Skip to main content
Glama
95,285 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"An introduction to GraphQL" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to perform passive security scans on domains, checking email spoofing (DMARC/SPF/DKIM), TLS weaknesses, security headers, exposed files, and subdomain-takeover risk without needing an API key.
    7
    77 npm
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that lets an AI agent probe a live URL and confirm whether sensitive files (e.g., .git, .env, source maps) are genuinely served by fetching and validating the content, avoiding false positives.
    2
    18 npm
    1
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check.
    4
    54 npm
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    14 atomic MCP tools for AppSec and AI Security engineers: source/schema/prompt audit primitives, JWT inspect, HTTP diff, pentest atoms (default creds, GraphQL introspect, phpggc, interactsh OOB), and a defensive helpers library that fixes the bugs the detectors flag. SARIF output, PyPI Trusted Publishing with Sigstore provenance.
    14
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Connects an AI assistant to an already-running mitmweb session so it can read, search, diff, replay, and generate code from the same network flows shown in the UI.
    10
    2
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    A production-ready MCP server that wraps Nmap to enable AI agents to perform automated network security assessments, including port scanning, host discovery, service detection, OS fingerprinting, and vulnerability scanning.
    6
    16
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    Static security scanner for AI-generated (vibe-coded) Supabase and Next.js apps. Runs as an MCP server so an LLM can scan, explain findings, and produce fixes while it writes code, all locally and offline.
    5
    103 npm
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI assistants to scan websites, public repositories, and OpenClaw/CLAW skills for security vulnerabilities, including local skill-package analysis before installation, cloud scans, and remediation guidance.
    10
    51 npm
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables users to retrieve and display CVE vulnerability information from the National Vulnerability Database (NVD) with support for keyword search and detailed lookup.
    2
    33 npm
    4
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables Claude to scan a website's HTTP security headers and receive an A–F grade against OWASP best practices, including per-header pass/warn/fail results and copy-paste fixes for missing headers.
    1
    MIT
  • F
    license
    A
    quality
    C
    maintenance
    Exposes a pentest toolbox (sqlmap, nuclei, ffuf, etc.) via Docker to an LLM orchestrator for authorized security audits, with strict whitelisting and timeout controls.
    6
    -
  • A
    license
    A
    quality
    B
    maintenance
    Enables plain-English website security checks from an MCP client, offering tools to assess site findings, explain individual issues, and list all available security checks.
    3
    480 npm
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    MCP server that exposes 31 OSINT checks from Lissy93/web-check as tools for website analysis, including SSL, DNS, headers, WHOIS, and security presets. Enables natural-language-driven web recon and health checks.
    8
    MIT