Server data from the Official MCP Registry
Zero-key security toolkit: grade sites A+ to F, check CVE exploits, plain-English attack defenses
About
Zero-key security toolkit: grade sites A+ to F, check CVE exploits, plain-English attack defenses
Security Report
security-mcp is a well-designed defensive security tool with no authentication requirements (appropriate for its purpose) and no malicious patterns. The code is clean, input validation is thorough, and permissions align with the server's stated purpose of auditing websites, checking CVEs, and explaining attack techniques. Minor code quality issues around error handling and DNS fallback robustness do not impact security significantly. Supply chain analysis found 9 known vulnerabilities in dependencies (1 critical, 3 high severity). Package verification found 1 issue.
4 files analyzed · 14 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-pratham-jain33-security-mcp": {
"args": [
"security-mcp"
],
"command": "uvx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
security-mcp
mcp-name: io.github.pratham-jain33/security-mcp
The zero-key cybersecurity toolkit for your AI assistant. No API keys, no signups, no configuration. Install it, ask Claude a security question, get an answer.
Three tools:
- audit_site — grade any website's security from A+ to F. Checks HTTP security headers (HSTS, CSP, X-Frame-Options and more), the SSL/TLS certificate (valid, issuer, days until expiry), and DNS email-auth records (SPF, DMARC, DKIM). Every finding comes with a plain-English explanation.
- check_cve — is this vulnerability actively exploited right now, and how likely is it to be exploited soon? Reads CISA's Known Exploited Vulnerabilities catalog and the FIRST EPSS score. Both are free public feeds.
- lookup_attack — MITRE ATT&CK techniques in plain English. Give a technique ID like
T1566or a keyword likephishing; get what it is, how attackers use it, how to spot it, and how to defend. The technique data ships with the package, so this works fully offline.
Defensive only. This server audits and explains; it does not scan ports, exploit anything, or do anything offensive.
Install
Requires Python 3.10+.
uvx security-mcp
Or with pip:
pip install security-mcp
Claude Desktop config:
{
"mcpServers": {
"shield": {
"command": "uvx",
"args": ["security-mcp"]
}
}
}
Try it
- "Audit the security of example.com"
- "Is CVE-2021-44228 being exploited right now?"
- "What is T1566 and how do I defend against it?"
How it works
audit_site fetches the site's homepage over HTTPS and reads its response headers, opens a TLS connection to inspect the certificate dates and issuer, and looks up SPF/DMARC/DKIM records over DNS (falling back to DNS-over-HTTPS where direct DNS is blocked). Each check carries a penalty; the penalties add up to a score, and the score maps to a grade. A failed certificate check fails the whole audit.
check_cve validates the CVE ID format, then asks two free public sources: the CISA KEV catalog (a JSON feed of vulnerabilities confirmed to be exploited in the wild, cached in memory for an hour) and the FIRST EPSS API (a 0–100% probability of exploitation in the next 30 days). The verdict combines both.
lookup_attack searches a compact bundle of the public MITRE ATT&CK catalog (697 techniques, trimmed from MITRE's CTI feed and shipped inside the package). ID lookups are exact; keyword searches rank name matches above description matches.
Development
python -m venv .venv
.venv/bin/pip install -e . pytest
.venv/bin/python -m pytest tests/ -q # unit tests (mocked network)
SHIELD_LIVE=1 .venv/bin/python -m pytest tests/ -q -k live # real network smoke tests
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Security MCP Servers
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
by Lharries · Communication
Read, search, and send WhatsApp messages through your AI assistant
