mcp-security — security grade SAFE, quality 63/100

Security audit verdict: SAFE · quality 63/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by google · MCP Server · ★ 525

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is mcp-security safe to install? View the security audit →

About mcp-security

Google Security Operations and Threat Intelligence MCP Server This repository contains Model Context Protocol (MCP) servers that enable MCP clients (like Claude Desktop or the cline.bot VS Code extension) to access Google's security products and services: Remote MCP Server for Google SecOps - Fully managed, enterprise-ready MCP server (Recommended) Google Security Operations (Chronicle) - For threat detection, investigation, and hunting Google Security Operations SOAR - For security orchestration, automation, and response Google Threat Intelligence (GTI) - For access to Google's threat intelligence data Security Command Center (SCC) - For cloud security and risk management For the new Remote MCP Server, please see the launch announcement and the setup guide. Each server can be enabled and run separately, allowing flexibility for environments that don't require all capabilities. Documentation Comprehensive documentation is available in the folder.

agentic-socai-agentsblueteamchronicle-siemchronicle-soarcybersecuritygoogle-cloudgoogle-secopsgoogle-threat-intelligenceincident-response

Quick Facts

Stars525
Forks138
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score63.4227624788306/100
Open Issues55
Last Updated2026-09-11
Created2025-04-02
Platformsmcp, python
Est. Tokens~17k

Compatible Skills

These tools work well together with mcp-security for enhanced workflows:

  • ai_for_the_win — semantic(0.44)+complementary+rare_topics+same_lang+similar_pop+shared_platform (79%)
  • allama — semantic(0.37)+complementary+rare_topics+same_lang+similar_pop+shared_platform (72%)
  • cti-expert — semantic(0.42)+complementary+rare_topics+same_lang+similar_pop+shared_platform (69%)
  • malwoverview — semantic(0.23)+complementary+rare_topics+same_lang+similar_pop+shared_platform (62%)
  • Wazuh-MCP-Server — semantic(0.52)+rare_topics+same_lang+similar_pop+shared_platform (62%)

mcp-security alternative? Top 6 similar tools

Looking for a mcp-security alternative? If you're comparing mcp-security with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • AiSOC by beenuar · ⭐ 2.4k

    Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a r

  • Wazuh-MCP-Server by gensecaihq · ⭐ 246

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • vigil by Vigil-SOC · ⭐ 340

    Vigil: The leading open source AI SOC. Apache 2.0. Runs against your own LLM, local or remote.

  • ai_for_the_win by depalmar · ⭐ 162

    Build AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red tea

  • mcp-virustotal by BurtTheCoder · ⭐ 127

    MCP server for VirusTotal API — analyze URLs, files, IPs, and domains with comprehensive security reports, rel

  • mcp-shodan by BurtTheCoder · ⭐ 118

    MCP server for Shodan — search internet-connected devices, IP reconnaissance, DNS lookups, and CVE/CPE vulnera

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is mcp-security?

mcp-security is an open-source mcp server by google with 525 GitHub stars.

What programming language is mcp-security written in?

mcp-security is primarily written in Python. It covers topics such as agentic-soc, ai-agents, blueteam.

How do I install or use mcp-security?

You can find installation instructions and usage details in the mcp-security GitHub repository at github.com/google/mcp-security. The project has 525 stars and 138 forks, indicating an active community.

What license does mcp-security use?

mcp-security is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to mcp-security?

The top alternatives to mcp-security on Agent Skills Hub include AiSOC, Wazuh-MCP-Server, vigil. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools