Skip to main content
Glama
step-security

stepsecurity-mcp

Official

Related Servers

Alternatives to stepsecurity-mcp

No user-submitted related servers found.

    Related Servers

    • A
      license
      A
      quality
      A
      maintenance
      MCP server for Cursor that scans codebases for security issues including hardcoded secrets, SAST, vulnerable dependencies, and IaC misconfigurations.
      7
      MIT
    • A
      license
      C
      quality
      D
      maintenance
      MCP server for ArmorCode security platform enabling finding triage, scans, exceptions, risk scores, and release gate checks via natural language.
      37
      13 npm
      MIT
    • F
      license
      Not graded
      quality
      C
      maintenance
      MCP server for Legit Security that answers questions about security issues, Actions, inventory, posture, and platform usage across one or multiple tenants.
      -
    • F
      license
      Not graded
      quality
      D
      maintenance
      MCP server that enables generating SBOMs, scanning for CVEs, and checking license compliance in VS Code via natural language with GitHub Copilot.
      -
    • A
      license
      Not graded
      quality
      C
      maintenance
      MCP server that provides AI coding assistants with access to call graphs, data flows, and security analysis for multi-file vulnerability detection.
      139
      Apache 2.0

    TDQS

    A4/5.0

    Scored across 30 tools

    Disambiguation4/5

    Tools are generally distinct but the many detection listing tools (e.g., list_anomalous_network_calls, list_blocked_domain_calls, list_https_outbound_calls, list_suspicious_process_events) could cause confusion despite descriptive names. Overlap is minimal due to specific filters.

    Naming Consistency5/5

    All tool names follow a consistent verb_noun snake_case pattern (e.g., list_anomalous_network_calls, create_suppression_rule). No mixing of conventions or abbreviations, making the pattern predictable.

    Tool Count4/5

    30 tools is high but justified for a security monitoring server covering incident response, suppression rules, detection listing, and package exposure. The scope is broad, but each tool has a clear purpose and the count is not excessive given the domain.

    Completeness4/5

    The tool surface covers detection management, threat incident analysis, package exposure (CI and dev machines), and suppression rules. Minor gaps exist, such as a generic 'list all detections' tool or user management, but core workflows are well-covered.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues