Skip to main content
Glama
91,234 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Companies Building Using MCP" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    Not graded
    quality
    C
    maintenance
    Lets MCP-compatible AI clients read your getdebug projects, findings, and proposed fixes using your existing bearer token.
    3 npm
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Scans MCP servers for security vulnerabilities, prompt injection, and tool poisoning, providing risk scores and protection.
    4
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables network security scanning using Nmap through MCP protocol. Supports quick port scans, full port scans with service detection, and custom Nmap commands with async task management.
    3
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables automated security code auditing using LLM and MCP, including AST parsing, taint analysis, dataflow tracing, and automated PoC generation for multi-language codebases.
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Fully automated MCP server built to communicate with JADX-AI-MCP Plugin to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.
    1
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    A harness for building test MCP servers that reproduce common attack patterns, enabling detection evaluation via streaming HTTP or stdio.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI assistants to query Microsoft Defender XDR telemetry for read-only threat hunting, incident triage, and vulnerability discovery using delegated per-user authentication and production guardrails.
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables permission-preserving access to DefectDojo OSS via MCP, using the caller's own API token, with read tools, deterministic analytics and reporting, plus optional gated write and history tools.
    2
    AGPL 3.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI-powered security scanning of codebases through conversational analysis, allowing users to assess, threat model, code review, DAST test, and generate security reports using natural language with Claude.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables local, persistent analysis of business workflows and application state from imported Burp XML or HAR traffic, building actor/entity/state graphs and generating testable hypotheses for manual validation during authorized security testing.
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to perform reconnaissance tasks using the reconFTW framework, supporting full, passive, subdomain, vulnerability, and OSINT scans through MCP tools.
    22
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    An MCP server that enables AI models to perform Android dynamic analysis using Frida, including spawning and attaching to applications, listing apps, and injecting scripts.
    121
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables network scanning and security assessment using Nmap through MCP, allowing AI assistants to perform port scans, service detection, and network reconnaissance on specified targets with configurable scan parameters.
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    Simulates sensitive internal tools as a honeypot to detect unauthorized access and AI agent behaviors using Canarytokens, deployed as a serverless Cloudflare Worker with MCP protocol support.
    21
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    An LLM-powered vulnerability auditor for MCP servers that catches semantically-equivalent attacks by using a local LLM grounded by retrieval against known attack patterns.
    -
  • A
    license
    A
    quality
    B
    maintenance
    Query Microsoft Patch Tuesday security updates from the official MSRC API — monthly rollups, CVE/KB lookups, supersedence chains, and urgency-ranked triage enriched with EPSS scores and the CISA KEV catalog. No API keys required.
    1
    4
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that scans local codebases for quantum-vulnerable cryptography (secp256k1, Ed25519, RSA, etc.) and CI signing commands, classifying each finding as quantum-broken, post-quantum, or neither. It runs entirely locally with no network calls, providing a deterministic inventory for AI agents.
    4
    503 PyPI
    Apache 2.0