Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Draugr
Draugr logo
Health: ActiveRecent health check succeeded.Last checked 9/22/2026, 7:02:17 AM

Draugr

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository7 GitHub StarsTotal stargazers on GitHub for the source repository (7 stars).Visit Website

Answers what to fix first, from your committed security descriptor rather than an invented scope.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for Draugr, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

Draugr

Run Trivy, Semgrep, Gitleaks and more from one file. Get one SARIF report and one verdict.

CI OpenSSF Scorecard OpenSSF Best Practices Latest release License

Describe your app. Draugr figures out the rest.

Every application carries problems nobody put there on purpose: a library that turned out to have a hole in it, a password committed by accident, a server setting that leaves a door open. Draugr finds them, works out which ones actually matter for your app, and answers the question you are really asking before a release. is this safe to ship?

It runs the established open-source scanners for you, Trivy, Semgrep, Gitleaks and others, so there is nothing to choose between, wire up, or read five of. You describe what you built, once, in one file: where the repositories are, what images it builds, what it exposes, what infrastructure it runs on. Draugr picks the checks that apply, runs the right tool for each, and produces evidence you can hand to somebody else. Bring the scanners you already pay for, or use the open-source defaults.

Findings are ranked, not listed. A scanner's "critical" describes a flaw in the abstract. How bad it could be at its worst, anywhere. The same flaw is act-now in the service strangers can reach and backlog in the internal tool three people use, and no scanner can tell those apart because the difference is in the file you wrote, not in the code. And draugr diff gates a pull request on new findings only, so inheriting two hundred existing ones does not block every change.

Quickstart Β· See it in action Β· What it checks Β· In your pipeline Β· Documentation Β· What Draugr doesn't promise Β· Security

See it in action

A draugr scan of the demo sandbox: a FAIL verdict, the four priority bands, the two controls that ran with their severity counts, what each was measured against, a per-component verdict, what reachability analysis concluded, an accepted risk and a supplier's VEX, then the ranked findings. The fifth is a vendored jQuery raised to critical and marked as being on CISA's exploited catalog.

Priority (P1–P4) is not severity. Severity says how bad a flaw is at its worst, anywhere. Priority weighs that against how exposed and how important the part of your app it sits in is, which no scanner can work out, because it is not in the code.

draugr-dev/draugr-demo is a deliberately vulnerable app wired to Draugr: every control lights up, findings land in the repo's Security β†’ Code scanning tab, and its example pull requests show the new-vs-fixed diff.

Quickstart

Terminal
curl -fsSL https://draugr.dev/install.sh | sh

Installs to ~/.local/bin, no sudo. It verifies before it installs and says which checks ran, the archive's SHA-256 against the release checksums.txt, plus the cosign signature on that file when cosign is on your PATH, and installs nothing if a check fails. The script is readable in the repo; other routes, including Homebrew and go install, are in the install guide.

bash
draugr init            # describe this project in a draugr.saga.yaml
draugr tools install   # fetch the scanners it needs, pinned and verified
draugr scan            # scan what the descriptor describes

tools install takes its answer from the descriptor beside it, so a small service gets three scanners rather than every one Draugr can provision. --all when you are preparing a machine for several projects.

Then describe what you actually ship:

yaml
project: my-app
release:
  version: "1.0"
config:
  controls:
    images:
      enabled: true
components:
  - name: web
    images:
      - image: alpine:3.19
bash
draugr scan draugr.saga.yaml            # console summary; exits non-zero on fail
draugr scan draugr.saga.yaml -o out/    # also writes report.json + results.sarif
draugr scan draugr.saga.yaml --format markdown   # or html, junit, json, sarif

Your editor already knows this file. Draugr's JSON Schema is registered with SchemaStore, so any *.saga.yaml gets completion, hover docs and typo warnings on open with nothing to configure.

Or let discovery write the descriptor for you:

bash
draugr survey github repos --org my-org -o draugr.saga.yaml
draugr survey k8s images --namespace prod -o draugr.saga.yaml

Full walkthrough: quickstart.

What it checks

Each control is backed by a tool Draugr executes rather than bundles, so every scanner stays under its own license, and you can swap it.

ControlLooks forBy default
scaknown flaws in the libraries you depend onTrivy, Grype and Mend opt-in
secretspasswords and keys committed by accident, history includedGitleaks
sastpatterns in the code you wrote that let somebody inSemgrep, gosec opt-in for Go
iacsettings that leave a door open, in Terraform, Kubernetes and DockerfilesTrivy
imageswhat is baked into your container imagesTrivy, Grype opt-in
licensesterms attached to code you did not writeTrivy
dastproblems only visible from outside a running appNuclei, authenticated, and from an OpenAPI spec
headershow your site answers a browsernative
tlscertificates and encryptionnative
infrastructureyour Kubernetes cluster, against the CIS benchmarksnative, kube-bench opt-in
threatswhether anything you talk to is on a public blocklistabuse.ch URLhaus
provenancewhether an image is signed by the builder you expectSigstore cosign

Every scanner, what it sends and whose terms it carries: integrations catalog.

Alongside them: content-hash caching, an SBOM per repository and image, KEV/EPSS enrichment, per-control gate thresholds, and suppressions that stay in the report with the reason someone gave rather than disappearing.

In your pipeline

The first-party GitHub Action installs Draugr, provisions the scanners, and hands the merged SARIF to code scanning, one clean Draugr tool in the Security tab:

yaml
permissions:
  contents: read
  security-events: write

steps:
  - uses: actions/checkout@v4
  - id: draugr
    uses: draugr-dev/draugr@v0     # pin @vX.Y.Z for reproducible CI
    with:
      saga: draugr.saga.yaml
      tools: true                  # provision the scanners the controls need
  - if: always()                   # publish findings even when the gate fails
    uses: github/codeql-action/upload-sarif@v3
    with:
      sarif_file: ${{ steps.draugr.outputs.sarif }}

GitHub Actions Β· GitLab, an include, GitLab's own report formats, a sticky merge-request comment Β· Azure Pipelines, a step template

From an AI coding assistant. Ask one to check a change and it will, using whatever scanner it finds over a scope it chose. draugr mcp serves Draugr over the Model Context Protocol so it reads your committed descriptor instead, and scanning is off by default, because it clones repositories and runs external tools.

Terminal
claude mcp add draugr -- draugr mcp

See use Draugr from an AI coding assistant.

Documentation

Documentation index β†’

  • Quickstart, install, first scan, first survey, CI
  • Concepts, the descriptor, controls, scanners, the verdict
  • Saga schema Β· CLI reference, every field, every flag
  • Integrations catalog, every scanner, with licenses and terms
  • Contributing Β· Changelog

What Draugr doesn't promise

A passing verdict means the controls you configured found nothing they were looking for. It is not a statement that your software is secure. It is silent about anything your descriptor does not declare, controls you did not enable, and whatever the underlying scanners miss. License findings are information, not legal advice. Draugr is provided under Apache-2.0 without warranty.

The details, including whose terms the scanners carry and your responsibility for authorization when scanning live endpoints: scope and disclaimer.

Security & supply chain

A security tool should hold itself to what it checks. Draugr does:

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • Ida Pro MCP logoIda Pro MCP

    MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

    πŸ”’ Security4 views
    Compare vs Ida Pro MCP β†’
  • Ui Ux Suite logoUi Ux Suite

    UI/UX design-audit MCP server: scores a project on 12 dimensions vs WCAG 2.2 + APCA.

    πŸ”’ Security1 views
    Compare vs Ui Ux Suite β†’
  • Agent Security Scanner MCP logoAgent Security Scanner MCP

    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

    πŸ”’ Security1 views
    Compare vs Agent Security Scanner MCP β†’
  • Huntress logoHuntress

    MCP server for Huntress β€” accounts, organizations, agents, incidents, and reports.

    πŸ”’ Security1 views
    Compare vs Huntress β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
7
Stargazers on the source repository.
Last commit
23d ago
Most recent push to the default branch.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Draugr

We don't have a confirmed install command for Draugr yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/draugr-dev/draugr) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewDraugr AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/draugr?style=directory)](https://allmcps.com/mcp/draugr)
HTML Embed
<a href="https://allmcps.com/mcp/draugr"><img src="https://allmcps.com/api/badge/draugr?style=directory" alt="Draugr on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
Last updatedSep 2, 2026
4/4 checks healthy over the last 42d
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars7
GitHub Star CountTotal stargazers on GitHub representing community popularity (7 stars).
Last commit23d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 2, 2026
36Quality signal: Fair Β· 36/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools11/30
Adoption & activity6/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Draugr β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients