Skip to main content
Glama

Related Servers

Alternatives to mcp-security-toolkit

No user-submitted related servers found.

    Related Servers

    • A
      license
      A
      quality
      C
      maintenance
      14 atomic MCP tools for AppSec and AI Security engineers: source/schema/prompt audit primitives, JWT inspect, HTTP diff, pentest atoms (default creds, GraphQL introspect, phpggc, interactsh OOB), and a defensive helpers library that fixes the bugs the detectors flag. SARIF output, PyPI Trusted Publishing with Sigstore provenance.
      14
      MIT
    • A
      license
      Not graded
      quality
      C
      maintenance
      Enables enterprise MCP security auditing through 12 deterministic no-LLM tools for evidence-gated claims, skill/prompt supply-chain audits, token profiling, and server auth-mode checks.
      MIT
    • A
      license
      Not graded
      quality
      A
      maintenance
      npm audit for MCP servers. Point it at an MCP server and get a security grade (A–F) covering missing auth, SSRF surface, high-privilege tools, prompt-injection-prone tool descriptions, and leaked secrets.
      17 npm
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Passive security scanner that audits a running MCP server against the OWASP MCP Top 10 and grades it A-F. Read-only static analysis of the advertised tools, prompts and resources with console/JSON/SARIF output, and it also runs as an MCP server itself.
      59 npm
      MIT
    • A
      license
      Not graded
      quality
      A
      maintenance
      Audits MCP server configurations for security risks including capability inventory, SSRF, prompt injection, and drift detection. Works in read-only mode and can also be used as an MCP server to let AI agents audit their own attack surface.
      4
      MIT
    • A
      license
      Not graded
      quality
      B
      maintenance
      Security scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.
      19 npm
      2
      MIT

    TDQS

    A4.2/5.0

    Scored across 14 tools

    Disambiguation5/5

    Each tool has a clearly distinct purpose, from auditing agent tool schemas to generating PHP gadget chains. No two tools overlap in functionality or target domain.

    Naming Consistency5/5

    All tool names follow a consistent snake_case pattern with a domain-specific prefix (e.g., graphql_introspect, jwt_inspect, wordlist_gen), making them predictable and easy to distinguish.

    Tool Count5/5

    14 tools is a well-scoped collection for a security toolkit. Each tool serves a distinct purpose without redundancy, and the count is neither too small nor too large for the domain.

    Completeness3/5

    The toolkit covers a wide range of security utilities, but there are notable gaps for a generic security toolkit (e.g., no port scanning, exploitation beyond PHP gadget chains, or vulnerability scanning). The focus seems skewed toward MCP and LLM security, but the presence of generic tools like default_creds_lookup suggests a broader scope, which is not fully covered.

    Maintenance

    ActivityStale
    ResponsivenessNo issues