Skip to main content
Glama
78,133 servers. Updated
20 Best GitHub MCP Servers — compared and ranked, August 2026Ranked from 1,416 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"A server that reviews GitHub pull requests or provides diffs" matching MCP servers:

  • F
    license
    Not graded
    quality
    C
    maintenance
    This server enables AI agents to delegate GitHub pull request diffs for automated security auditing, returning structured vulnerability and architecture feedback while routing requests through a resilient multi-provider fallback pipeline.
  • A
    license
    A
    quality
    C
    maintenance
    MCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.
    7
    29
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    MCP server that provides AI-native access to BeVigil's OSINT API, enabling mobile app security research and asset discovery through tools for hosts, subdomains, S3 buckets, URLs, wordlists, and multi-step investigations.
    6
    7
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A minimal, dependency-free MCP server that gives AI agents three real, read-only security-orchestration tools: cve_lookup, shodan_host_lookup, and nuclei_scan.
    3
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables comprehensive security reconnaissance, vulnerability assessment, and threat intelligence gathering by integrating Shodan's API. It provides tools for searching internet-connected devices, performing DNS operations, and querying the Shodan exploit database.
    11
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    MCP server that enables LLMs to operate Acunetix/Invicti web vulnerability scanners through 15 tools, covering authentication, target management, scanning, vulnerability retrieval, and reporting via GraphQL and REST APIs.
    15
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Provides AI agents with 37 OSINT tools and 12 data sources to perform unified reconnaissance, domain analysis, and attack surface mapping. It enables agents to query, correlate, and reason across platforms like Shodan, VirusTotal, and Censys in parallel.
    37
    681
    44
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A comprehensive reconnaissance toolset that provides AI agents with 37 tools across 12 data sources like Shodan and VirusTotal for automated intelligence gathering. It enables agents to perform domain reconnaissance, attack surface mapping, and cross-platform data correlation within a single conversational interface.
    37
    681
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    A self-contained stdio JSON-RPC 2.0 server that brings AI capabilities to any MCP client, primarily for Pentool, enabling tasks like picking checks, bypassing WAF, and finding non-obvious endpoints.
    3
    1
    AGPL 3.0
  • A
    license
    B
    quality
    D
    maintenance
    Provides access to Shodan API functionality, enabling AI assistants to query information about internet-connected devices for cybersecurity research and threat intelligence.
    23
    47
    MIT
  • F
    license
    C
    quality
    D
    maintenance
    Provides access to 20+ Kali Linux penetration testing tools through isolated Docker containers, enabling network scanning, vulnerability assessment, password cracking, web security testing, and forensics through natural language commands.
    26
    1
  • A
    license
    D
    quality
    D
    maintenance
    Integrates Snyk security scanning with MCP clients like Claude Code, enabling listing of projects, querying issues by severity, and filtering by project or scope.
    3
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Provides AI coding assistants with real-time security scanning superpowers, including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment.
    18
    Apache 2.0