Browse MCP servers
MCP Harbor, an MCP Server Registry, Directory, and Tower to Buzz.
27 matching
Showing 1–27 of 27 servers
-
toxic flow auditor
stdioio.github.4hmetuyar/toxic-flow-auditor
Finds lethal-trifecta toxic flows in MCP tool catalogs: untrusted input, sensitive data, egress
official -
prompt leak scanner
stdioio.github.4hmetuyar/prompt-leak-scanner
Catches leaked credentials and PII in outbound LLM prompts
official -
secret scanner
stdioio.github.4hmetuyar/secret-scanner
Scans files for leaked secrets and API keys
official -
prompt injection scanner
stdioio.github.4hmetuyar/prompt-injection-scanner
Scans RAG content/scraped pages for indirect prompt injection
official -
security proxy
stdioio.github.4hmetuyar/security-proxy
MCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log
official -
elicitation auditor
stdioio.github.4hmetuyar/elicitation-auditor
MCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs
official -
dns intelligence
stdioio.github.4hmetuyar/dns-intelligence
DNS record enumeration, misconfiguration and dangling-subdomain detection
official -
compliance checker
stdioio.github.4hmetuyar/compliance-checker
KVKK/GDPR/CCPA compliance checks for codebases
official -
memory poisoning scanner
stdioio.github.4hmetuyar/memory-poisoning-scanner
Scans agent code for untrusted input poisoning persistent cross-session memory
official -
vulnerability scanner
stdioio.github.4hmetuyar/vulnerability-scanner
Triggers GuardBee scans, queries findings, AI-assisted remediation guidance
official -
vector store scanner
stdioio.github.4hmetuyar/vector-store-scanner
Probes vector-database endpoints for unauthenticated exposure of embeddings/RAG data
official -
tool poisoning scanner
stdioio.github.4hmetuyar/tool-poisoning-scanner
Scans MCP tool definitions for hidden instructions and confused-deputy sinks
official -
ssl inspector
stdioio.github.4hmetuyar/ssl-inspector
TLS certificate/cipher/protocol inspection
official -
slopsquat scanner
stdioio.github.4hmetuyar/slopsquat-scanner
Checks declared npm/PyPI dependencies against real registries to catch slopsquatting
official -
security suite
stdioio.github.4hmetuyar/security-suite
Bundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence
official -
rug pull detector
stdioio.github.4hmetuyar/rug-pull-detector
Baselines an MCP server's tools and detects tool-definition changes after approval
official -
oauth auditor
stdioio.github.4hmetuyar/oauth-auditor
Scans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience
official -
model scanner
stdioio.github.4hmetuyar/model-scanner
Scans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks
official -
mcp server auditor
stdioio.github.4hmetuyar/mcp-server-auditor
Scans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets
official -
mcp config auditor
stdioio.github.4hmetuyar/mcp-config-auditor
Scans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats
official -
llm redteam
stdioio.github.4hmetuyar/llm-redteam
Active jailbreak/extraction/obfuscation red-teaming for live LLM endpoints
official -
dependency auditor
stdioio.github.4hmetuyar/dependency-auditor
CVE scanning for npm/pip/cargo dependencies via OSV
official -
db gateway
stdioio.github.4hmetuyar/db-gateway
KVKK/GDPR-compliant LLM-to-database gateway: PII masking, RBAC, rate limiting, audit log
official -
ai code scanner
stdioio.github.4hmetuyar/ai-code-scanner
Scans code for insecure LLM/AI integration: exposed keys, unsafe output, prompt injection
official -
agent graph auditor
stdioio.github.4hmetuyar/agent-graph-auditor
Finds transitive excessive agency across LangGraph/CrewAI/AutoGen orchestration graphs
official -
a2a auditor
stdioio.github.4hmetuyar/a2a-auditor
Scans Agent2Agent (A2A) protocol code for webhook SSRF, missing auth, and credential exposure
official -
unbounded consumption auditor
stdioio.github.4hmetuyar/unbounded-consumption-auditor
Scans LLM/agent code for Unbounded Consumption / denial-of-wallet risks (OWASP LLM Top 10 2026 #6)
official
Search this catalogue from your agent
The registry is itself an MCP server. Add it once and your agent runs these same searches, with no account and no key.
claude mcp add --transport http mcp-registry-search https://ai.mcpharbor.dev/mcp