mcpbeat Sign in

AgentSec MCP Server

by traveljamboree Your server? Claim it
answering

AgentSec MCP is answering right now. Last checked 14 min ago. It exposes 3 tools.

Security intelligence via x402 on Base. CVE lookup, IP reputation, secret scanning.

Uptime history 47 days of history
47 days agonow
100.0%
Uptime 24h
91 of 91 checks
3
Tools
read from the server
172 ms
Response time
average over 24h
open, no key
Access
streamable-http

Nothing serious here today

Today is the operative word: we check AgentSec MCP every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.

Three servers free · no card

Connect this server

Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 14 min ago.

run in your terminal
claude mcp add agentsec-mcp --transport http https://agentsec-mcp.agentsec-mcp.workers.dev/mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "agentsec-mcp": {
      "url": "https://agentsec-mcp.agentsec-mcp.workers.dev/mcp"
    }
  }
}
~/.codex/config.toml
[mcp_servers.agentsec-mcp]
url = "https://agentsec-mcp.agentsec-mcp.workers.dev/mcp"
.cursor/mcp.json
{
  "mcpServers": {
    "agentsec-mcp": {
      "url": "https://agentsec-mcp.agentsec-mcp.workers.dev/mcp"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "agentsec-mcp": {
      "url": "https://agentsec-mcp.agentsec-mcp.workers.dev/mcp"
    }
  }
}

Available tools 3

Read directly from the server with tools/list, grouped by what they act on. If a tool disappears, we record the date.

cve
cve_lookup
Look up known CVE vulnerabilities for an npm package+version or a specific CVE ID. Returns CVSS scores, descriptions, and fix versions from NVD and OSV. Results are cached for 10 minutes. Costs $0.01 USDC per call.
reputation
reputation_check
Check the reputation of an IP address or domain using AbuseIPDB and VirusTotal. Returns a security verdict (malicious/suspicious/unknown/clean) with confidence signals. Verdict is conservative: incomplete data returns 'unknown' never 'clean'. Results are cached for 10 minutes. Costs $0.01 USDC per call.
secret
secret_scan
Scan text content for hardcoded secrets, API keys, and credentials using 20 pre-compiled patterns. Privacy guarantee: Input text is NEVER logged, cached, stored, or forwarded. Only findings_count and finding offsets (not matched values) are returned. Detected pattern types include: AWS keys, GitHub/GitLab PATs, OpenAI/Anthropic keys, Stripe secrets, Slack tokens, PEM private keys, JWT tokens, and 13 more. Per-call rate limit: 100/min. Payment: $0.05 USDC per scan.

Endpoints

URLTransportStateLatencyChecked
https://agentsec-mcp.agentsec-mcp.workers.dev/mcp streamable-http answering 183 ms 14 min ago

Alternatives to AgentSec MCP

same job, measured the same way
Security Recipes
by stevologic

Read-only CVE intelligence, remediation playbooks, and agent setup guides. Not a scanner.

75 tools answering
Domainintel MCP
by bishop81

Domain intelligence for agents: WHOIS, DNS, SSL/TLS, security headers, reputation, subdomains.

47 installs/wk local only
I
Pyresec Agent
by renaat-s

SAST and SCA security auditing via x402 USDC on Base. Quick scans, deep audits, remediation.

local only
Repository Intelligence
by nirholas

Analyze repos of any size - security scanning code analysis monorepo support

local only
Tollbooth
by huwhitememes

37 paid x402 MCP tools for OSINT, prediction markets, web intel, and agent security on Base USDC.

104 tools answering
BentCrypto Machine Payments
by ghstaking

Paid token risk and security intelligence for AI agents over MCP with x402 payments.

2 tools answering
Rune
by thecolourfoundation

Evidence-traced codebase understanding and security scanning for AI agents over MCP.

24 installs/wk local only
Cobalt
by pipeworx-io

Cobalt Intelligence MCP — US Secretary-of-State business registration, UCC

answering

AgentSec MCP — questions

Answers built from our own checks of this server.

What can AgentSec MCP do?
It exposes 3 tools, read directly from the server on our last check. Among them: cve_lookup, reputation_check, secret_scan. The full list with descriptions is on this page — we take it from the server itself via tools/list, not from a README. How MCP servers expose tools in the first place →
Is AgentSec MCP working right now?
We send a real MCP handshake every 15 minutes. Over the last 24 hours 91 of 91 checks got a reply (100.0%), average response time 172 ms. The bar chart above shows every period we have measured.
How do I connect AgentSec MCP?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It is a remote server, so there is nothing to install — the client connects to the address.
Does AgentSec MCP need an API key?
No. AgentSec MCP completed a full MCP handshake with us as an anonymous client and listed its tools without asking for anything. All 3 of them are readable on this page. This is what we observed, not what the docs claim.
How fast is AgentSec MCP?
It answers our handshake in 172 ms on average, which is faster than 72% of all working MCP servers we measure. The comparison comes from our own checks across the whole registry, every 15 minutes.