Draugr MCP Server

Describe your app. Draugr figures out the rest. Every application carries problems nobody put there on purpose: a library that turned out to have a hole in it, a password committed by accident, a server setting that leaves a door open. Draugr finds them, works out which ones actually matter for your app, and answers the question you are really asking before a release - is this safe to ship?

People who need security tools inside Claude, Cursor, VS Code, or another MCP client. The project is written in Go.

VERIFIED ACTIVE

LAST COMMIT 2026-08-24 · ★ 3 · #146 OF 182 MAINTAINED SECURITY · VERIFIED 2026-08-25

Apache-2.0 · Go servers · how we verify → /methodology

01 · Install Draugr

Claude Desktop

Settings → Extensions → Install, then select the https://github.com/draugr-dev/draugr/releases/download/v0.106.0/draugr-0.106.0.mcpb .mcpb bundle

02 · Evidence

Security posture

What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.

runs as Claude Desktop extension (.mcpb bundle)

repo age created 2026-07-06 - young repo, little track record yet

license Apache-2.0 - declared in the repository

registry vendor namespace dev.draugr - domain-verified with the official MCP registry

03 · What Draugr can do

Prose above is summarized from the project's README and registry record - no invented capabilities.

Latest releases

v0.106.0 · 2026-08-24

Added · A report says what produced it, not only what it found. report.json gained two blocks: descriptor - the digest of the merged, effective Saga plus every file it was assembled from, each with its own digest - and…

v0.105.0 · 2026-08-22

Added · Every finding says which control found it. results.sarif now carries · properties.control - sca, sast, secrets - beside the scanner in properties.tool. · Anything that reads the report and groups findings, from…

v0.104.0 · 2026-08-22

Added · Findings keep their identity when code moves. Draugr now emits SARIF · partialFingerprints, computed from the code around a finding rather than the line it sits on. · Adding an import at the top of a file used…

04 · Who maintains Draugr

Draugr is maintained by draugr-dev. It's the only MCP server we track from this author; the repo dates to Jul 2026.

05 · Facts

category
security - ranked #146 of 182 actively-maintained security servers as of 2026-08-25.
release cadence
10+ releases in the last 90 days (latest 2026-08-24)
registry
dev.draugr/draugr (active, first published 2026-07-27 · 83 versions)
packages
mcpb:https://github.com/draugr-dev/draugr/releases/download/v0.106.0/draugr-0.106.0.mcpb

06 · Draugr FAQ

What is Draugr?

Describe your app. Draugr figures out the rest. Every application carries problems nobody put there on purpose: a library that turned out to have a hole in it, a password committed by accident, a server setting that leaves a door open. Draugr finds them, works out which ones actually matter for your app, and answers the question you are really asking before a release - is this safe to ship?

Is Draugr still maintained?

Yes - as of 2026-08-25, its last commit was 2026-08-24 and it shipped 10+ releases in the last 90 days. We re-verify nightly.

07 · Alternatives to Draugr

More security MCP servers · DSers Official MCP Server · ZAP Server · Toolmesh · Reolink MCP · Zzop

More Go MCP servers · Office Addin MCP · Pituitary · Yutu · Go Model · see all