Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
NVD_API_KEYNoAPI key for the National Vulnerability Database (NVD).
OTX_API_KEYNoAPI key for AlienVault OTX.
HIBP_API_KEYNoAPI key for Have I Been Pwned (HIBP).
SUPABASE_URLNoSupabase project URL (required for HTTP mode).
ABUSECH_API_KEYNoAPI key for abuse.ch.
ABUSEIPDB_API_KEYNoAPI key for AbuseIPDB.
X402_PAYEE_ADDRESSNoWallet address for x402 micropayments (required for HTTP mode).
SUPABASE_SERVICE_KEYNoSupabase service role key (required for HTTP mode).

Capabilities

Features and capabilities supported by this server

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
compliance_framework_checkC

Assess an organization's security posture against a compliance framework (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST CSF).

evidence_collectC

Generate evidence collection plans for compliance controls.

control_gap_analysisC

Deep-dive analysis of compliance control gaps with remediation roadmap.

audit_report_generateD

Generate audit-ready compliance reports.

policy_generateC

Generate tailored security policy documents.

vuln_scan_networkC

Scan an IP/domain for open ports, services, and vulnerabilities.

vuln_scan_web_appC

Scan a web app for OWASP Top 10 vulnerabilities.

vuln_prioritizeC

Prioritize vulnerabilities by exploitability and business impact.

cve_lookupC

Look up CVE details, CVSS scores, and patches.

ssl_tls_auditC

Audit SSL/TLS configuration for a domain.

sast_scanC

Static analysis for security vulnerabilities. Supports Python, JS/TS, Java, Go, Ruby, PHP, C/C++.

secret_scanC

Detect hardcoded secrets in source code.

dependency_auditC

Audit dependencies for known vulnerabilities (npm, pip, Go, Ruby, Java, Cargo).

incident_triageD

Classify and respond to security incidents.

threat_intel_lookupC

IOC lookup against threat intel feeds.

dns_security_checkB

Check DNS security (SPF, DKIM, DMARC, DNSSEC).

email_security_auditC

Comprehensive email security audit.

access_reviewC

Audit user access against least-privilege.

mfa_auditC

Assess MFA coverage and strength.

credential_checkC

Check email/domain in breach databases (HIBP).

vet_endpointA

Composite trust verdict (PROCEED/CAUTION/BLOCK) for an endpoint an agent is about to call or pay — combines TLS/cert health, DNS hygiene, threat-intel reputation, and domain age into one decision with reasons.

scan_mcp_pluginA

Scan an MCP server (git repo or code) for supply-chain risk BEFORE trusting it — exfiltration (secrets/env to the network), prompt-injection sinks, dangerous capabilities, npm install hooks, obfuscation, plus Semgrep + secret scanning → a PROCEED/CAUTION/BLOCK verdict with findings.

scan_skillA

Scan an agent SKILL (git repo or SKILL.md) for supply-chain risk BEFORE trusting it — prompt-injection / hidden-unicode in the instructions (hard block), over-broad allowed-tools grants, plus exfiltration, dangerous capabilities, secrets and obfuscation in bundled scripts → a PROCEED/CAUTION/BLOCK verdict.

account_balanceA

Returns the calling API key's prepaid balance, monthly limit, current month usage, and a breakdown of how many of each tool the customer can still afford. Free to call.

helpA

Returns AgentAegis FAQ — authentication, balance/billing, tool catalog, async jobs, error codes, x402, rate limits, security. Optional topic filter. Free to call.

agent_whoamiA

Returns your persistent AgentAegis agent identity (agent_id), how you're identified (API key / wallet / anonymous session), and lifetime call count + spend. Free to call.

agent_historyA

Lists your recent scans (scan_id, tool, target, status, time) so you can retrieve or chain from a prior result. Optional limit/tool/target/since filters. Free to call.

agent_scan_getA

Retrieves one of your prior scans by scan_id, including the stored full output, so you can build on earlier results without re-paying. Free to call.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/astafford8488/agentaegis-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server