Skip to main content
Glama
70,205 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"An overview of Supabase" matching MCP servers:

  • A
    license
    A
    quality
    A
    maintenance
    Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.
    6
    718
    36
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables out-of-band interaction testing by integrating ProjectDiscovery's interactsh service as an MCP server. Allows AI agents to create callback domains, send probes, and capture DNS/HTTP interactions for security testing and verification workflows.
    4
    15
    3
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    An MCP security toolkit that integrates Burp-style HTTP proxying, AI-driven vulnerability hunting, source code auditing, and reporting into AI coding agents, enabling authorized security testing of web applications and source code.
    24
    MIT
  • A
    license
    B
    quality
    C
    maintenance
    Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.
    8
    MIT
  • A
    license
    C
    quality
    C
    maintenance
    A deliberately vulnerable MCP server for practicing exploitation of tool poisoning, command injection, and path traversal. Includes fixed versions and an agent demo to reproduce the issues in a controlled environment.
    2
    MIT
  • A
    license
    C
    quality
    D
    maintenance
    An automated penetration testing framework that enables intelligent security assessments through reconnaissance, vulnerability scanning, and controlled exploitation. Features AI-driven workflow management with comprehensive reporting for authorized security testing.
    27
    6
    7
    BSD 3-Clause
  • A
    license
    C
    quality
    D
    maintenance
    An AI-powered penetration testing reasoning engine that provides automated attack path planning, step-by-step guidance for CTFs/HTB challenges, and tool recommendations using Beam Search and MCTS algorithms.
    1
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    Provides AI coding assistants with real-time security scanning superpowers, including SAST, secrets detection, dependency CVE scanning, and web vulnerability assessment.
    159
    Apache 2.0
  • A
    license
    -
    quality
    D
    maintenance
    Enables running Kali Linux security tools and commands in a containerized environment for semi-automated penetration testing, with background job management and out-of-band interaction detection.
    16
    Apache 2.0
  • A
    license
    -
    quality
    B
    maintenance
    Read-only observation of a single live URL: parses static HTML to report security posture, forms, links, accessibility signals, and leaks, with described fixes. SSRF-gated and safe, never executes JavaScript.
    97
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    Automatically generates pocsuite3-compliant POC (Proof of Concept) code from vulnerability information, with built-in safety features to prevent harmful payloads and ensure secure security testing.
    2
    MIT