Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MCPSENTINEL_MCP_JUDGENoOptional judge setting for MCP-native scans: 'heuristic' (default), 'openai', or 'auto'.
MCPSENTINEL_RULES_PATHNoOptional path to a custom rules JSON file.
MCPSENTINEL_POLICY_PATHNoOptional path to a policy JSON file.
MCPSENTINEL_ALLOWED_HOSTSYesComma-separated allowlist of hosts (or host:port) that the MCP server is permitted to scan. HTTP targets not in this list are rejected.
MCPSENTINEL_MCP_JUDGE_MODELNoOptional model name for the OpenAI judge, e.g., 'gpt-4o-mini'.
MCPSENTINEL_MCP_BASELINE_DIRNoOptional directory for baseline and judge cache storage.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
scan_mcp_serverA

Enumerate metadata from an operator-allowlisted HTTP MCP server and return static, semantic, and baseline security findings. Dynamic tool invocation is never performed and baselines are never approved from this MCP-native interface.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.7/5.0

Scored across 1 tool

Disambiguation5/5

With only a single tool, there is no possibility of confusion or misselection; scan_mcp_server has one unambiguous purpose.

Naming Consistency5/5

The lone name follows a clean verb_noun convention (scan_mcp_server), establishing a predictable pattern that any future tools could follow.

Tool Count3/5

A single tool is thin even for a narrow security-scanning scope; there is no companion tool for listing targets, retrieving past results, or managing baselines.

Completeness3/5

It covers enumeration and static/semantic/baseline scanning, but the description itself admits baseline approval is unavailable and there is no way to list servers or fetch prior results, leaving notable gaps.

Maintenance

ActivityMaintained
ResponsivenessNo issues