Awesome MCPSecurity & Reverse Engineering

cyproxio/mcp-for-security

⭐ 630 TypeScript added to this list on 2025-05-14 repository created 2025-04-03

MCP for Security is an open-source project that provides a collection of Model Context Protocol (MCP) servers integrating popular security and penetration testing tools into AI workflows through a standardized interface. The project is developed by Cyprox, a company focused on pioneering AI-driven cybersecurity solutions that combine artificial intelligence with traditional security tools to enhance threat detection and automate responses. MCP for Security enables seamless access to a wide range of security tools via MCP servers, facilitating their use in AI-driven security automation and orchestration. The repository includes MCP server implementations for numerous well-known security tools such as Amass for subdomain enumeration, Arjun for discovering hidden HTTP parameters, Nmap for network scanning, SQLmap for SQL injection detection, WPScan for WordPress vulnerability scanning, and many others. Each tool is wrapped as an MCP server, allowing standardized interaction and integration into AI workflows. The project supports deployment via Docker, making it easy to run all MCP servers in containerized environments, and also provides a general setup script for manual installation. MCP for Security covers a broad spectrum of security testing capabilities including subdomain discovery, port scanning, vulnerability scanning, web crawling, SSL/TLS analysis, HTTP header security analysis, mobile application security testing, cloud security auditing, and HTTP request smuggling detection. The project aims to reduce human latency in threat detection by automating security tool usage and providing a trustworthy, transparent platform built on open standards. The repository is community-driven and encourages contributions, using TypeScript and the MCP SDK for development. It is designed to foster collaboration and rapid evolution of AI-driven cybersecurity tools. MCP for Security is a comprehensive framework that bridges traditional security tools with modern AI workflows, enabling organizations to enhance their cybersecurity posture through automation and integration.

https://github.com/cyproxio/mcp-for-security

ai-assistantsai-driven-cybersecurityai-integrationai-securityai-workflowsalterxamassarjunautomationcertificate-searchcloud-security-auditingcrt.shcybersecuritycyproxdockerffuffuzzinghacking-toolshttp-headers-securityhttp-request-smugglinghttpxmasscanmcpmcp-aimcp-pentestmcp-securitymobile-securitymobsfmodel-context-protocolnetwork-scanningnmapnucleiopen-sourcepenetration-testingpentestingsecurity-automationsecurity-integrationssecurity-testingsecurity-testing-toolssecurity-toolsshufflednssqlmapssl/tls-analysissslscansubdomain-enumerationthreat-detectiontypescriptvulnerability-discoveryvulnerability-scanningwaybackurlsweb-security

Also in Security & Reverse Engineering

mukul975/Anthropic-Cybersecurity-Skills

A comprehensive open-source library featuring 754 structured cybersecurity skills for AI agents, mapped to five industry frameworks to provide expert-level guidance.

NVIDIA/SkillSpector

NVIDIA security scanner for AI agent skills and MCP tooling that detects prompt injection, data exfiltration, MCP tool poisoning and least-privilege problems, and can itself be run as an MCP server inside agent sessions.

mrexodia/ida-pro-mcp

ida-pro-mcp is an MCP server for IDA Pro that enables advanced reverse engineering capabilities through MCP-based interactions and automation.

LaurieWired/GhidraMCP

GhidraMCP is an MCP server that integrates Ghidra's reverse engineering capabilities with MCP clients, enabling automated binary analysis and decompilation through large language models.

invariantlabs-ai/mcp-scan

MCP-Scan is a security tool that statically and dynamically scans and monitors Model Context Protocol (MCP) connections to detect and prevent vulnerabilities such as prompt injections, tool poisoning, and cross-origin escalations.

zinja-coder/jadx-ai-mcp

JADX-AI-MCP is a JADX plugin integrating Model Context Protocol to enable AI-powered live reverse engineering, vulnerability detection, and code analysis of Android APKs using large language models like Claude.

mariocandela/beelzebub

Beelzebub is a secure low-code honeypot framework leveraging large language models and the Model Context Protocol (MCP) to detect and analyze cyber attacks, including prompt injection attempts against LLM agents.

svnscha/mcp-windbg

mcp-windbg is a Model Context Protocol server that enables AI models to analyze Windows crash dumps using WinDBG through natural language interaction and command execution.