Skip to main content
Glama
76,044 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"An overview of REST (Representational State Transfer)" matching MCP servers:

  • A
    license
    A
    quality
    D
    maintenance
    Connects AI assistants to Solodit's 49,000+ blockchain vulnerability database, enabling search, browse, and lookup of audit findings directly from your AI workflow.
    4
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Provides an MCP interface to a full Kali Linux environment running in Docker, enabling AI assistants to execute security tools like nmap, sqlmap, and metasploit. It allows users to start/stop the container, run shell commands, and transfer files for security testing and educational purposes.
    7
    8
    3
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    MCP server that enables LLMs to operate Acunetix/Invicti web vulnerability scanners through 15 tools, covering authentication, target management, scanning, vulnerability retrieval, and reporting via GraphQL and REST APIs.
    15
    1
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables out-of-band interaction testing by integrating ProjectDiscovery's interactsh service as an MCP server. Allows AI agents to create callback domains, send probes, and capture DNS/HTTP interactions for security testing and verification workflows.
    4
    35
    3
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    An MCP security toolkit that integrates Burp-style HTTP proxying, AI-driven vulnerability hunting, source code auditing, and reporting into AI coding agents, enabling authorized security testing of web applications and source code.
    24
    MIT
  • F
    license
    A
    quality
    Not graded
    maintenance
    Enables management of penetration testing reports and vulnerabilities through a REST API, supporting CVSS 3.1 scoring, HTML formatting, and secure JWT authentication for comprehensive security assessment documentation.
    9
    3
  • A
    license
    B
    quality
    C
    maintenance
    Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.
    8
    MIT
  • A
    license
    C
    quality
    C
    maintenance
    A deliberately vulnerable MCP server for practicing exploitation of tool poisoning, command injection, and path traversal. Includes fixed versions and an agent demo to reproduce the issues in a controlled environment.
    2
    MIT
  • A
    license
    C
    quality
    C
    maintenance
    Community MCP server for the Cymulate security validation platform. It exposes the full Cymulate REST API (337 endpoints) as 106 semantic tools for BAS, exposure validation, attack surface management, and platform administration.
    100
    MIT
  • A
    license
    C
    quality
    D
    maintenance
    Enables AI agents to generate and manage specialized bug bounty hunting workflows including reconnaissance, vulnerability testing, OSINT gathering, and file upload testing. Provides REST API endpoints for comprehensive security assessments with intelligence-driven vulnerability prioritization.
    40
    2
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables running Kali Linux security tools and commands in a containerized environment for semi-automated penetration testing, with background job management and out-of-band interaction detection.
    16
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Read-only observation of a single live URL: parses static HTML to report security posture, forms, links, accessibility signals, and leaks, with described fixes. SSRF-gated and safe, never executes JavaScript.
    82
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Automatically generates pocsuite3-compliant POC (Proof of Concept) code from vulnerability information, with built-in safety features to prevent harmful payloads and ensure secure security testing.
    3
    MIT