Skip to main content
Glama
shyshlakov

pci-dss-mcp

by shyshlakov

Related Servers

Alternatives to pci-dss-mcp

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      A
      maintenance
      Scans self-hosted, multi-tenant AI-agent platforms for tenant-isolation gaps. Native Go MCP server exposing a scan tool that wraps the CLI's audit engine.
      Apache 2.0
    • A
      license
      A
      quality
      D
      maintenance
      Agent-native "safe to ship?" security gate for AI-generated code. Uses real parsers and inter-rocedural taint analysis (JS/TS, Python, Go) to flag the classes AI coding agents get wrong — secrets, SQL injection, SS, SSRF, path traversal, command injection, weak JWT/CORS — and ranks findings by confidence. Exposes a scan tool over MCP.
      1
      6 npm
      2
      MIT
    • A
      license
      A
      quality
      C
      maintenance
      An AppSec-focused MCP server that performs static analysis scans on C/C++ source code for memory-safety vulnerabilities and parses compiled PE/ELF binary headers locally to audit active defensive compiler mitigations (ASLR, DEP/NX, PIE).
      4
      1
      MIT
    • A
      license
      Not graded
      quality
      D
      maintenance
      Security scanning MCP server. Semgrep integration, SARIF parsing, baseline diffing, framework-aware ruleset selection, and automated finding triage.
      5 npm
      1
      MIT

    TDQS

    A4.6/5.0

    Scored across 15 tools

    Disambiguation5/5

    Each tool targets a distinct security check or utility: audit log coverage, authentication strength, data retention, dependencies, encryption, error handling, payment page scripts, secrets, TLS, requirement lookup, compliance report, SBOM, PAN data scan, triage, and vulnerability DB update. No two tools have overlapping purposes.

    Naming Consistency5/5

    Tool names follow a clear verb_noun pattern (e.g., check_*, generate_*, explain_*, update_*, scan_*, triage_). All use consistent snake_case, and the verb clearly indicates the action. The slight deviation of 'audit_log_coverage' is minor and still descriptive.

    Tool Count5/5

    15 tools is well-scoped for a PCI DSS compliance server. It covers a wide range of checks (authentication, encryption, secrets, etc.) plus utilities (SBOM, report, requirement lookup), without being excessive or too few.

    Completeness5/5

    The tool set comprehensively covers PCI DSS requirements relevant to Go source code and configuration, including authentication (8.3), data retention (3.2, 3.3), encryption (4.2, 6.2), error handling (6.2), TLS (4.2), secrets (8.6), dependencies (6.3), and software inventory (6.3). The triage and report tools tie everything together.

    Maintenance

    ActivityStale
    ResponsivenessNo issues