Skip to main content
Glama

Related Servers

Alternatives to Spotter-SAST

No user-submitted related servers found.

    Related Servers

    • A
      license
      B
      quality
      D
      maintenance
      An MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.
      6
      MIT
    • A
      license
      A
      quality
      D
      maintenance
      MCP server that scans Salesforce Agentforce metadata for security vulnerabilities using 61+ SAST rules, integrating into AI coding workflows to guard against OWASP LLM top 10 risks.
      16
      18 npm
      Cryptographic Autonomy 1.0 (Combined Work Exception)
    • A
      license
      Not graded
      quality
      C
      maintenance
      MCP server that provides AI coding assistants with access to call graphs, data flows, and security analysis for multi-file vulnerability detection.
      139
      Apache 2.0
    • A
      license
      A
      quality
      D
      maintenance
      Unified MCP server integrating NIST and OWASP security frameworks with live vulnerability data, enabling security searches, compliance mapping, threat modeling, and checklist generation.
      41
      14
      MIT

    TDQS

    C2.7/5.0

    Scored across 23 tools

    Disambiguation2/5

    Several tools overlap or are redundant, especially legacy tools (auto_fix_file, generate_sast_report, scan_directory, scan_file) that are explicitly superseded. The compliance tools are numerous and have subtle distinctions, while the echo tool is unrelated to the domain. Agents may struggle to select the correct tool.

    Naming Consistency4/5

    Tool names predominantly follow a verb_noun convention using snake_case, e.g., ai_enhanced_auto_fix, collect_compliance_evidence. A few names start with a noun (compliance_analytics_dashboard) breaking the pattern slightly, but overall consistency is high.

    Tool Count3/5

    23 tools is high for a security scanner, especially with 4 legacy tools that could be removed. The domain (SAST + compliance) is broad, but the count feels slightly bloated. The echo tool seems unnecessary.

    Completeness4/5

    The tool set covers scanning, vulnerability info, reporting, compliance management, remediation, and monitoring. Minor gaps: no direct tool for user/team management, and legacy tools might cause confusion. Overall, core workflows are well-covered.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues