Skip to main content
Glama
97,619 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"BNB Chain" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    B
    quality
    A
    maintenance
    Wraps the recon CLIs security researchers already use (subfinder, httpx, nmap, ffuf, nuclei) into a single MCP server so an LLM agent can plan and execute reconnaissance itself — passive subdomain/DNS/wayback discovery, active port scanning, WAF detection and origin-bypass checks, endpoint fuzzing, and nuclei scans. Structured JSON results carry scan tokens that let the agent chain one step's output into the next without re-typing targets.
    10
    1
    MIT
  • A
    license
    D
    quality
    C
    maintenance
    A Model Context Protocol server that integrates essential penetration testing tools (Nmap, Gobuster, Nikto, John the Ripper) into a unified natural language interface, allowing security professionals to execute and chain multiple tools through conversational commands.
    9
    106 npm
    147
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Audits AI agent skills for safety using static, semantic, adversarial, and supply-chain analysis, providing scores and risk flags. Can be run via CLI, CI, or as an MCP tool from Claude Code, Cursor, and Codex.
    2
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables LLM clients to conduct authorized penetration testing and CTF challenges through a multi-mode agent with evidence-chain anti-hallucination, skill evolution, and MCP tool orchestration.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    An offensive security dataset generator that creates high-quality, multi-turn penetration testing conversation datasets for fine-tuning security-focused LLMs. It enables users to generate realistic pentesting workflows featuring chain-of-thought reasoning, tool outputs, and over 45 diverse attack scenarios.
    102
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to orchestrate 100+ security tools over MCP for authorized penetration testing, including recon, scanning, exploitation, attack-chain planning, and knowledge-base retrieval.
    5
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Security scanner for MCP servers — vet an MCP before you wire it into an agent. Detects prompt-injection, credential exfiltration (via taint analysis), RCE, and supply-chain risks, and catches cross-server exfil chains no single server reveals. Zero-dependency local CLI, SARIF output, CI-gateable, no account.
    43 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables enterprise MCP security auditing through 12 deterministic no-LLM tools for evidence-gated claims, skill/prompt supply-chain audits, token profiling, and server auth-mode checks.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Authorized Android pentest lab, drivable by hand or by AI — Frida bypass chain, live traffic capture with automatic IDOR flagging, full MCP control plane, web dashboard.
    8
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    AI-native security testing platform with native MCP support, enabling automated penetration testing, vulnerability discovery, and attack-chain analysis through conversational commands.
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to call 93 pay-per-call machine-to-machine services spanning web scraping, crypto sentiment, market data, on-chain analytics, social and threat intelligence, vulnerability scanning, and micro-SaaS utilities. Payments are settled in USDC on Arbitrum via the x402 protocol using a wallet header, so no API keys, signups, or billing setup are required.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Reverse engineering against a running Windows process instead of the file on disk: memory reads, pattern and value scanning, disassembly of the code that actually executed, resolved IAT thunks, caller-chain tracing, and structure recovery. Complements the Ghidra and IDA servers rather than replacing them — correlate_addr maps a runtime address back to a module and RVA.
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Simulates the Deadbugz MCP supply-chain attack for educational and research purposes, demonstrating a 3-call gate evasion where tool descriptions mutate to steal credentials.
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    Exposes AI-augmented network reconnaissance and evasion capabilities as callable FastMCP tools, enabling natural language orchestration of host discovery, service fingerprinting, CVE mapping, and attack chain synthesis.
    1
    -