MCP servers
Official MCP servers for security and code quality
Run security and quality scans as part of the agent's loop so issues are fixed before review.
Reviewed Oct 5, 2026. Every server here is published under the vendor's own namespace in the official MCP registry.
| Server | What it does | Runs | Version |
|---|---|---|---|
| SnykSnyk | Scan code, dependencies, containers and IaC for vulnerabilities from the agent. | Local | 1.1304.2 |
| SonarQubeSonarSource | Check code quality and security issues with SonarQube Server or Cloud. | Local | 1.21.0 |
What teams use these for
- Scan new dependencies with Snyk before committing
- Check SonarQube issues on the files the agent changed
How to choose
- Remote first. A hosted server with OAuth means no API key on your laptop and updates without reinstalling.
- Local when data must stay put. Packages run on your machine, which suits private networks and self-hosted instances.
- Fewer tools, better results. Every connected server adds tool descriptions to the context. Connect what the task needs, not everything.
Other categories
Built an MCP server for security & code quality?
Feature it at the top of this page and the directory from $49/month, or list it for free.