Skip to main content
Glama
93,505 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"API for Framer design tool" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    Not graded
    quality
    B
    maintenance
    MCP server that detects and guards against tool poisoning and prompt injection attacks in tool descriptions and schemas. It provides risk scoring, pattern detection, safe rewriting, and audit reports with zero external API cost.
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    MCP security firewall (stdio): vet advertised tool definitions through static-scan → threat-feed → origin → pinning before they reach the model. Zero npm runtime deps. No secrets.
    6
    307 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables Android APK reverse engineering and Flutter runtime injection through a six-step pipeline of decompile, analyze, synthesize, inject, patch, and repackage. Provides MCP tools for authorized security research and penetration testing.
    2
    9
    43 npm
    5
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Agent-native "safe to ship?" security gate for AI-generated code. Uses real parsers and inter-rocedural taint analysis (JS/TS, Python, Go) to flag the classes AI coding agents get wrong — secrets, SQL injection, SS, SSRF, path traversal, command injection, weak JWT/CORS — and ranks findings by confidence. Exposes a scan tool over MCP.
    1
    10 npm
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables AI coding assistants to scan projects for security issues such as leaked API keys, missing Supabase RLS, open Firebase rules, unauthenticated routes, and hallucinated packages, then fix and verify the results.
    8
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Open behavioral litmus for MCP servers — grades A–F across tool-output injection, egress, sensitive-data, and adversarial-input, with reproducible, content-addressed evidence. Tools: run_litmus, verify_attestation.
    4
    137 npm
    8
    Apache 2.0
  • A
    license
    A
    quality
    D
    maintenance
    GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check.
    4
    54 npm
    MIT
  • F
    license
    A
    quality
    C
    maintenance
    Provides a generic HTTP client tool allowing AI agents to make arbitrary HTTP requests from their environment, with support for environment-variable placeholders for secrets.
    1
    -
  • A
    license
    A
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for interacting with the Intigriti bug bounty platform's Researcher API. It enables AI assistants to manage bug bounty programs, submissions, and research workflow.
    8
    4
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables agents and CI pipelines to audit MCP servers and agent tool-chains by statically scanning repositories, local checkouts, tools/list exports, or live endpoints for risks such as destructive actions without confirmation, mismatched safety annotations, injection surfaces, credential or PII exposure, and unguarded command, path, or URL sinks. All checks are read-only and never execute the scanned code or call tools/call.
    3
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables users to retrieve and display CVE vulnerability information from the National Vulnerability Database (NVD) with support for keyword search and detailed lookup.
    2
    12 npm
    4
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI assistants and agents to search bug bounty programs, retrieve policies and scopes, and check targets against active scope across HackerOne, YesWeHack, and Intigriti using personal API credentials.
    5
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables interaction with Picus Security's Breach & Attack Simulation API, allowing natural language queries for simulations, threat library searches, and agent management through MCP-compatible clients.
    23
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Scans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.
    5
    MIT