Best Sec AI Skills & MCP Servers
214 curated Sec skills and MCP servers — install any of them into Claude, Cursor, ChatGPT, n8n, or any AI stack with one command.
Guardvibe
Security MCP for vibe coding. 424 rules, 36 tools, CLI + doctor. Host security, auth coverage mapping, LLM-powered deep scan (IDOR/business logic), taint analysis. 61 CVE rules refreshed daily from GHSA/OSV/CISA KEV — Next.js May 2026 13-advisory cluster,
Freeweb
Secure MCP server for web browsing with multi-layer fetcher chain - no API keys required
Mcp
MCP server for the 1claw secrets vault — lets AI agents fetch, store, and manage secrets at runtime
Oauth
Multi-account orchestration and secure token storage for OAuth-based MCP servers
Codeslick Cli
CodeSlick CLI tool for pre-commit security scanning — 308 checks across JS, TS, Python, Java, Go
Bufab
MCP server that exposes Bufab's design system (UI guidelines, tokens, section specs), infrastructure rules, and Azure Bicep validation. Includes a UI guideline validator usable via `bufab-mcp validate <file>`.
Cutline Cli
CLI and MCP servers for Cutline, including SlopBurn: a product quality engineering roguelike RPG for vibecoding workflows.
Mcp
Model Context Protocol (MCP) server for the A2A (Agent2Agent) protocol compliance test kit. Lets Claude Desktop, Cursor, Codex, and other MCP clients invoke run_compliance / validate_agent_card / list_checks / explain_check / ssrf_check_url as native tool
Ainative Zerodb
AINative ZeroDB MCP Server - 77 operations for vector search, quantum compression, NoSQL, dedicated PostgreSQL management, files, events, RLHF, and persistent memory for AI agents with enterprise security. All tools annotated with readOnly/destructive/ide
Ftp
Enterprise-grade MCP server providing heavily optimized FTP/SFTP operations with smart sync, patch/chunk streaming, caching, and explicit read-only security mappings for AI code assistants.
Secure Vault
MCP server for agent-native secrets management — store, rotate, and inject secrets without agents seeing raw values
Cleaner Code
Scans AI-generated code for invisible Unicode, Trojan Source, and supply-chain threats.
Fmr8
MCP server for Section 8 Fair Market Rent (FMR) lookups — ZIP code search, state/county browsing, historical trends, and HUD glossary
Enquire
MCP server giving AI agents (Claude Code, Claude Desktop, Cursor, ChatGPT, Codex, OpenClaw) persistent long-term memory backed by your local Obsidian markdown vault. Hybrid retrieval (BM25 + ML embeddings + BGE reranker, RRF-fused), HNSW + int8 quantizati
Server
VettIQ MCP server — security scanning for AI-generated code, callable from Cursor, Claude Code, and any MCP-compatible agent.
Agent Security
MCP server providing security scanning, prompt injection detection, secret leak detection, and agent permission auditing for AI agent workflows
Openinsider
MCP server that exposes openinsider.com to any MCP compatible client.
Cinema4D
TypeScript MCP server for Cinema 4D with generic entity CRUD, parameter-level access, undo-grouped batch ops, and security controls.
Git
A secure and scalable Git MCP server enabling AI agents to perform comprehensive Git version control operations via STDIO and Streamable HTTP.
Ironward
Security scanning for the vibe coding era. MCP server + CLI that finds secrets, auth bugs, SQL injection, XSS, IDOR, and vulnerable deps — and opens fix PRs. Works in Cursor, Claude Code, and VS Code. Bring your own model (Anthropic, OpenAI, Gemini, Groq,
Proxy
Standalone MCP proxy that wraps any MCP server with Clampd's 9-stage security pipeline
Server
Security, cost, and health governance proxy for MCP infrastructure — three-layer detection engine (regex + schema + LLM), monorepo, corpus, CI/CD
Mcp
⚠️ Pre-release — wait for 1.0.0 before relying on this. Currently under active development; APIs and behaviour may change without notice. SPYS MCP client — local stdio bridge + reverse tunnel for AI-driven pentest tools (Claude Code, Cursor, etc).
Mcp
MCP server for SwarmApi: 9 pay-per-call tools for SEC filings, company news, insider transactions, jobs, web search, GitHub repos, and npm/PyPI/cargo package security. Payments settled per request in USDC on Base via x402.
About Sec skills on iClaude
iClaude is the universal install layer for AI skills. Every Sec skill on this page can be installed into Claude Code, Claude Desktop, Cursor, ChatGPT, n8n, Codex, and more — using a single copy-paste command. No config drift, no per-stack adapters, no manual MCP wiring.