Registry

Browse by Category

Every category is analysed for security findings. High-risk categories and servers with critical findings are surfaced first.

Database

Connectors for SQL, NoSQL, vector, and time-series databases — query execution, schema inspection, and data management.

SQL injection · credential exposure · schema leakage
Filesystem

Servers that read, write, list, or watch files on the local or remote filesystem, including cloud storage backends.

Path traversal · arbitrary write · data exfiltration
API Integration

Wrappers around third-party REST, GraphQL, and webhook APIs — Stripe, Twilio, SendGrid, GitHub, and similar services.

OAuth misconfiguration · token exposure · SSRF
Dev Tools

Development tooling — code search, linters, test runners, build systems, and IDE integrations.

Command injection · arbitrary code execution
AI / ML

Machine learning model inference, embedding generation, vector similarity search, and AI pipeline orchestration.

Prompt injection · model poisoning · data leakage
Browser / Web

Browser automation, web scraping, screenshot capture, and general HTTP request execution.

Indirect injection via web content · CSRF · SSRF
Code Execution

REPL environments, sandbox runners, shell command execution, and scripting language interpreters.

Arbitrary execution · sandbox escape · RCE
Communication

Email, Slack, Discord, and messaging platform integrations — read and send messages, manage channels.

Indirect injection via messages · phishing via send
Cloud Infrastructure

AWS, GCP, Azure, and cloud-native tools — infrastructure provisioning, resource management, and deployment.

Excessive IAM permissions · privilege escalation
Security

Security-focused tools — vulnerability scanners, secret detection, penetration testing aids, and compliance checks.

Privilege abuse · scanner blind spots · false safety
Data Processing

ETL pipelines, data transformation, format conversion, CSV/JSON/XML parsing, and stream processing.

Unsafe deserialization · template injection · DoS
Monitoring

Observability tooling — metrics, logs, traces, alerts, dashboards, and on-call integrations.

Log injection · sensitive data in telemetry
Search

Full-text and semantic search across codebases, documents, databases, and the web.

Indirect injection via search results · SSRF
Other

Miscellaneous MCP servers that don't fit a primary category — utilities, experiments, and niche integrations.

Varies — review individual server findings

Looking for something specific?

Search across all categories with filters, score ranges, and sort options.

Search all servers