Skip to main content
Glama
86,452 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, September 2026Ranked from 1,553 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"Checking Supabase migrations in GitHub Actions" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • F
    license
    Not graded
    quality
    C
    maintenance
    This server enables AI agents to delegate GitHub pull request diffs for automated security auditing, returning structured vulnerability and architecture feedback while routing requests through a resilient multi-provider fallback pipeline.
    -
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to perform passive security scans on domains, checking email spoofing (DMARC/SPF/DKIM), TLS weaknesses, security headers, exposed files, and subdomain-takeover risk without needing an API key.
    7
    98 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check.
    4
    49 npm
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Connects an AI assistant to an already-running mitmweb session so it can read, search, diff, replay, and generate code from the same network flows shown in the UI.
    10
    2
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables agents and CI pipelines to audit MCP servers and agent tool-chains by statically scanning repositories, local checkouts, tools/list exports, or live endpoints for risks such as destructive actions without confirmation, mismatched safety annotations, injection surfaces, credential or PII exposure, and unguarded command, path, or URL sinks. All checks are read-only and never execute the scanned code or call tools/call.
    3
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Converts Claude into a cybersecurity assistant by exposing 17 tools for network reconnaissance, cryptography, and security analysis, enabling users to perform tasks like SSL certificate checking, port scanning, and JWT analysis directly within conversations.
    17
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Security scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.
    55
    87 npm
    5
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Adds security capabilities like port scanning, TLS inspection, DNS enumeration, process monitoring, secrets scanning, HTTP header auditing, and CVE checking to Claude Code and Cursor.
    23
    21 npm
    MIT
  • A
    license
    B
    quality
    B
    maintenance
    Enables MCP-capable LLM agents to control YADS queues, manage tags, and trigger scans through YADS's API-authenticated /api/v1 interface without dashboard access. All actions respect tenant isolation and scan limits.
    31
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    Provides AI agents with structured access to the OWASP Bug Logging Tool (BLT) ecosystem for logging bugs, triaging issues, and managing security workflows. It enables actions like submitting vulnerabilities, tracking contributor leaderboards, and awarding gamified bacon points through a unified interface.
    4
    9
    AGPL 3.0