Task · Coding
Best AI agents to scan code for vulnerabilities
This task needs 2 capabilities. 19 tools cover all of them; 916 cover at least one.
| # | Tool | Coverage | Access | Trust | Seen |
|---|---|---|---|---|---|
| 151 | SimplyScanMCP Security, SEO and AI-visibility scanner for web apps · free scans and focused checks via MCP. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 152 | RTK Motion — Motion Capture, Biomechanics, Threat & Fleet IntelligenceMCP Mocap, rehab biomechanics, threat intel, fleet vision. 21 MCP tools, 10 free. x402/USDC paid. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 153 | MCP MarketplaceMCP Search and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 154 | mytesla.ioMCP Control your Tesla from your AI assistant - climate, charging, access, and security. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 155 | token-riskMCP DeFi pool yield+security intelligence & token/contract risk scanner. USDC on Base via x402. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 156 | KernelScanMCP Linux kernel CVE analyzer: upload a .config, get a CycloneDX VEX report of affecting CVEs. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 157 | mcpMCP Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 158 | heronMCP Signed security scores for what an AI agent runs and reads: skills, MCP servers, prompts, tokens. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 159 | SPARDAMCP AI writes. SPARDA proves. Deterministic, offline security gate for AI edits. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 160 | Azure DevOps On-PremisesMCP MCP server for on-premises Azure DevOps Server and TFS: repos, pull requests, work items, and wiki. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 161 | VMware NSX SecurityMCP VMware NSX security: DFW policies and exclusions, groups, tags, Traceflow, IDPS — 22 MCP tools. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 162 | PkgSeek Linux IntelligenceMCP Linux package, file, command, vulnerability, lifecycle, migration, and repository intelligence. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 163 | tablecloth-mcpMCP Open Korean e-Gov and finance sites in a clean, disposable Windows Sandbox with security programs. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 164 | webcheckMCP Website health analysis: SEO, accessibility, performance, security, and broken links | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 165 | lavelaMCP Launch and operate a SaaS from one conversation — domain, hosting, email, Stripe, ads, security. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 166 | SaaS AlertsMCP MCP server for Kaseya SaaS Alerts — SaaS security monitoring for M365 & Google Workspace. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 167 | Abnormal SecurityMCP MCP server for Abnormal Security — AI-powered email threat detection, cases, and remediation. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 168 | AvananMCP MCP server for Check Point Harmony Email & Collaboration (Avanan) email security. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 169 | ProofpointMCP MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 170 | SpamTitanMCP MCP server for SpamTitan email security — quarantine, allow/block lists, and policy management. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 171 | MimecastMCP MCP server for Mimecast email security: message queue, held messages, domains, and threats. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 172 | KnowBe4MCP MCP server for KnowBe4 security awareness training — users, groups, training, phishing campaigns. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 173 | nockchain-mcpMCP Moved to io.github.winter0x/nockchain-mcp. This entry is no longer updated. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 174 | suprawall-mcpMCP SupraWall security gateway for AI agents. Provides deterministic guardrails for MCP agents. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 175 | mne-docsMCP MCP server for MNE-Python documentation, source code, GitHub issues, and forum | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 176 | bounty-mcpMCP Live coding-bounty deal-flow from verified-escrow GitHub bounties for AI agents. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 177 | agent-toolkitMCP Pay-per-call developer utilities and npm supply-chain security tools for coding agents, over x402. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 178 | MCP Gateway ScanMCP Read-only MCP/agent-gateway readiness scanner — scores a repo across 7 security dimensions. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 179 | cve-cacheMCP Recent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go). | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 180 | shodanMCP MCP server for Shodan API — device search, IP lookup, DNS, and CVE/CPE queries. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 181 | cynicalsallyMCP Brutally honest code reviews: scores, real issues, and usable fixes. CLI + MCP server. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 182 | mcp-server-security-scannerMCP Scan MCP configs for 30+ CVEs, prompt injection, tool poisoning; validate OAuth configs | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 183 | VulnCheckMCP VulnCheck exploit intelligence — CVE research, exploit data, advisories, and threat analysis. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 184 | mcp-gitlabMCP MCP server for GitLab API — projects, MRs, pipelines, CI/CD, approvals, issues, code review. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 185 | Motiv FleetMCP DeFi MCP fleet: oracle, security audit, treasury yield, QA attestation, and compute tools on Base. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 186 | secretguard-mcpMCP Scans code for hardcoded secrets (AWS, Stripe, GitHub, JWTs) before an AI agent commits it. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 187 | jshookmcpMCP MCP server for JavaScript analysis, security auditing, browser automation and hooks | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 188 | visus-mcpMCP Security-first web access for Claude. Sanitizes pages, blocks injection, redacts PII. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 189 | nslookupMCP DNS lookups, health reports, SSL certs, security scans, GEO scoring, uptime checks | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 190 | Vizier GuardMCP Deterministic authorization and security guard for AI agent actions with signed receipts. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 191 | AegisMCP Charter-bound defensive security copilot: secrets, obfuscation, deps, Dockerfile, IaC scans. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 192 | siteaudit-mcpMCP SEO, performance, and security audits for any URL — no API keys required | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 193 | FlowSentryMCP Security scanner for n8n workflows + live MCP Trust-Check. 18 rules, OWASP mapped. Paid x402 API. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 194 | release-notes-mcpMCP A small, generic MCP server for combining GitHub/GitLab/Gitea releases into product release notes | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 195 | MCP-BastionMCP Security middleware for MCP. Blocks prompt injection, PII leakage, and resource exhaustion. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 196 | ctxMCP Turn a GitHub repo or docs site into agent-ready context: pack it or search it, over MCP. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 197 | cursor-chat-bridgeMCP Drive the Cursor agent from Telegram, Discord, or GitHub — with images and voice notes. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 198 | PitchPilot Agent Tools (legacy name - see sigtap)MCP Legacy name of io.github.unnamedaiagent/sigtap-agent-tools. Endpoints moved; see sigtap listing. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 199 | ActionsPulseMCP Real-time GitHub Actions observability: DORA Metrics, Cost Analysis, CI/CD Health dashboards. | 50% | REMOTELOCAL | DECLARED | 5d ago |
| 200 | TrusteedMCP CTEM for your Trusteed tenant: security summary, findings, compliance gaps, and scans via OAuth. | 50% | REMOTELOCAL | DECLARED | 5d ago |
Coverage = share of this task's required capabilities that an agent or tool documents. For AI agents, capabilities are those stated on the vendor's website; for tools, they are matched automatically from the publisher's description (keyword method, low confidence).