Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MCPFP_AUTHORIZEDYesSet to true to confirm you have permission (mandatory).
MCPFP_PORT_RANGENoOptional port range to scan.
MCPFP_REPORT_DIRNoOptional directory where Markdown reports are written.
MCPFP_TARGET_HOSTYesIP/host of the lab VM.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
load_target_infoA

Carga y valida el objetivo unico desde .env, confirmando autorizacion.

check_environmentA

Verifica que herramientas externas de reconocimiento estan instaladas.

scan_networkA

Descubre puertos y servicios del objetivo (nmap no intrusivo).

analyze_http_headersC

Evalua las cabeceras de seguridad HTTP del objetivo.

analyze_tlsB

Inspecciona el certificado y protocolo TLS del objetivo.

assess_owaspB

Fingerprinting web y mapeo pasivo a OWASP Top 10.

get_guidanceB

Guia pedagogica paso a paso (obvios / no obvios / siguiente paso).

Temas: reconocimiento, a01, a02, a05, a06, bandera.

write_reportB

Guarda hallazgos en un reporte Markdown en el directorio de invocacion.

Prompts

Interactive templates invoked by user choice

NameDescription
metodologiaMetodologia de abordaje siguiendo OWASP e ISO 27001 (sin explotacion).

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.6/5.0

Scored across 8 tools

Disambiguation5/5

Each tool targets a distinct stage or concern: target setup, environment checks, network scanning, HTTP header analysis, TLS inspection, OWASP mapping, guidance, and reporting. Even the two analyze tools are clearly separated by layer, so no agent should confuse one tool for another.

Naming Consistency5/5

All tool names follow a consistent snake_case verb_noun pattern: load_, check_, scan_, analyze_, assess_, get_, and write_. The verb clearly signals the action and the noun signals the target, making the naming predictable and easy to extend.

Tool Count5/5

Eight tools is a well-scoped set for a reconnaissance and OWASP assessment workflow. Each tool has a clear responsibility and no tool feels redundant or extraneous.

Completeness5/5

The workflow is complete for the stated passive-assessment and pedagogical purpose: it covers target validation, environment readiness, network discovery, HTTP/TLS inspection, OWASP mapping, guidance, and report generation. There are no obvious dead ends or missing core operations.

Maintenance

ActivityMaintained
ResponsivenessNo issues