No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by Puliczek · MCP Server · ★ 726
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is awesome-mcp-security safe to install? View the security audit →
🤝 Show your support - give a ⭐️ if you liked the content Awesome MCP Security Everything you need to know about Model Context Protocol (MCP) security. Table of Contents Awesome MCP Security 📔 Security Considerations 📃 Papers 📺 Videos 📕 Articles, X threads and Blog Posts 🧑🚀 Tools and code 💾 MCP Security Servers 💻 Other Useful Resources 📔 Security Considerations Official Security Considerations from the Official MCP Specification Rev: 2025-03-26 [!NOTE] 15.04.2025: The current MCP auth specification is in progress of being replaced by a more robust specification. Please join the conversation if you have concerns around the current auth specification. Servers MUST: Validate all tool inputs Implement proper access controls Rate limit tool invocations Sanitize tool outputs Clients SHOULD: Prompt for user confirmation on sensitive operations Show tool inputs to the user before ca
| Stars | 726 |
| Forks | 194 |
| Category | MCP Server |
| Quality Score | 51.3169014280933/100 |
| Open Issues | 161 |
| Last Updated | 2026-03-03 |
| Created | 2025-04-08 |
| Platforms | cli, mcp |
| Est. Tokens | ~10k |
Looking for a awesome-mcp-security alternative? If you're comparing awesome-mcp-security with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Plugin for JADX to integrate MCP server
MCP Router — development, support and security updates ended 2026-09-18. Historical source and final release f
An MCP client for Neovim that seamlessly integrates MCP servers into your editing workflow with an intuitive i
A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains.
Connect Cursor, Copilot & Claude AI directly to Cheat Engine via MCP. Automate reverse engineering, pointer sc
MCP configuration to connect AI agent to a Linux machine.
Explore other popular mcp server tools:
awesome-mcp-security is 🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️. It is categorized as a MCP Server with 726 GitHub stars.
You can find installation instructions and usage details in the awesome-mcp-security GitHub repository at github.com/Puliczek/awesome-mcp-security. The project has 726 stars and 194 forks, indicating an active community.
The top alternatives to awesome-mcp-security on Agent Skills Hub include jadx-ai-mcp, mcp-router, mcphub.nvim. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: