Best Sec AI Skills & MCP Servers
214 curated Sec skills and MCP servers — install any of them into Claude, Cursor, ChatGPT, n8n, or any AI stack with one command.
Serpentstack
Find any AI agent skill or MCP server. Search every registry, install in seconds.
Server
MCP server exposing cellar-door EXIT and ENTRY verifiable markers as AI-native tools
Testforge
TestForge MCP Server — AI-powered testing in your IDE. Analyzes code for security, unit tests, load, accessibility, vision alignment, scope coverage, and stack quality.
Nsauditor Ai Agent Skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows.
Controlkeel
Bootstrap installer for the ControlKeel native CLI - a control plane for agent-generated software delivery.
Financial Hub
MCP server for financial data — SEC EDGAR filings, XBRL financials, FRED economic indicators, and Finnhub market data.
Budget Aware
Model-agnostic code memory MCP server. Budget-aware graph retrieval for AI agents — sub-millisecond queries, token budgeting, no embeddings, no API keys. Built on CodeGraphContext for 155-language tree-sitter indexing.
Server
MCP server for Doppler API with auto-generated tools from OpenAPI specification
Eslint Plugin Secure Coding
Security-focused ESLint plugin with 89 AI-parseable rules for detecting and preventing vulnerabilities. OWASP Top 10 2021 + Mobile Top 10 2024 coverage, CWE references, and AI-assisted fix guidance.
Sanitizer
Comprehensive security sanitization library for Model Context Protocol (MCP) servers with trusted security libraries
Google Workspace
Google Workspace MCP Server - Model Context Protocol server providing secure access to Google Drive, Docs, Sheets, Slides, Calendar, and Gmail through MCP clients e.g. Claude Desktop
Jshook
MCP server with built-in tools across multiple domains for AI-assisted JavaScript analysis and security analysis — browser automation, CDP debugging, network monitoring, JS hooks, code analysis, and workflow orchestration
Brick Review
Structured code review — analyze code quality, security, architecture patterns, compare versions.
Depwire Cli
Dependency graph + 23 MCP tools for AI coding assistants. Impact analysis, health scoring, security scanner, agent coordination.
Excalidraw
Security-hardened MCP server for Excalidraw with API key auth, rate limiting, and real-time canvas sync
Brick Fullaudit
Full project audit workflow — code quality review, security scan, architecture analysis, and metrics report.
Server Scf
MCP server for the SCF Controls Platform — security compliance controls, frameworks, evidence, and risk management for AI agents
Fast Mermaid Validator
High-performance API and Model Context Protocol (MCP) server for validating Mermaid diagrams with comprehensive security features, multiple transport options, and enterprise-grade capabilities
Edgar
MCP server for SEC EDGAR — search filings, extract sections, financials, insider transactions. No API key required.
Lighthouse
A comprehensive Model Context Protocol (MCP) server that provides web performance auditing, accessibility testing, SEO analysis, security assessment, and Core Web Vitals monitoring using Google Lighthouse. Enables LLMs and AI agents to perform detailed we
Eslint Plugin Node Security
Security-focused ESLint plugin for Node.js built-in modules (fs, child_process, vm, path, Buffer). Detects command injection, path traversal, code execution vulnerabilities with AI-parseable error messages.
Obsidian Second Brain
MCP server for Obsidian-based second brain memory using PARA methodology
Signal
MCP server for VC Deal Flow Signal — search startup engineering acceleration data across 20 sectors. Commit velocity, contributor growth, and repo expansion signals for seed/Series A investors.
Veil
A TypeScript library for selective context access, visibility control & safety enforcement for LLMs
About Sec skills on iClaude
iClaude is the universal install layer for AI skills. Every Sec skill on this page can be installed into Claude Code, Claude Desktop, Cursor, ChatGPT, n8n, Codex, and more — using a single copy-paste command. No config drift, no per-stack adapters, no manual MCP wiring.