containers with automatic resource management for local command execution.
Control Windows command-line interfaces securely.
Integrates with Japan's official e-Gov legal database to provide search and retrieval of Japanese laws and regulations for legal research, compliance checking, and regulatory analysis.
Provides random number generation utilities including pseudorandom and cryptographically secure operations for integers, floats, weighted selections, list shuffling, and secure token generation.
Scans projects and files for security vulnerabilities including secrets, injections, and unsafe configurations.
Security-hardened fork with post-quantum encryption, secrets scanning, and enterprise-grade protections
Integrates with PostgreSQL databases to enable schema management, data migration, performance monitoring, and security configuration through direct database operations without requiring separate management tools.
Provision and manage AI-native Postgres databases with REST API, auth, storage, and static site hosting via x402 micropayments.
Execute code securely in cloud sandboxes.
Enables secure execution of LLM-generated scripts and processes in isolated environments with environment variable management for teams needing to run code directly from AI assistants.
Transforms OpenAPI/Swagger specifications into dynamic HTTP tools with secret management and URL restrictions, enabling secure API integration through automatic tool generation from API documentation.
Provides a secure Python execution environment with isolated working directories, enabling code execution, file operations, and package management for development, data analysis, and educational tasks.
AI-powered containerization workflows with Docker builds, security scanning, Kubernetes deployment, and OPA policy enforcement.
Security-hardened file organizer with smart categorization, duplicate detection, and rollback support.
Provides 50+ developer utilities including cryptographic operations, text processing, data format conversion, network calculations, and encoding functions through a containerized TypeScript server with security features and rate limiting.
Integrates with Microsoft Teams through Graph API to search messages, manage chats and channels, send messages, create group chats, and handle user/team operations with device code authentication for secure access.
API governance toolkit with breaking change detection, security audit, persistent task ledger, and multi-model consensus for AI coding assistants.
Exposes database tables and schemas via HTTP endpoints, allowing tools to query database structure without direct database access for security-conscious development.
Integrates with Bitcoin SV blockchain to enable wallet operations, transaction management, and NFT interactions while maintaining local private key security
Provides secure access to Azure Health Data Services FHIR servers, enabling authenticated retrieval and search of healthcare resources across 70+ resource types for medical applications requiring standards-compliant patient data access.
Provides secure access to two-factor authentication codes and passwords stored in the Authenticator App, enabling seamless login assistance across multiple services without manual code entry.
Integrates with EVM-compatible blockchain networks including BSC, Ethereum, Arbitrum, Polygon, Base, and Optimism to enable DeFi operations, security analysis, cross-chain bridging, NFT management, and portfolio tracking.
Analyzes and decompiles Java class files with CFR decompiler integration, Maven repository support, and dependency scanning to enable reverse engineering, security auditing, and understanding of compiled bytecode when source code is unavailable.
Bridges local AI capabilities with governance protocols through secure command execution, file operations, and meta-cognitive reflection tools.
FAQ
9,081 Security MCP servers are indexed on Lulu MCPs, ranked by trust score and aggregated from the official MCP Registry, Glama, PulseMCP and Smithery. Every listing links back to its source registry and installs in one click for Claude Code, Cursor and VS Code.
Lulu MCPs matches each server's name and description against a validated term set for the security category. Servers can appear in more than one category when their functionality spans multiple areas.