Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
dns_reconA

Passive DNS/WHOIS reconnaissance for a domain using only public data.

Args: domain: The domain to inspect, e.g. "example.com". checks: Which checks to run. Any of "records", "whois", "email". Defaults to all three when omitted. timeout: Per-query network timeout in seconds.

Returns: A structured dict keyed by the requested checks: - records: DNS records grouped by type (A, AAAA, MX, NS, TXT, SOA, CNAME) - whois: parsed registration fields plus the raw WHOIS text - email: SPF / DMARC / DKIM posture, plus advisory MTA-STS, TLS-RPT, BIMI, and DNSSEC signals, with a graded assessment

tls_checkA

Inspect a host's SSL/TLS configuration and grade it.

Checks the certificate (validity, expiry, key algorithm), supported protocol versions (flagging legacy SSLv3/TLS 1.0/1.1), cipher suites and forward secrecy, TLS compression, HSTS, OCSP stapling, and known protocol vulnerabilities. Returns a letter grade plus structured findings.

Args: host: Hostname or IP to inspect, e.g. "example.com". port: TLS port (default 443). timeout: Per-connection network timeout in seconds.

Returns: A structured dict with: grade, certificate, protocols, cipher info, forward_secrecy, hsts, vulnerabilities, and a findings list.

http_headers_auditA

Audit a web server's HTTP security response headers and grade them.

Inspects headers such as Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the COEP/COOP/CORP isolation headers. Returns a letter grade plus per-header findings with recommendations.

Args: host: Hostname or IP to audit, e.g. "example.com". port: TCP port. Defaults to 443 when use_ssl is True, else 80. use_ssl: Connect over HTTPS (default True). timeout: Per-connection network timeout in seconds.

Returns: A structured dict with: grade, score, the observed headers, and a findings list.

port_scanA

TCP connect scan of a single host, reporting open ports and services.

Scoped to a single host with a hard cap of 1024 ports per call — it is recon for one authorized target, not a mass scanner. Only scan hosts you own or have explicit permission to assess.

Args: host: Hostname or IP to scan, e.g. "example.com". ports: Ports to scan as a string: "22,80,443", a range "1-1024", or a mix "1-100,443,8080". Omit to scan a built-in set of common ports. timeout: Per-port connection timeout in seconds.

Returns: A dict with: host, ip, scanned (count), open_count, and open_ports (each with port and service). Returns an error field on bad input or DNS failure.

subdomain_enumA

Discover subdomains of a domain via DNS brute-force and/or CT logs.

Two complementary sources:

  • "dns": probe candidate labels with DNS A lookups (active but light, capped at 512 candidates). Returns resolved IPs.

  • "ct": query public Certificate Transparency logs (crt.sh) for every name ever certified for the domain — fully passive, and finds real hosts no wordlist would guess.

  • "both": run both and merge, marking which source saw each host.

Enumerate only domains you are authorized to assess.

Args: domain: The base domain, e.g. "example.com". wordlist: Comma-separated labels for the DNS source (e.g. "www,api,dev"). Omit to use a built-in list of common labels. Ignored for "ct". source: "dns" (default), "ct", or "both". timeout: Per-query DNS timeout in seconds (the CT query uses its own longer timeout since crt.sh can be slow).

Returns: A dict with domain, sources, found_count, and found (each with subdomain, the source(s) that saw it, and resolved ips when known).

well_known_auditA

Fetch and parse a host's security.txt and robots.txt.

Both are standard public files. security.txt (RFC 9116) gives the vulnerability-disclosure contact, policy, and encryption key; its absence is itself a finding for a security-conscious site. robots.txt lists the paths the operator asks crawlers to skip — frequently admin/internal areas worth noting during recon.

Args: host: Hostname to inspect, e.g. "example.com". timeout: Per-request network timeout in seconds.

Returns: A dict with host, security_txt (present flag, parsed fields, structural issues, location), and robots_txt (present flag, sitemaps, disallow/allow paths, user_agents).

cookie_auditA

Follow a host's redirect chain and audit the cookies it sets.

Walks each redirect hop (capped at 10) from the host, recording status and Location and flagging any HTTPS->HTTP downgrade. Every Set-Cookie seen along the way is checked for the Secure, HttpOnly, and SameSite flags and graded. Cookie values are never returned (they may be secrets).

Args: host: Hostname to inspect, e.g. "example.com". port: TCP port. Defaults to 443 when use_ssl is True, else 80. use_ssl: Start the chain over HTTPS (default True). timeout: Per-hop network timeout in seconds.

Returns: A dict with host, redirect_chain, final_url, cookies (flags only), cookie_grade, cookie_score, and a findings list.

ip_infoA

Resolve a host and enrich its IP with RDAP registry ownership data.

Looks up the IP in the public RDAP registry (via rdap.org's bootstrap to the right RIR) and reports who owns the address block, the country, the CIDR range, and the abuse-reporting contact. Read-only registry query; nothing is sent to the target.

Args: host: Hostname or IP, e.g. "example.com". timeout: Per-request network timeout in seconds. Defaults high because rdap.org's bootstrap redirect can take 10-15s on its own.

Returns: A dict with host, ip, and rdap (handle, name, country, cidr, org, abuse_email). An unresolved host or RDAP failure is reported via an error field.

cors_checkA

Probe a host's CORS policy with a crafted Origin and flag misconfigurations.

Sends one GET with an untrusted Origin header and inspects the Access-Control-Allow-Origin / -Allow-Credentials response. Reflecting an arbitrary Origin while allowing credentials is high severity (any site can read authenticated responses); a wildcard or a trusted 'null' origin are lesser issues. One request, read-only.

Args: host: Hostname to test, e.g. "example.com". port: TCP port. Defaults to 443 when use_ssl is True, else 80. use_ssl: Connect over HTTPS (default True). timeout: Network timeout in seconds.

Returns: A dict with host, port, test_origin, acao, allows_credentials, reflects_origin, wildcard, severity, and a findings list.

subdomain_takeoverA

Check subdomains for a dangling-CNAME takeover risk.

A subdomain is takeover-prone when it CNAMEs to a third-party service (GitHub Pages, S3, Heroku, Azure, ...) whose resource was deleted or never claimed — anyone who registers that resource then controls the subdomain. For each host this resolves the CNAME, recognizes known takeover-prone services, fetches the page, and flags the provider's "unclaimed resource" fingerprint and/or a CNAME target that no longer resolves.

Read-only recon (DNS lookups + one HTTP GET per host). Pair it with subdomain_enum: enumerate first, then pass the interesting hosts here. Only check domains you are authorized to assess.

Args: hosts: One hostname or a comma-separated list, e.g. "blog.example.com,shop.example.com". Capped at 100 per call. timeout: Per-probe network timeout in seconds.

Returns: A dict with checked, vulnerable_count, and results (one entry per host with host, cname, service, status, vulnerable, severity, and detail). status is one of not_applicable, not_vulnerable, potential, dangling_cname, or vulnerable.

http_methods_auditA

Audit which HTTP request methods a server allows and grade the risk.

Enabled write/diagnostic methods widen the attack surface: TRACE enables Cross-Site Tracing (XST), and PUT / DELETE can allow file upload or deletion under weak access control. This is read-only and never sends a mutating request: it actively probes only OPTIONS, HEAD, and TRACE (TRACE merely echoes the request); PUT, DELETE, PATCH, and CONNECT are read from the OPTIONS Allow header and reported as advertised, never invoked.

Args: host: Hostname to audit, e.g. "example.com". port: TCP port. Defaults to 443 when use_ssl is True, else 80. use_ssl: Connect over HTTPS (default True). path: Request path to test (default "/"). timeout: Network timeout in seconds.

Returns: A dict with host, url, grade, score, allow_header, advertised_methods, trace_enabled, dangerous_methods, and a findings list. An error field on fetch failure.

tech_detectA

Fingerprint the technology stack behind a website from one HTTP GET.

Passively identifies the web server, reverse proxy / CDN, WAF, programming language, web framework, CMS, JavaScript framework, and analytics by matching response headers, set cookies, the HTML body, and the meta-generator tag against a signature table. Disclosed versions are captured and flagged (a precise version eases known-CVE lookup). One read-only HTTP GET.

Args: host: Hostname to fingerprint, e.g. "example.com". port: TCP port. Defaults to 443 when use_ssl is True, else 80. use_ssl: Connect over HTTPS (default True). timeout: Network timeout in seconds.

Returns: A dict with host, url, status, technology_count, technologies (each with name, category, version when known, and evidence), and a findings list noting any version disclosure. An error field on fetch failure.

recon_reportA

One-shot security posture report for a domain.

Runs DNS/email, TLS, HTTP-header, web-stack (tech_detect), and apex subdomain-takeover recon concurrently and returns a single graded overview: an overall grade (as weak as the weakest component, and capped at F if a live takeover is found), each component's grade, the actionable issues found, the detected technology stack, and any takeover risk. Use this for a quick full picture; call the individual tools for raw detail.

Args: domain: The domain to assess, e.g. "example.com". timeout: Per-connection network timeout in seconds.

Returns: A dict with domain, ip, overall_grade, summary, components (email / tls / headers, each with a grade and issues), a tech section (detected technologies + any version disclosure), and a takeover section when the apex is at risk. A check that errors is reported without breaking the rest.

Prompts

Interactive templates invoked by user choice

NameDescription
security_reconGuided full security reconnaissance of a domain, summarized by severity.

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.4/5.0

Scored across 13 tools

Disambiguation5/5

Each tool maps to a distinct reconnaissance technique — IP ownership, port scanning, DNS records/WHOIS, TLS, HTTP security headers, cookies, CORS, HTTP methods, subdomain enumeration, takeover checks, tech detection, well-known files, and the aggregate report — so misselection risk is low. The several *_audit tools are clearly differentiated by target (headers, cookies, methods, well-known files).

Naming Consistency4/5

Names are uniformly lower_snake_case and mostly follow a predictable `<target>_<operation>` pattern (port_scan, dns_recon, tls_check, cookie_audit). A few entries use noun-like suffixes (ip_info, recon_report, subdomain_takeover) rather than a strict verb, so the convention is consistent but not perfectly uniform.

Tool Count5/5

Thirteen tools is well within the ideal size for a security-recon server; every tool covers a distinct phase or technique and none feels redundant. This scope comfortably supports both targeted checks and the aggregate one-shot report.

Completeness4/5

The server covers the main recon lifecycle: discovery, DNS/WHOIS/email checks, TLS and HTTP posture, subdomain enumeration/takeover, tech fingerprinting, and a summary report. It omits deeper optional techniques such as banner grabbing, directory brute-forcing, and web vulnerability scanning, but those are reasonable workarounds rather than blocking gaps.

Maintenance

ActivityMaintained
ResponsivenessNo issues