Skip to main content
Glama
Ownership verified

Server Details

Protects AI coding agents from installing malicious open source packages. Every npm and PyPI package is checked against SafeDep’s real-time threat intelligence before installation.

Status
Unhealthy
Last Tested
Transport
Streamable HTTP
URL

Glama MCP Gateway

Connect through Glama MCP Gateway for full control over tool access and complete visibility into every call.

MCP client
Glama
MCP server

Full call logging

Every tool call is logged with complete inputs and outputs, so you can debug issues and audit what your agents are doing.

Tool access control

Enable or disable individual tools per connector, so you decide what your agents can and cannot do.

Managed credentials

Glama handles OAuth flows, token storage, and automatic rotation, so credentials never expire on your clients.

Usage analytics

See which tools your agents call, how often, and when, so you can understand usage patterns and catch anomalies.

100% free. Your data is private.
Tool DescriptionsA

Average 4.4/5 across 2 of 2 tools scored.

Server CoherenceA
Disambiguation5/5

The two tools have completely distinct purposes: check_package_security is a mandatory security gate for package installation, while ping is a connectivity test for the service. There is no overlap in functionality or potential for confusion between these tools.

Naming Consistency5/5

Both tools follow a consistent snake_case naming pattern with clear verb_noun structure: check_package_security and ping (where ping is a standard networking term that functions as both verb and noun). The naming is predictable and follows the same convention throughout.

Tool Count2/5

With only 2 tools, the server feels under-scoped for its apparent security-focused domain. While the check_package_security tool is comprehensive, a security service would typically offer additional capabilities like vulnerability scanning for existing dependencies, security policy management, or detailed reporting tools beyond just a connectivity check.

Completeness2/5

The tool surface is severely incomplete for a security-focused package dependency service. There's no way to scan existing dependencies, view security reports, manage policies, or perform post-installation security checks. The server provides only a pre-installation gate and connectivity test, leaving significant gaps in security workflow coverage.

Discussions

No comments yet. Be the first to start the discussion!

Related MCP Servers

  • A
    license
    A
    quality
    F
    maintenance
    Acts as a security checkpoint for AI coding agents by intercepting package installations to verify existence, check against CVE databases, and block vulnerable or hallucinated dependencies before they reach your codebase. Provides seven security tools including pre-install gates, full project audits, safe version recommendations, and deep transitive dependency scanning for npm and PyPI packages.
    Last updated
    7
    15
    4
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    Validates and checks packages across 19 ecosystems to prevent AI agents from installing hallucinated, deprecated, or malicious packages.
    Last updated
    70
    AGPL 3.0

View all MCP Servers

Try in Browser

Your Connectors

Sign in to create a connector for this server.

Resources