Skip to main content
Glama

Related Servers

Alternatives to mcp-semclone

No user-submitted related servers found.

    Related Servers

    • A
      license
      A
      quality
      B
      maintenance
      Enables AI coding agents to audit Python and npm dependency licenses against your distribution context before shipping, returning CLEAN, REVIEW, or BLOCK verdicts with plain-language reasons and supporting notice generation.
      3
      1
      MIT
    • A
      license
      A
      quality
      D
      maintenance
      Enables AI assistants to perform vulnerability scanning on Docker/OCI images, check CVE details, analyze licenses, and compare scan results via ScanRook.
      8
      8 npm
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables automated security code auditing using LLM and MCP, including AST parsing, taint analysis, dataflow tracing, and automated PoC generation for multi-language codebases.
      1
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Enables AI agents to run deterministic, fully local static security and compliance audits of code, configurations, and dependencies through 32 MCP tools covering 24 vulnerability categories. It also detects the project stack, generates risk reports and checklists, suggests stack-aware remediations, and re-validates fixes to confirm vulnerabilities were eliminated.
      1
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables AI coding agents to scan a project's real dependency tree against a declared shipping intent (e.g. hosted closed-source SaaS) and return contextual license alerts with package paths, rule IDs, and assumptions. Also explains the highest-priority findings, shows resolved license evidence, and updates the shipping intent before rescanning.
      1
      MIT
    • A
      license
      B
      quality
      D
      maintenance
      Allows developers to query security findings (SAST issues, secrets, patches) using natural language within AI-assisted tools like Claude Desktop, Cursor, and other MCP-compatible environments.
      17
      9
      MIT

    TDQS

    A3.9/5.0

    Scored across 14 tools

    Disambiguation5/5

    Every tool has a clearly distinct purpose. While generate_legal_notices and generate_legal_notices_from_purls are similar, their descriptions explicitly differentiate them by input method and use case, preventing confusion. All other tools target unique aspects of compliance analysis.

    Naming Consistency4/5

    Tool names predominantly follow a verb_noun pattern (e.g., scan_directory, validate_policy), but there is minor inconsistency: some use hyphens (check_license_compatibility) while others use underscores consistently, and verbs vary (analyze, check, generate, scan, validate). Overall, the pattern is predictable and readable.

    Tool Count5/5

    With 14 tools, the server covers a comprehensive compliance workflow—from scanning and package analysis to license validation, legal notice generation, and SBOM creation. Each tool serves a clear role without redundancy, and the count is well-scoped for the domain.

    Completeness5/5

    The tool surface covers the entire lifecycle: scanning (source, binary), package analysis (simple and deep), license checks (details, obligations, compatibility), risk assessment, policy validation, legal notices (source and PURL-based), SBOM generation, and an end-to-end compliance workflow. No significant gaps are apparent.

    Maintenance

    ActivitySlowing
    ResponsivenessUnresponsive