Skip to main content
Glama

Related Servers

Alternatives to MCP Shamash

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      D
      maintenance
      Enables comprehensive security scanning of code repositories to detect secrets, vulnerabilities, dependency issues, and configuration problems. Provides real-time security checks and best practice recommendations to help developers identify and prevent security issues.
      5 npm
      2
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Integrates authoritative security compliance frameworks (ISO 27001, NIST 800-53, OWASP ASVS, NIST SSDF) into AI-assisted development, offering control lookups, cross-framework mappings, build-time guardrails, and automated audit evidence generation.
      174 npm
      3
      MIT
    • F
      license
      Not graded
      quality
      C
      maintenance
      Enables local security scanning and compliance gap analysis for code and text, detecting secrets, PII, and OWASP vulnerabilities, and assessing readiness across major frameworks like NCA, ISO 27001, NIST CSF, and SOC 2.
      -
    • A
      license
      Not graded
      quality
      D
      maintenance
      Enables security scanning of codebases through integrated tools for secret detection, SCA, SAST, and DAST vulnerabilities, with AI-powered remediation suggestions based on findings.
      MIT
    • A
      license
      B
      quality
      D
      maintenance
      Universal AI security layer for code scanning, PII detection, prompt injection defense, secret detection, dependency auditing, and audit logging.
      27
      3
      Apache 2.0

    TDQS

    B3/5.0

    Scored across 7 tools

    Disambiguation4/5

    Most tools have distinct purposes targeting different security activities (compliance, remediation, rule management, false positives, pentesting, network scanning, project scanning), though 'scan_network' and 'scan_project' could potentially overlap in scope if network scanning is part of project scanning. The descriptions help clarify their boundaries, with only minor ambiguity.

    Naming Consistency4/5

    Tools follow a consistent verb_noun pattern throughout (e.g., check_compliance, generate_remediation, manage_custom_rules), with all using snake_case. The only deviation is 'pentest_application' which uses 'pentest' as a verb instead of a more standard verb like 'perform_pentest', but this is minor and still readable.

    Tool Count5/5

    With 7 tools, the count is well-scoped for a security-focused server, covering key areas like scanning, testing, compliance, and management. Each tool appears to earn its place without feeling too thin or bloated, fitting typical server tool ranges (3-15 tools).

    Completeness4/5

    The toolset provides good coverage for security operations, including scanning (network and project), testing (pentest), compliance validation, remediation generation, and rule/false positive management. Minor gaps might include tools for reporting results or integrating with external systems, but core workflows are well-covered and agents can likely work around these omissions.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues