Skip to main content
Glama
zer0-kr

security-framework-mcp

by zer0-kr

Related Servers

Alternatives to security-framework-mcp

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      B
      maintenance
      An MCP server that automates vulnerability correlation across security tools like Checkmarx and Tenable, using LLMs to determine reachability, map compliance controls (SOC2, ISO27001), and generate remediation and regression testing patterns.
      MIT
    • A
      license
      A
      quality
      F
      maintenance
      A comprehensive security testing MCP server providing 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It enables automated security audits and technical investigations across web applications, cloud environments, and network captures.
      51
      36 npm
      23
      MIT
    • A
      license
      B
      quality
      C
      maintenance
      A comprehensive MCP server for structured threat modeling using STRIDE methodology, with automatic code validation and report generation.
      100
      103
      Apache 2.0
    • F
      license
      Not graded
      quality
      B
      maintenance
      MCP server for ConnectSecure vulnerability management, exposing 285 read-only tools to query assets, vulnerabilities, Active Directory, and more via natural language.
      -

    TDQS

    A3.7/5.0

    Scored across 41 tools

    Disambiguation5/5

    Each tool has a clearly distinct purpose, targeting specific data sources (e.g., OWASP, NIST, CVE) or actions (e.g., assess, search, map). Even with many similar 'get_' tools, the target differs explicitly (e.g., get_top10 vs get_api_top10 vs get_llm_top10). No two tools appear to do the same thing.

    Naming Consistency4/5

    The majority of tools follow a verb_noun pattern (e.g., get_asvs, search_cve, assess_mcp_security). However, a few tools like 'database_status' (noun_noun) break the pattern. The inconsistency is minor but present.

    Tool Count3/5

    With 41 tools, the server is well beyond the typical 3-15 range. While the comprehensive coverage of multiple security frameworks justifies the count, the number is high and could be streamlined. Some tools are very similar (e.g., multiple 'get_top10' variants), making the set feel oversized.

    Completeness5/5

    The tool set covers an exhaustive range of security frameworks and data sources: OWASP (Top 10, API, LLM, MCP, ASVS, MASVS, WSTG, CheatSheets, Proactive Controls, Projects), NIST (CSF, SP 800-53, RMF, PF, Glossary, Publications, CMVP, NICE), CVE/KEV, compliance mappings, threat modeling, and triage. No obvious gaps for its stated purpose.

    Maintenance

    ActivityInactive
    ResponsivenessNo issues