Skip to main content
Glama
momoaftabi

qa-sec-scan-mcp-server

by momoaftabi

Related Servers

Alternatives to qa-sec-scan-mcp-server

No user-submitted related servers found.

    Related Servers

    • F
      license
      Not graded
      quality
      C
      maintenance
      Enables AI agents to locally parse and analyze HAR files through read-only MCP tools, including searching requests, discovering endpoints, tracing values, detecting auth and API patterns, comparing requests, and exporting redacted cURL commands.
      -
    • A
      license
      Not graded
      quality
      D
      maintenance
      Scan APIs for security vulnerabilities and get OWASP risk scores. Detects auth bypass, BOLA/IDOR, data exposure, prompt injection, and 12+ security categories.
      24 npm
      Apache 2.0
    • A
      license
      Not graded
      quality
      B
      maintenance
      Audits HAR captures locally with MCP tools for triage, findings, vendor blast radius, CSP generation, and sanitization—no network calls, redacted by default.
      42 npm
      1
      MIT
    • A
      license
      Not graded
      quality
      Not graded
      maintenance
      Enables security scanning of code projects to identify common vulnerabilities like XSS, injections, SSRF, and path traversal issues. Provides local, offline scanning with severity-grouped results and actionable fix suggestions for improving code security.
      38 npm
      -
    • A
      license
      Not graded
      quality
      B
      maintenance
      Enables local, persistent analysis of business workflows and application state from imported Burp XML or HAR traffic, building actor/entity/state graphs and generating testable hypotheses for manual validation during authorized security testing.
      MIT

    TDQS

    A4.4/5.0

    Scored across 1 tool

    Disambiguation5/5

    With a single tool there is no risk of overlap or misselection. secscan_scan_har is precisely described as a passive HAR security scanner, making its purpose unmistakable.

    Naming Consistency5/5

    The tool name follows a clear snake_case verb_object convention with a consistent secscan_ prefix. Having only one tool means there are no conflicting naming patterns to confuse agents.

    Tool Count3/5

    One tool is at the low end of the scale and the server name suggests a broader security-scanning purpose, so the surface feels thin. That said, the single tool is substantial and not trivial, so it is borderline rather than severely undersized.

    Completeness4/5

    For the described passive HAR-scanning domain, the tool covers the full input-analysis-output flow with a useful format option. The only potential gap is the absence of additional scan types or live-traffic scanning, but those are explicitly outside the tool's stated scope.

    Maintenance

    ActivityMaintained
    ResponsivenessNo issues