Best Sec AI Skills & MCP Servers
214 curated Sec skills and MCP servers — install any of them into Claude, Cursor, ChatGPT, n8n, or any AI stack with one command.
Bufab
MCP server that exposes Bufab's design system (UI guidelines, tokens, section specs), infrastructure rules, and Azure Bicep validation. Includes a UI guideline validator usable via `bufab-mcp validate <file>`.
Mcp
MCP server for the 1claw secrets vault — lets AI agents fetch, store, and manage secrets at runtime
Guardvibe
Security MCP for vibe coding. 424 rules, 36 tools, CLI + doctor. Host security, auth coverage mapping, LLM-powered deep scan (IDOR/business logic), taint analysis. 61 CVE rules refreshed daily from GHSA/OSV/CISA KEV — Next.js May 2026 13-advisory cluster,
Freeweb
Secure MCP server for web browsing with multi-layer fetcher chain - no API keys required
Mcp
MCP server for SwarmApi: 9 pay-per-call tools for SEC filings, company news, insider transactions, jobs, web search, GitHub repos, and npm/PyPI/cargo package security. Payments settled per request in USDC on Base via x402.
Judges
45 specialized judges that evaluate AI-generated code for security, cost, and quality.
Publicfinance
Public finance MCP server — SEC EDGAR filings, US Treasury rates, BLS labor statistics, and economic indicators. Zero API keys required.
Secedgar
Query SEC EDGAR filings, XBRL financials, and company data through MCP. STDIO & Streamable HTTP.
Server Sec Filings
SEC EDGAR financial intelligence with XBRL data, filing search, and insider trades for 8000+ companies
Stock Scanner
MCP server providing Claude Code with real-time stock and crypto market data, SEC filings, insider trades, and technical analysis
Code Impact
Lightweight pre-commit safety gate for AI agents. Answers 'is this change safe?' with PASS/WARN/BLOCK verdict in seconds. Zero setup, no database.
Openinsider
MCP server that exposes openinsider.com to any MCP compatible client.
Knit
Knit — second brain for any MCP-speaking AI coding agent (Claude Code, Cursor, Codex CLI, Cline, Continue, GitHub Copilot). Per-project memory, tier-routed workflow protocol, parallel team worktrees.
Edgar
EDGAR MCP — SEC EDGAR public APIs (free, no auth)
Git
A secure and scalable Git MCP server enabling AI agents to perform comprehensive Git version control operations via STDIO and Streamable HTTP.
Cutline Cli Staging
CLI and MCP servers for Cutline, including SlopBurn: a product quality engineering roguelike RPG for vibecoding workflows.
Infrawise
CLI-first infrastructure intelligence platform — analyzes DynamoDB, PostgreSQL, MySQL, MongoDB, SQS, SNS, SSM, Secrets Manager, Lambda, CloudWatch Logs and exposes findings as an MCP server for Claude Code
Audit Cli
Lightweight dependency vulnerability audit tool with CLI and MCP Server support
Axiom Data
Financial & research data MCP server — SEC filings, DeFi analytics, wallet profiling, academic papers, US macro data, patent search, token sentiment. 30 tools for AI agents.
Kastell
CLI toolkit for provisioning, securing, and managing self-hosted servers
Server Sec
MCP server for Claude Desktop: search SEC filing sections, financial statements, insider trades, institutional ownership, earnings actuals, XBRL metrics, and company lookup.
Agent Security Scanner
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1700+ vulnerability rules with AST & taint analysis, LLM-powered semantic code review, auto-fix. For Claude Code, Cursor, Windsu
Autoremediator
Agentic CVE remediation platform for Node.js. Correlates threat intelligence, applies policy-governed fixes, and delivers auditable remediation outcomes across CI/CD pipelines, agent workflows, and service portfolios.
Excalidraw Sentinel
Hardened, self-hosted Excalidraw MCP server with SQLite persistence, multi-tenancy, auto-sync, security middleware, and 369 tests
About Sec skills on iClaude
iClaude is the universal install layer for AI skills. Every Sec skill on this page can be installed into Claude Code, Claude Desktop, Cursor, ChatGPT, n8n, Codex, and more — using a single copy-paste command. No config drift, no per-stack adapters, no manual MCP wiring.