PluginBench

MCP Servers

Model Context Protocol servers that give AI agents access to tools and data — sourced from the official MCP registry and ranked by GitHub stars.

37,330 MCP servers
LOloci logo

loci

Active

Scoped memory for coding agents: picks the right project, answers in scope, or abstains.

1
Python
MIT
View repository →
SESession Forge logo

Session Forge

Maintained

Persistent memory and session intelligence for AI coding assistants. Zero config.

1
TypeScript
MIT
View repository →

Scans Agent2Agent (A2A) protocol code for webhook SSRF, missing auth, and credential exposure

1
TypeScript
View repository →

Finds transitive excessive agency across LangGraph/CrewAI/AutoGen orchestration graphs

1
TypeScript
View repository →

Scans code for insecure LLM/AI integration: exposed keys, unsafe output, prompt injection

1
TypeScript
View repository →

KVKK/GDPR/CCPA compliance checks for codebases

1
TypeScript
View repository →

KVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log

1
TypeScript
View repository →

CVE scanning for npm/pip/cargo dependencies via OSV

1
TypeScript
View repository →

DNS record enumeration, misconfiguration and dangling-subdomain detection

1
TypeScript
View repository →

Active jailbreak/extraction/obfuscation red-teaming for live LLM endpoints

1
TypeScript
View repository →

Scans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats

1
TypeScript
View repository →

Scans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets

1
TypeScript
View repository →

Scans agent code for untrusted input poisoning persistent cross-session memory

1
TypeScript
View repository →

Scans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks

1
TypeScript
View repository →

Scans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience

1
TypeScript
View repository →

Scans RAG content/scraped pages for indirect prompt injection

1
TypeScript
View repository →

Catches leaked credentials and PII in outbound LLM prompts

1
TypeScript
View repository →

Baselines an MCP server's tools and detects tool-definition changes after approval

1
TypeScript
View repository →

Scans files for leaked secrets and API keys

1
TypeScript
View repository →

Security proxy between an MCP client and server: prompt injection and drift detection

1
TypeScript
View repository →

Bundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence

1
TypeScript
View repository →

Checks declared npm/PyPI dependencies against real registries to catch slopsquatting

1
TypeScript
View repository →

TLS certificate/cipher/protocol inspection

1
TypeScript
View repository →

Scans MCP tool definitions for hidden instructions and confused-deputy sinks

1
TypeScript
View repository →

Scans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6)

1
TypeScript
View repository →

Probes vector-database endpoints for unauthenticated exposure of embeddings/RAG data

1
TypeScript
View repository →

Triggers GuardBee scans, queries findings, AI-assisted remediation guidance

1
TypeScript
View repository →

Norwegian public data: companies, statistics, exchange rates, addresses, property. Zero API keys.

1
Python
MIT
View repository →

MCP server for the Geomelon geographic API — stdio and remote HTTP transports

1
TypeScript
View repository →

MCP server for the Geomelon geographic API — stdio and remote HTTP transports

1
TypeScript
View repository →