Free MCP directory + security guides + audit pack

Browse free MCP servers, then audit risky setups before production.

BestMCPServers keeps MCP server discovery free, adds practical security guides and tools, and points production setups to the MCP Security Audit Pack for permission scoring, prompt-injection review, and rollout gates.

Directory stays freeBrowse servers, categories, and client-specific MCP setup pages.
Security comes nextUse guides and tools before adding production access.
Audit pack is the upgradeScore permissions, test prompt injection, and document rollout gates.

MCP Directory

Browse servers as security-reviewed building blocks

The directory remains the free library for choosing MCP servers before you review permissions, secrets, prompt-injection exposure, and rollout controls.

Browse MCP Servers by Category

20 servers
Filesystem

Secure file operations with configurable access controls.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-filesystem /path/to/allowed/dir
DevTools

Repository management, file operations, and search.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-github
Database

Read-only database access with schema inspection.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-postgres postgresql://localhost/mydb
Database

SQLite database interaction and querying.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-sqlite /path/to/database.db
Browser

Browser automation and web scraping capabilities.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-puppeteer

Web and local search using Brave Search API.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-brave-search

Fetch any URL and extract content as markdown.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-fetch
Communication

Send and read Slack messages across channels.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-slack

Access and search Google Drive files and documents.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-google-drive

Dynamic problem-solving with structured thought chains.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-sequential-thinking

Retrieve information from AWS Knowledge Base.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-aws-kb-retrieval
DevTools

Error tracking and performance monitoring integration.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-sentry
Database

Redis operations including read, write, and search.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-redis
DevTools

Reference server demonstrating all MCP features.

ClaudeCursorGeneric
npx -y @modelcontextprotocol/server-everything

Scrape and convert any website to LLM-ready markdown.

ClaudeCursorGeneric
npx -y mcp-server-firecrawl

Cloud browser automation and session management.

ClaudeCursorGeneric
npx -y @browserbasehq/mcp-server-browserbase
Communication

Read and write Notion pages and databases.

ClaudeCursorGeneric
npx -y @notionhq/notion-mcp-server
Communication

Project management and issue tracking integration.

ClaudeCursorGeneric
npx -y @linear/mcp-server
Cloud

Manage Vercel deployments and projects.

ClaudeCursorGeneric
npx -y @vercel/mcp-server
Browser

End-to-end testing and browser automation.

ClaudeCursorGeneric
npx -y @playwright/mcp-server

Next: secure the stack

Do not stop at server discovery

Review filesystem, network, shell, database, browser, and secret access before connecting an MCP server to production systems.

Audit an MCP setup

Resources

AI coding, prompt, PRD, and utility pages remain available

These secondary resources stay indexable, but the primary site path now starts with the MCP Directory and security handoff.

Featured workflow packs

MCP Security Audit Pack, then secondary workflow packs

The flagship upgrade is the MCP Security Audit Pack. Other workflow packs remain available as secondary implementation resources for AI builders.

Claude CodeLow setup

MCP Security Audit Pack

A high-trust asset pack for permission scoring, prompt-injection review, rollout gates, and safe MCP adoption.

Outcome: You need a repeatable decision package before giving an AI agent powerful tools in production.

Saves 2–6 hours per toolchain approval.

Claude CodeLow setup

Claude Code Repo Onboarding Pack

Understand an unfamiliar repo, choose the right MCP stack, and make the first safe change.

Outcome: You need to add a feature or fix a bug in a repo you did not write, without breaking auth, billing, deployment, or data flows.

Saves 4–8 hours per unfamiliar repo onboarding.

CursorLow setup

Cursor Full-Stack Feature Pack

Ship a full-stack feature with repo context, docs, browser QA, and deployment checks.

Outcome: You need to add a customer-visible feature and verify it across UI, API, billing, analytics, and SEO.

Saves 3–6 hours per feature sprint.

OpenAI CodexLow setup

OpenAI Codex PR Review Pack

Review, fix, and merge PRs with targeted MCP context instead of broad code reading.

Outcome: You have a PR that might work, but you need risk review, tests, security checks, and a merge decision quickly.

Saves 2–5 hours per complex PR review.

Claude CodeLow setup

Claude Desktop Production MCP Pack

Configure Claude MCP access with least privilege, secrets discipline, and rollback notes.

Outcome: You want Claude to work with real project files and tools, but you need safe boundaries.

Saves 2–4 hours per secure setup.

HermesMedium setup

Hermes Solo SaaS Command Center Pack

Run a small AI team across product, code, content, QA, deployment, and evidence reporting.

Outcome: You need a front-office agent to route code, content, QA, growth, and deployment tasks without losing accountability.

Saves 5–10 hours per launch cycle.

How it works

Directory as library. Workflows as product.

1

Browse the free directory

Start with the MCP server category, client, and access boundary you actually need.

2

Review security guidance

Check permissions, secrets, prompt-injection exposure, and production rollout risk before installing.

3

Audit the MCP setup

Use the MCP Security Audit Pack when the setup needs approval-ready worksheets, scorecards, and rollout gates.

Security & permissions

Review MCP risk before production access

Use free security guides and tools to define least-privilege scopes, review prompt-injection exposure, and decide whether the setup needs an audit-ready package.

Pricing

Pick the workflow depth you need now

Transparent MVP pricing for individual AI builders. No unimplemented team or enterprise promises.

Builder Pack

$9.99 lifetime

Secondary workflow assets for validating one concrete AI coding workflow.

  • ✓ Claude Code Repo Onboarding
  • ✓ Cursor Full-Stack Feature
  • ✓ OpenAI Codex PR Review
  • ✓ Copy-ready MCP stack recommendations

Recommended

Pro

$19/mo

Best for builders who need the MCP Security Audit Pack plus repeated repo, QA, and launch workflows.

  • ✓ Full workflow library across Claude Code, Cursor, Codex, Gemini CLI, and Hermes
  • ✓ Pro implementation checklists and acceptance steps
  • ✓ MCP security audit and production setup workflows
  • ✓ Lifetime Builder access and Pro unlocks use the same account path

Free builder tools

Use the free tools, then upgrade the workflow

Calculators, stack builders, config generators, PRD templates, agents, prompts, and guides stay free. Use them to scope the job; Builder and Pro packs turn the output into repeatable implementation workflows.

Design agent workflows

Secondary resources for choosing the CLI, planning loop, website agent, or MCP stack after the MCP directory path is clear.

Plan AI cost & pricing

Validate the numbers before you buy or build the workflow.

Plan products and agents

Scope the product, agent, prompt, or guide before upgrading the implementation workflow.

FAQ

Straight answers for the MVP homepage

Is BestMCPServers still a directory?

Yes. The MCP Directory remains free and indexable. The homepage now leads with free MCP discovery, then points security-sensitive setups to guides, tools, and the MCP Security Audit Pack.

What changed in the positioning?

BestMCPServers is positioned around one primary path: Free MCP Directory -> MCP Security Guides/Tools -> MCP Security Audit Pack.

Are these workflow packs real products?

The public pages describe the actual pack structure already in the site: use case, MCP stack, workflow steps, saved time, prompts, config guidance, and safety checks.

Do you claim team seats or unlimited usage?

No. The homepage intentionally avoids unimplemented Team, Enterprise, Unlimited, and save-server claims.

Which plans are available now?

Builder Pack is $9.99 lifetime for the first workflow packs. Pro is $19/mo for the broader workflow library and Pro implementation checklists.

Can I still browse MCP servers for free?

Yes. Directory, guides, and free developer tools stay available as public resources.

Which tools are covered first?

The MVP highlights Claude Code Repo Onboarding, Cursor Full-Stack Feature, OpenAI Codex PR Review, Claude Desktop Production MCP, Hermes Solo SaaS Command Center, and MCP Security Audit.