Skip to main content
Glama

Related Servers

Alternatives to contrastapi

  • A
    license
    A
    quality
    A
    maintenance
    MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.
    7
    227
    165
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    A MCP server for querying the VirusTotal API. This server provides tools for scanning URLs, analyzing file hashes, and retrieving IP address reports.
    11
    301
    149
    MIT

Related Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    Vulnerability intelligence for AI agents that enables CVE lookup, package vulnerability checks, and dependency auditing without API keys.
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Domain security reconnaissance for AI agents — 13 tools (DNS+DNSSEC, SSL/TLS, HTTP security headers, SPF/DKIM/DMARC email auth, port scan, ASN, RDAP/WHOIS) plus a one-shot security_scan returning a 0–100 Health Score (A–F). Free, no API key.
    15
    86
    1
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Provides real-time threat intelligence for AI agents, enabling checks on IPs, domains, URLs, hashes, CVEs, prompt-injection payloads, and malicious AI-skill/MCP-tool definitions against a free database of 890K+ IOCs.
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    Provides real-time vulnerability intelligence including CVE lookup, EPSS exploit probability, and CISA KEV status from free APIs, enabling AI assistants to prioritize CVEs by real-world risk.
    MIT

TDQS

A4.4/5.0

Scored across 55 tools

Disambiguation4/5

Most tools have distinct, well-scoped purposes (e.g., cve_lookup vs cve_search vs bulk_cve_lookup), but there is overlap between contrastapi functions like domain_report and audit_domain, and between ioc_lookup and threat_intel which both cover reputation data. The tech_stack_cve_audit tool is redundantly described as 'MCP-only' yet has no REST counterpart, creating mild confusion about the API surface.

Naming Consistency4/5

The majority of tools follow a consistent `<domain>_<action>` convention (cve_lookup, cve_search, domain_report, asn_lookup, etc.), making the surface approachable. However, there are exceptions like contrastapi-specific names (contrastapi_get_domain) and some tools lack the clear action suffix (cve_search vs cve_lookup), introducing minor inconsistency.

Tool Count4/5

55 tools is a large number but the domain (CVE/recon) is broad enough to warrant a substantial surface. There is some redundancy—for example, domain_report, audit_domain, and separate lookup tools overlap in functionality—but the count remains justified by the breadth of the security-recon domain.

Completeness5/5

The tool surface covers the full vulnerability-research workflow: discovery (cve_search, cve_lookup), enrichment (exploit_lookup, kev), and response (bulk_cve_lookup). There is comprehensive coverage of related domains including email verification, phone lookup, IP/ASN, URL scanning, malware scanning, and AI-related scanning (ai_* tools). The missing pieces would be things like a true Q&A-style chat loop, but for a security API, this is near-complete.

Maintenance

ActivityActive
ResponsivenessResponsive