Draugr MCP Server

Describe your app. Draugr figures out the rest. Every application carries problems nobody put there on purpose: a library that turned out to have a hole in it, a password committed by accident, a server setting that leaves a door open. Draugr finds them, works out which ones actually matter for your app, and answers the question you are really asking before a release. is this safe to ship?

People who work with appsec, code scanning and container security and want it reachable from Claude, Cursor, VS Code, or another MCP client. The project is written in Go.

VERIFIED ACTIVE

LAST COMMIT 2026-09-18 · ★ 7 · #149 OF 204 MAINTAINED SECURITY · VERIFIED 2026-09-18

Apache-2.0 · Go servers · how we verify → /methodology

01 · Install Draugr

Claude Desktop

Settings → Extensions → Install, then select the https://github.com/draugr-dev/draugr/releases/download/v0.126.0/draugr-0.126.0.mcpb .mcpb bundle

02 · Evidence

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as Claude Desktop extension (.mcpb bundle)

license Apache-2.0 - declared in the repository

registry vendor namespace dev.draugr - domain-verified with the official MCP registry

03 · What Draugr can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

Latest releases

v0.126.0 · 2026-09-17

Added · A new provenance control checks that a container image is signed by the identity you expect, with cosign. Declare your signers once under config.controls.provenance.signers, saying which images each covers, and…

v0.125.0 · 2026-09-15

Added · A run says whether its findings came from a cache, how old the oldest reused one is, and which directory it came from. stats.cache in the report carries enabled, dir, ttl, readOnly, hits, oldestHit and the…

v0.124.0 · 2026-09-15

Added · Every environment variable you would set is in one table in the CLI reference, with the OpenTelemetry endpoints named rather than gestured at as OTEL_. Sixteen of them were spread over eight pages, and…

04 · Who maintains Draugr

Draugr is maintained by draugr-dev. It's the only MCP server we track from this author; the repo dates to Jul 2026.

05 · Facts

category
security - ranked #149 of 204 actively-maintained security servers as of 2026-09-18.
release cadence
10+ releases in the last 90 days (latest 2026-09-17)
registry
dev.draugr/draugr (active, first published 2026-07-27 · 106 versions)
packages
mcpb:https://github.com/draugr-dev/draugr/releases/download/v0.126.0/draugr-0.126.0.mcpb

06 · Draugr FAQ

What is Draugr?

Describe your app. Draugr figures out the rest. Every application carries problems nobody put there on purpose: a library that turned out to have a hole in it, a password committed by accident, a server setting that leaves a door open. Draugr finds them, works out which ones actually matter for your app, and answers the question you are really asking before a release. is this safe to ship?

Is Draugr still maintained?

Yes - as of 2026-09-18, its last commit was 2026-09-18 and it shipped 10+ releases in the last 90 days. We re-verify nightly.

07 · Alternatives to Draugr

More security MCP servers · DSers Official MCP Server · ZAP Server · Toolmesh · Reolink MCP · Zzop

More Go MCP servers · Office Addin MCP · Pituitary · Yutu · Go Model · see all