Skip to main content
Glama
dewhush
by dewhush

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
logging
{}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}

Tools

Functions exposed to the LLM to take actions

NameDescription
subdomain_enumC

Passive subdomain enumeration for a domain.

dns_resolveC

Resolve DNS records for a host.

http_probeC

Probe hosts for live HTTP(S) services.

tech_detectC

Fingerprint web technology behind a URL (httpx tech-detect).

waf_detectC

Detect a WAF/CDN in front of a URL from headers and response body.

origin_bypass_checkA

Check whether a WAF-protected host resolves directly to its origin IP.

If the A record lands outside known WAF/CDN ranges, the origin is exposed and the WAF can be bypassed by hitting that IP with a spoofed Host header.

wayback_discoverB

Pull historical URLs for a host from the Wayback Machine.

port_scanC

nmap top-N port scan of a host.

endpoint_discoverC

Fuzz common paths on a URL with ffuf.

nuclei_scanC

Run nuclei templates against a target.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.4/5.0

Scored across 10 tools

Disambiguation4/5

Most tools target distinct phases of reconnaissance (enumeration, probing, detection, scanning). Slight overlap exists between tech_detect and waf_detect, both analyzing URL response characteristics, and between http_probe and port_scan in service discovery, but descriptions clarify boundaries.

Naming Consistency5/5

All tool names follow a consistent snake_case noun_verb pattern (tech_detect, port_scan, dns_resolve, etc.), making the set highly predictable and readable.

Tool Count5/5

10 tools is well-scoped for a reconnaissance toolkit, covering the essential discovery, fingerprinting, and scanning operations without redundancy or bloat.

Completeness4/5

The set covers subdomain enumeration, DNS resolution, port scanning, HTTP probing, technology/WAF detection, origin bypass checks, historical URL discovery, endpoint fuzzing, and vulnerability scanning. Minor gaps include whois/ASN lookups or SSL/TLS inspection, but core recon workflows are well supported.

Maintenance

ActivityMaintained
ResponsivenessNo issues