Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
check_scopeA

Check whether target is authorized in scope.yaml before running any red-team tool.

nmap_scanC

Run an nmap scan against target (profile: quick|full_tcp|service|udp). Refuses if target not in scope.yaml.

gobuster_dirC

Directory-brute-force url with gobuster. Refuses if the host is not in scope.yaml.

nikto_scanB

Run a nikto web vulnerability scan against target:port. Refuses if target not in scope.yaml.

hydra_bruteforceA

Credential brute-force target/service with hydra using local userlist/passlist files. Requires confirm=True as an explicit double opt-in, and target must be in scope.yaml.

audit_listening_portsA

List listening ports (ss -tulnp) cross-referenced with firewall rules on this local host.

audit_suid_world_writableA

Find SUID and world-writable files under paths (default /usr /etc /opt /home) on this local host.

review_auth_logC

Summarize sshd auth log entries on this local host since since.

lint_ssh_configA

Check sshd_config at path against a baseline hardening ruleset on this local host.

list_installed_toolsA

Inventory installed BlackArch security-tool packages, grouped by category (recon, exploitation, cracking, etc.).

audit_pacman_packagesA

Report orphan packages, available updates, and package integrity via pacman (read-only) on this local host.

crack_hash_offlineB

Run an offline password-strength audit with hashcat/john against a hash file placed in data/hashes/.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.3/5.0

Scored across 12 tools

Disambiguation4/5

Most tools have clearly distinct purposes: scanning (nmap, nikto, gobuster), credential attacks (hydra), local auditing (audit_*, lint_*, review_*), and offline cracking (crack_hash_offline). However, check_scope is a utility tool that could be considered overlapping with the scope checks built into other tools, but it serves as a proactive check rather than a reactive refusal.

Naming Consistency3/5

The naming pattern mixes styles: verbs like 'check_', 'nmap_scan', 'gobuster_dir', and 'hydra_bruteforce' use a tool_name format, while others like 'audit_listening_ports' and 'review_auth_log' use verb_noun. The category for local auditing tools is consistent, but the overall set lacks a single unified pattern.

Tool Count4/5

12 tools is a reasonable count for a security auditing server covering reconnaissance, brute-forcing, local system auditing, and offline cracking. It's slightly high but each tool has a specific role, and no tool feels redundant. The scope is well-defined for a BlackArch-oriented toolset.

Completeness3/5

The toolset covers external scanning, web vulnerability scanning, brute-forcing, local host auditing, and password cracking. However, there are gaps: no network sniffing, exploitation, or privilege escalation tools, and no reporting or logging of results. For a comprehensive security assessment suite, these missing capabilities could hinder an agent's workflow.

Maintenance

ActivitySlowing
ResponsivenessNo issues