Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Jikida
Jikida logo
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Jikida

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for unesLam/jikida, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

Jikida guardian

Jikida.io

The hosted AI pentester for people who ship β€” not just security engineers.
Pentest your live app, scan your repo, protect it with a WAF, and watch its uptime. One account. No Docker, no LLM key, free tier.

site mcp sdks npm scan packagist license

Why it beats Nuclei / Strix / Shannon ↓ Β· Install Β· MCP Β· SDKs Β· Compare

Install it, scan it, or plug it into your AI editor:

Terminal
npx @jikida/init      # add the SDK + protection to your app in 30 seconds
npx @jikida/scan      # pentest any site or repo from your terminal
npx -y @jikida/mcp    # security tools inside Claude Code, Cursor, Windsurf
Code
[object Object],
 pentest Β· repo scan Β· uptime Β· alerts        https://jikida.io

 β†’ scanning example.com …
 βœ“ 41 checks Β· grade B (88/100)

   CRITICAL  Exposed .env file            /.env                 CWE-538
   CRITICAL  Stripe secret key in JS      /app.js:1204          CWE-312
   HIGH      Missing Content-Security-Policy                    CWE-693
   MEDIUM    Cookie without Secure flag   session               CWE-614

 Every finding has a fix. Full report: https://app.jikida.io

Pentest & scan for developers, AI IDEs & vibe coders

Pentest and scan websites, web apps, code and GitHub for vulnerabilities and exposed keys. Secure vibe-coded apps, monitor uptime, SSL and domains, and rate-limit APIs. One platform.

Website & app pentest Β· Code & repo scan Β· Deep pentest Β· MCP for AI IDEs Β· Agentic & vibe-coded security Β· SDKs


Jikida.io is a developer-first security platform. The core is pentest and scanning: it pentests your live website and app, scans your code and connected GitHub/GitLab/Bitbucket repos for exposed secrets and vulnerable dependencies, runs a deeper authenticated pentest, and plugs into your AI IDE (Claude Code, Cursor, Windsurf) over MCP so it guides agentic and vibe-coded work to write secure code and catches mistakes before they ship. Uptime, SSL & domain monitoring, a managed WAF, and a compliance generator come bundled as complementary extras β€” installed in one line for Node, PHP/Laravel, Python, Go, Ruby, Java, .NET, Rust, Bun, or Deno.

Your security layer. Shipped in 30 seconds. One line β€” npx @jikida/init β€” and every SDK fails open, so if Jikida.io is ever down your app keeps serving.


Why Jikida beats the other security tools

The strongest open-source security tools are deep but narrow β€” pentest-only, self-hosted, bring-your-own-LLM-key. Jikida does the deep work and hosts it, runs with no key of your own, and adds a WAF, uptime and repo scan the pentest-only tools skip. βœ… full Β· ⚠️ partial Β· ❌ none.

JikidaNucleiStrixShannonSnykCloudflare
Live-app pentest with real exploitβœ…βš οΈΒ matchβœ…βœ…βŒβŒ
SAST + DAST (code and live app)βœ…βš οΈΒ DASTβœ…βœ…βš οΈΒ SAST❌
Repo secret + CVE (OSV) scanβœ…βŒβš οΈβš οΈβœ…βŒ
Managed WAF (blocks live attacks)βœ…βŒβŒβŒβŒβœ…
Uptime + SSL / domain monitoringβœ…βŒβŒβŒβŒβš οΈ
Hosted β€” no Docker, no self-hostβœ…βš οΈΒ cloudβŒβŒβœ…βœ…
Runs with no LLM key of yoursβœ…βœ…βŒΒ BYOK❌ BYOKβœ…βœ…
Install: CLI + Docker + npxβœ…Β all⚠️ CLI⚠️ Docker⚠️ npx⚠️ CLI⚠️ DNS
MCP tools in your AI editorβœ…βŒβŒβš οΈβŒβŒ
Free tier, no cardβœ…βœ…βœ…βœ…βœ…βœ…

The one axis the AI pentesters still go deeper on is raw exploitation β€” exactly what our source-to-exploit deep pentest is closing. Everywhere else, the builder who shipped with Cursor last week wins with Jikida: nothing to self-host, no key to buy, the whole stack in one account. Full breakdowns: nuclei Β· strix Β· shannon Β· snyk Β· cloudflare.


Get started β€” pick your entry point

Every command below sits in its own copy box. Lines that start with ! are notes, not commands β€” do not copy those.

Scan a URL or repo β€” no account needed.

Terminal
npx @jikida/scan https://your-app.com

! Scan a local repo for committed secrets:

Terminal
npx @jikida/scan ./

Add the WAF + SDK β€” auto-detects your framework.

Terminal
npx @jikida/init

Install a language SDK β€” Node shown; PHP, Python, Go and the rest are in the SDK table.

Terminal
npm install @jikida/sdk-node

MCP server for Claude Code, Cursor and Windsurf β€” add this to ~/.claude/mcp.json:

config.json
{ "mcpServers": { "jikida": { "command": "npx", "args": ["-y", "@jikida/mcp"] } } }

Agent skills β€” copy the skills/ folder into your assistant's skills folder (.claude/skills/, Cursor rules, and the like). Three skills: security, clean-code, UX design β€” see the table below.

Full details for each are below.

Where things live

FolderWhat it holds
sdks/Ten language SDKs β€” Node, PHP, Python, Go, Ruby, Java, .NET, Rust, Bun, Deno.
tools/The scan CLI, the init onboarding CLI, and the mcp server.
skills/The Jikida agent skill for Claude Code, Cursor and Windsurf.
waf-rules/Versioned WAF rule packs (OWASP Top 10, API abuse, bot scanners, vibe-coder).

Get a token at app.jikida.io/developer. Set it as JIKIDA_TOKEN.


See it in action

One dashboard for a site's whole security posture β€” protection status, uptime, pentest grade, email security (SPF/DKIM/DMARC) and compliance β€” with instant alerts to your phone, Slack, Telegram, Discord, email or a webhook.

Jikida.io dashboard β€” site overview with protection status, uptime, pentest grade, email security and compliance

  • Uptime & performance β€” response-time trend, uptime %, P95 and an incident timeline for every page and API you watch.
  • API rate-limits & rules β€” your SDK auto-detects endpoints from real traffic; approve per-endpoint rate caps and WAF rules, or dismiss the ones you don't need.

Table of contents

  • Why Jikida beats the other security tools
  • Why Jikida.io
  • How access works
  • What's inside
  • Quick install
  • Security for your stack
  • SDKs β€” every language
  • MCP server for AI IDEs
  • Free tools
  • Skill for Claude Code
  • Standards & mappings
  • Threats Jikida.io stops
  • Contributing

Why Jikida.io

Most small teams ship without a Web Application Firewall in front of their app. They know they should. They put it on the backlog. Then the free trial ends, or a user reports a slow page, and the WAF ticket rots another quarter.

Jikida.io removes three specific frictions:

  1. Install β€” one line, one language, five minutes.
  2. Downside risk β€” every SDK is fail-open. If Jikida.io is down, your app keeps serving. You lose protection, not availability.
  3. Cost β€” there's a real free tier that protects a hobby project. Plans and current pricing live at jikida.io.

How access works β€” free, then account-gated, then plan-gated

Everything in this repo is open source, and a lot of Jikida.io is usable before you ever sign up. The model is three tiers of friction, on purpose:

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • I
    Ida Pro MCP

    MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

    πŸ”’ Security4 views
    Compare vs Ida Pro MCP β†’
  • U
    Ui Ux Suite

    UI/UX design-audit MCP server: scores a project on 12 dimensions vs WCAG 2.2 + APCA.

    πŸ”’ Security1 views
    Compare vs Ui Ux Suite β†’
  • A
    Agent Security Scanner MCP

    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

    πŸ”’ Security1 views
    Compare vs Agent Security Scanner MCP β†’
  • M
    MCP Audit

    Transparent audit proxy for MCP servers: logs every tool call, flags poisoning and rug pulls.

    πŸ”’ Security1 views
    Compare vs MCP Audit β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Jikida

We don't have a confirmed install command for unesLam/jikida yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/unesLam/jikida) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewJikida AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/uneslam-jikida?style=directory)](https://allmcps.com/mcp/uneslam-jikida)
HTML Embed
<a href="https://allmcps.com/mcp/uneslam-jikida"><img src="https://allmcps.com/api/badge/uneslam-jikida?style=directory" alt="Jikida on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging Β· 27/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Featured
A

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Jikida β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients