Skip to main content
Glama

Related Servers

Alternatives to mcp-server-malcolm

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      C
      maintenance
      A governed MCP server for digital-forensics and incident-response (DFIR) work, exposing curated forensic tools (Volatility 3, Plaso, RegRipper, etc.) through a single FastMCP HTTP endpoint with bearer-token authentication and tamper-evident audit logging.
      MIT
    • F
      license
      Not graded
      quality
      B
      maintenance
      Enterprise MCP server for Google SecOps (Chronicle) SIEM/SOAR, enabling alert triage, UDM telemetry search, YARA-L detection rule management, log ingestion, and parser administration via Streamable HTTP.
      -
    • A
      license
      Not graded
      quality
      C
      maintenance
      A universal MCP server for registering internal, external, and OpenAPI-based APIs as MCP tools. It exposes them to MCP clients via Streamable HTTP and provides admin portal, RBAC/session auth, credential injection, and audit logging.
      Academic Free v1.1
    • A
      license
      Not graded
      quality
      D
      maintenance
      This repository implements an MCP (Model Connector Plugin) server for NetBox with full CRUD capabilities, search, and changelog retrieval.
      Apache 2.0
    • A
      license
      A
      quality
      A
      maintenance
      Local-first MCP proxy with BM25 tool discovery, quarantine security, Docker isolation, OAuth support, activity logging, and web UI. Routes multiple upstream MCP servers through a single endpoint.
      9
      379
      MIT

    TDQS

    A4.1/5.0

    Scored across 51 tools

    Disambiguation3/5

    The 51 tools cover many overlapping search and aggregation paths (arkime_sessions vs malcolm_search vs search_dsl, arkime_unique vs malcolm_field_values). Each tool has a documented niche, but the sheer number of similar query tools creates selection ambiguity. Some pairs like malcolm_alerts and malcolm_alerting_alerts are explicitly differentiated, but names alone don't make their distinct roles obvious.

    Naming Consistency4/5

    Most tools follow a consistent `<prefix>_<noun>` pattern (malcolm_*, arkime_*), and related tools share stems (arkime_session_*, malcolm_field_*, malcolm_alerting_*). However, there is no consistent verb_noun convention: some are verbs (search_dsl, list_indices), some are nouns (arkime_spigraph, malcolm_ping), and mixed styles like malcolm_saved_objects vs malcolm_dashboard_export exist.

    Tool Count2/5

    51 tools is far beyond the typical well-scoped count; it reflects a very broad read-only API surface. While each tool fills a niche, the number creates cognitive load and suggests insufficient consolidation (e.g., many Arkime field-analysis variants, multiple file/hash retrieval tools).

    Completeness3/5

    The surface covers read-only querying well: search, aggregation, status, field discovery, file metadata, dashboards, alerts, anomalies, NetBox. But write operations are missing entirely, despite descriptions referencing tools like malcolm_create_alert, arkime_create_view, and arkime_create_hunt that are not present. This creates dead ends when an agent needs to create or modify resources.

    Maintenance

    ActivityActive
    ResponsivenessSlow