# Security — MCP servers and agent skills, ranked

> Every security capability tashan measures, ranked on public evidence.

Source: https://tashan.sh/category/security.html
Ranked by the tashan score
  (upkeep and freshness, gated by real adoption). Public evidence only — nothing paid can
  change a rank. Method: https://tashan.sh/methodology.html

## Ranked

| # | Capability | tashan score | Adoption evidence | Activity |
|---|---|---|---|---|
| 1 | [Consent](https://tashan.sh/capability/pkg-transcend-io-mcp-server-consent.html) | 85 | 60k/wk | active |
| 2 | [Assessment](https://tashan.sh/capability/pkg-transcend-io-mcp-server-assessment.html) | 80 | 12k/wk | active |
| 3 | [Ifixai](https://tashan.sh/capability/plugin-ifixai-ai-ifixai-ifixai.html) | 79 | 13k ★ | active |
| 4 | [Cybersecurity Skills](https://tashan.sh/capability/plugin-mukul975-anthropic-cybersecurity-skills-cybersecurity-skills.html) | 75 | 32k ★ | active |
| 5 | [Agent Skill Creator](https://tashan.sh/capability/plugin-francyjglisboa-agent-skill-creator-agent-skill-creator.html) | 74 | 2k ★ | active |
| 6 | [Prowler](https://tashan.sh/capability/plugin-prowler-cloud-prowler-prowler.html) | 74 | 15k ★ | active |
| 7 | [Auth0](https://tashan.sh/capability/pkg-auth0-auth0-mcp-server.html) | 74 | 4k/wk | active |
| 8 | [Agt Governance](https://tashan.sh/capability/plugin-microsoft-agent-governance-toolkit-agt-governance.html) | 72 | 6k ★ | active |
| 9 | [Claude Bughunter](https://tashan.sh/capability/plugin-elementalsouls-claude-bughunter-claude-bughunter.html) | 72 | 4k ★ | active |
| 10 | [Preflight](https://tashan.sh/capability/pkg-newrelic-preflight.html) | 72 | 4k/wk | active |
| 11 | [Accessibility Scanner](https://tashan.sh/capability/pkg-mcp-accessibility-scanner.html) | 71 | 3k/wk | active |
| 12 | [Ghl Command](https://tashan.sh/capability/pkg-elitedcs-ghl-mcp.html) | 71 | 3k/wk | active |
| 13 | [Fullcourtdefense CLI](https://tashan.sh/capability/pkg-fullcourtdefense-cli.html) | 71 | 3k/wk | active |
| 14 | [Agent Hooks](https://tashan.sh/capability/pkg-pushary-agent-hooks.html) | 71 | 2k/wk | active |
| 15 | [Safety Net](https://tashan.sh/capability/plugin-kenryu42-claude-code-safety-net-safety-net.html) | 70 | 1k ★ | active |
| 16 | [1Claw Vault](https://tashan.sh/capability/pkg-1claw-mcp.html) | 70 | 2k/wk | active |
| 17 | [Kya OS](https://tashan.sh/capability/pkg-kya-os-mcp.html) | 70 | 1k/wk | active |
| 18 | [Hephaestus](https://tashan.sh/capability/plugin-agentlas-ai-agentlas-os-hephaestus.html) | 69 | 1k ★ | active |
| 19 | [Shieldcortex](https://tashan.sh/capability/pkg-shieldcortex.html) | 69 | 2k/wk | active |
| 20 | [Remnux](https://tashan.sh/capability/pkg-remnux-mcp-server.html) | 69 | 2k/wk | active |
| 21 | [Prodcheck](https://tashan.sh/capability/pkg-prodcheck.html) | 69 | 2k/wk | active |
| 22 | [Marrow](https://tashan.sh/capability/pkg-getmarrow-mcp.html) | 69 | 1k/wk | active |
| 23 | [Observatory](https://tashan.sh/capability/pkg-kryptosai-mcp-observatory.html) | 69 | 1k/wk | active |
| 24 | [Pathmode](https://tashan.sh/capability/pkg-pathmode-mcp-server.html) | 69 | 1k/wk | active |
| 25 | [Docguard](https://tashan.sh/capability/pkg-docguard-cli.html) | 69 | 1k/wk | active |
| 26 | [Scf](https://tashan.sh/capability/pkg-mcp-server-scf.html) | 69 | 923/wk | active |
| 27 | [Tuteliq](https://tashan.sh/capability/pkg-tuteliq-mcp.html) | 69 | 485/wk | active |
| 28 | [Governance SDK](https://tashan.sh/capability/pkg-governance-sdk.html) | 68 | 3k/wk | active |
| 29 | [ArcBounty](https://tashan.sh/capability/pkg-arcbounty-mcp.html) | 68 | 2k/wk | active |
| 30 | [Pushci](https://tashan.sh/capability/pkg-pushci.html) | 68 | 2k/wk | active |
| 31 | [Exceptd Skills](https://tashan.sh/capability/pkg-blamejs-exceptd-skills.html) | 68 | 1k/wk | active |
| 32 | [Coderabbit](https://tashan.sh/capability/plugin-coderabbitai-skills-coderabbit.html) | 67 | 142 ★ | active |
| 33 | [Nah](https://tashan.sh/capability/plugin-manuelschipper-nah-nah.html) | 67 | 457 ★ | active |
| 34 | [Dotagents](https://tashan.sh/capability/plugin-getsentry-dotagents-dotagents.html) | 67 | 217 ★ | active |
| 35 | [Depwire CLI](https://tashan.sh/capability/pkg-depwire-cli.html) | 67 | 2k/wk | active |
| 36 | [Arc 1](https://tashan.sh/capability/pkg-arc-1.html) | 67 | 1k/wk | active |
| 37 | [Clinicaltrialsgov](https://tashan.sh/capability/pkg-clinicaltrialsgov-mcp-server.html) | 67 | 802/wk | active |
| 38 | [Agentsmesh](https://tashan.sh/capability/pkg-agentsmesh.html) | 67 | 731/wk | active |
| 39 | [Codeguard Security](https://tashan.sh/capability/plugin-cosai-oasis-project-codeguard-codeguard-security.html) | 66 | 276 ★ | active |
| 40 | [Knowledge Rail](https://tashan.sh/capability/pkg-knowledge-rail.html) | 66 | 890/wk | active |

Showing the top 40 of 994. The full ranked shelf is at https://tashan.sh/category/security.html.

## What these numbers are not

- The tashan score measures upkeep, freshness and adoption. It is **not** a security
  verdict and **not** a measure of whether the capability works well.
- `not scored` means too little public evidence to rank, never that something is bad.
- The security audit is separate and free per capability, on each page above.
