Skip to main content
Glama

Related Servers

Alternatives to PentestMCP

No user-submitted related servers found.

    Related Servers

    • F
      license
      B
      quality
      C
      maintenance
      Enables LLMs to perform automated penetration testing and Active Directory reconnaissance through Mythic, with tools for executing PowerShell, AD recon, domain user enumeration, and Kerberoasting.
      12
      -
    • A
      license
      C
      quality
      C
      maintenance
      Enables AI agents to orchestrate 25+ security tools for penetration testing through natural language, automating scans, vulnerability detection, and report generation.
      31
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Enables AI agents to orchestrate 100+ security tools over MCP for authorized penetration testing, including recon, scanning, exploitation, attack-chain planning, and knowledge-base retrieval.
      5
      Apache 2.0
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables Active Directory enumeration and abuse operations through the bloodyAD tool. Supports LDAP queries, user/group management, DNS operations, and security testing directly from AI assistants.
      16
      MIT
    • A
      license
      Not graded
      quality
      D
      maintenance
      Integrates 7 security tools (nmap, nuclei, dirsearch, sqlmap, hydra, Acunetix, Metasploit) via MCP protocol for AI-assisted penetration testing with enterprise-grade safety features.
      1
      MIT

    TDQS

    C2.4/5.0

    Scored across 26 tools

    Disambiguation3/5

    The tools cover distinct pentesting tasks like ASREPRoast, Kerberoast, and nmap scanning, but there is significant overlap between some tools. For example, dump_ntds_dit and dump_sam_hashes both handle credential dumping with similar descriptions, and check_module/check_options/use_module form a confusing workflow that could lead to misselection. Descriptions help clarify, but the boundaries are not always clear.

    Naming Consistency2/5

    Naming is highly inconsistent with mixed conventions: some use snake_case (bloodhound_ingest), others use camelCase (ASREPRoast), and some are verbose (get_project_directory_files). There is no predictable pattern across the set, making it hard for agents to infer tool purposes from names alone. This inconsistency reduces usability and coherence.

    Tool Count2/5

    With 26 tools, the count is excessive for a single server, leading to a bloated and overwhelming interface. Many tools could be consolidated (e.g., the multiple hash-dumping and module-checking tools). This heavy toolset will likely confuse agents and increase the risk of misselection, detracting from the server's effectiveness.

    Completeness4/5

    The toolset provides comprehensive coverage for pentesting workflows, including reconnaissance (nmap scans), exploitation (module usage), credential attacks (ASREPRoast, Kerberoast), and data analysis (Bloodhound integration). Minor gaps exist, such as lacking tools for post-exploitation cleanup or reporting, but agents can work around these with the available tools for most attack scenarios.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues