mcpbeat Sign in

Security Tools MCP Server

by rangercheck Your server? Claim it
answering

Security Tools is answering right now. Last checked 5 min ago. It exposes 1 tools.

Free front-end security check for any website: a grade plus the secrets and keys it exposes.

Uptime history 11 hours of history
11 hours agonow
100.0%
Uptime 24h
40 of 40 checks
1
Tools
read from the server
535 ms
Response time
average over 24h
open, no key
Access
streamable-http

Nothing serious here today

Today is the operative word: we check Security Tools every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 5 min ago.

run in your terminal
claude mcp add security-tools --transport http https://rangercheck.com/api/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "security-tools": {
      "url": "https://rangercheck.com/api/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.security-tools]
url = "https://rangercheck.com/api/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "security-tools": {
      "url": "https://rangercheck.com/api/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "security-tools": {
      "url": "https://rangercheck.com/api/mcp"
    }
  }
}

Available tools 1

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

scan
scan_security
Run a free front-end security check on any website and get a letter grade (A to F) plus specific findings. Answers questions like 'is example.com leaking API keys or secrets in its front-end code', 'does this site expose a Stripe/AWS/OpenAI key or a publicly readable database', or 'how is this website's client-side security'. Reads only what the site serves publicly; never logs in or changes anything.

Endpoints

URLTransportStateLatencyChecked
https://rangercheck.com/api/mcp streamable-http answering 1214 ms 5 min ago

Alternatives to Security Tools

same job, measured the same way
Nel Veil
by nelproinc

Free passive security scanning - check any domain's DMARC, TLS, headers, and exposures.

1 018 installs/wk local only
ExposureGuard
by exposureguard

Domain security scanning for AI agents. A-F grades, 8 checks, fix snippets.

91 installs/wk local only
Mcpgrade
by mcpgrade

Security grades (A-F) for MCP servers. Check one before you install or trust it. mcpgrade.dev

61 installs/wk local only
C
Opzyai Security Check
by opzyai

Local-first security check for AI coding agents: secrets, .env exposure, git-history leaks, CVEs.

68 installs/wk local only
Domain Intel
by erikirby

Website intelligence for AI agents: tech stack, hosting, security posture, SEO, and DNS.

31 installs/wk local only
MCP Server Security Audit
by joepangallo

Scan websites for security vulnerabilities, headers, TLS, and email security.

33 installs/wk local only
Arcwall Security
by rom-baro

Security scanning for AI coding tools. Detects secrets, threat models, and runs pre-commit checks.

50 installs/wk local only
Env Secret Exposure Analyzer MCP
by vola-trebla

Scans projects for secret exposure: leaked API keys, unprotected .env files, and secrets in logs.

58 installs/wk local only

Security Tools — questions

Answers built from our own checks of this server.

What can Security Tools do?
It exposes 1 tools, read directly from the server on our last check. Among them: scan_security. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is Security Tools working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 40 of 40 checks got a reply (100.0%), average response time 535 ms. The bar chart above shows every period we have measured.
How do I connect Security Tools?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does Security Tools need an API key?
No. Security Tools completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 1 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is Security Tools?
It answers our handshake in 535 ms on average, which is faster than 31% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.