Skip to main content
Glama

Penetration Testing

Tools and frameworks for security testing, vulnerability scanning, and penetration testing. Enables security professionals to identify and exploit security weaknesses in applications and networks.

MCP ServersBrowse all →

  • A
    license
    A
    quality
    D
    maintenance
    MCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.
    7
    37 npm
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Exposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.
    3
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables MCP-native multi-agent security audits for Google Antigravity, orchestrating subagents for 0day research, static analysis, PoC verification, exploit chaining, reporting, and code remediation.
    6
    15
    3
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    This server enables AI-assisted APK reverse-engineering entirely on-device, orchestrating jadx, apktool, adb, frida, and APKiD through a job/workflow engine, and exposing those agents as native MCP tools for Claude without any cloud dependency.
    38
    20
    8
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables AI coding assistants to scan projects for security issues such as leaked API keys, missing Supabase RLS, open Firebase rules, unauthenticated routes, and hallucinated packages, then fix and verify the results.
    8
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Provides passive OSINT reconnaissance for domains and IPs using public sources, with tools for WHOIS/RDAP, DNS, subdomain enumeration, Wayback Machine, HTTP headers, Shodan InternetDB, email security, TLS certificates, and ASN lookups, all without requiring API keys.
    2
    11
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    A comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.
    51
    110 npm
    24
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    This local MCP server keeps vulnerability intelligence, research scope, scanner results, evidence receipts, Bugcrowd VRT assessments, and report drafts in one SQLite ledger. It is built for authorized defensive research and does not scan, exploit, or submit reports.
    19
    1
    MIT
  • A
    license
    B
    quality
    F
    maintenance
    A security testing tool that enables automated vulnerability detection including XSS and SQL injection, along with comprehensive browser interaction capabilities for web application penetration testing.
    3
    12
    204 npm
    22
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Enables AI assistants to perform vulnerability scanning using Grype, supporting scans of directories, container images, and packages via the Model Context Protocol.
    9
    9
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    MCP server that exposes 31 OSINT checks from Lissy93/web-check as tools for website analysis, including SSL, DNS, headers, WHOIS, and security presets. Enables natural-language-driven web recon and health checks.
    18
    8
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables plain-English website security checks from an MCP client, offering tools to assess site findings, explain individual issues, and list all available security checks.
    3
    236 npm
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Open behavioral litmus for MCP servers — grades A–F across tool-output injection, egress, sensitive-data, and adversarial-input, with reproducible, content-addressed evidence. Tools: run_litmus, verify_attestation.
    4
    269 npm
    8
    Apache 2.0
  • A
    license
    A
    quality
    D
    maintenance
    Enables AI assistants to execute security testing tools on a Kali Linux machine over SSH, including reconnaissance, web app scanning, and static/dynamic analysis.
    11
    11 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables Android APK reverse engineering and Flutter runtime injection through a six-step pipeline of decompile, analyze, synthesize, inject, patch, and repackage. Provides MCP tools for authorized security research and penetration testing.
    2
    9
    43 npm
    5
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Connects MCP clients to pre-submission review that argues against a draft bug-bounty report or smart-contract finding the way a triager would, tying every claim to a supplied file and line and returning a submit, rewrite-then-submit, prove-first, hold-duplicate or drop verdict. Exposes tools to list review profiles, prepare reviews for the agent's own model, build hash-verified review packets, and — with a connection token — run hosted profiles on your own provider key.
    6
    1
    MIT

MCP ConnectorsBrowse all →