No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by FuzzingLabs · MCP Server · ★ 758
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcp-security-hub safe to install? View the security audit →
Offensive Security MCP Servers Production-ready, Dockerized MCP (Model Context Protocol) servers for offensive security tools. Enable AI assistants like Claude to perform security assessments, vulnerability scanning, and binary analysis. Features 38 MCP Servers covering reconnaissance, web security, binary analysis, blockchain security, cloud security, code security, secrets detection, threat intelligence, OSINT, Active Directory, fuzzing, and more 300+ Security Tools accessible via natural language through Claude or other MCP clients Production Hardened - Non-root containers, minimal images, Trivy-scanned
| Stars | 758 |
| Forks | 95 |
| Language | Python |
| Category | MCP Server |
| License | MIT |
| Quality Score | 77.2157687672206/100 |
| Open Issues | 6 |
| Last Updated | 2026-04-08 |
| Created | 2026-01-06 |
| Platforms | claude-code, docker, mcp, python |
| Est. Tokens | ~22k |
These tools work well together with mcp-security-hub for enhanced workflows:
Looking for a mcp-security-hub alternative? If you're comparing mcp-security-hub with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
MCP server that connects AI assistants to HackerOne for bug bounty hunting
Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability
⚡ Blitz Strike — a universal MCP penetration-testing toolbelt. Structured methodology: reconnaissance & attack
120-tool MCP server for real-time global intelligence: markets, SEC filings, conflict, military, cyber, climat
Explore other popular mcp server tools:
mcp-security-hub is A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.. It is categorized as a MCP Server with 758 GitHub stars.
mcp-security-hub is primarily written in Python. It covers topics such as ai, claude, cybersecurity.
You can find installation instructions and usage details in the mcp-security-hub GitHub repository at github.com/FuzzingLabs/mcp-security-hub. The project has 758 stars and 95 forks, indicating an active community.
mcp-security-hub is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to mcp-security-hub on Agent Skills Hub include pentest-ai, CyberStrike, h1-brain. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: