Skip to main content
Glama
86,485 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Design Resources and Prototyping Best Practices" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables Claude to scan a website's HTTP security headers and receive an A–F grade against OWASP best practices, including per-header pass/warn/fail results and copy-paste fixes for missing headers.
    1
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables LLM clients like Claude to interact with IDA Pro for binary analysis, decompilation, cross-references, patching, and more via 41 MCP tools, 8 resources, and 7 guided prompts.
    51
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI assistants to drive OWASP ZAP for authorized penetration testing and bug-bounty workflows, including authenticated scans and vulnerability triage through 67 curated safety-gated tools.
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Security auditor for MCP servers that enumerates tools, resources, and prompts, scans for injection patterns, classifies risk levels, and produces a scored report (0-100, grades A-F).
    2
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Passive security scanner that audits a running MCP server against the OWASP MCP Top 10 and grades it A-F. Read-only static analysis of the advertised tools, prompts and resources with console/JSON/SARIF output, and it also runs as an MCP server itself.
    85 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Security scanner for MCP servers. Detects prompt injection, command injection, auth bypass, and excessive permissions across tools, resources, and prompts.
    38 npm
    2
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Integrates ProjectDiscovery's Katana web crawler with Claude Desktop, enabling users to crawl websites, discover endpoints and hidden resources, extract JavaScript files, and perform reconnaissance with customizable depth, scope, and filtering options.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to control and analyze RFID hardware through natural language: read, crack, emulate, and clone cards via MCP tools, with safety gates, offline dump analysis, and a host-side card library.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI assistants to perform Volatility 3 memory forensics through natural language, including process and network analysis, injection detection, and shellcode extraction from memory dumps.
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server for Frida dynamic instrumentation, enabling AI agents to enumerate devices/processes, attach, inject JavaScript, hook functions, read memory, and collect results via MCP tools.
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables agents to operate ARL, ScopeSentry, and XingRin attack surface management platforms through stdio tools for listing resources, testing connections, creating/managing tasks, and retrieving assets.
    Apache 2.0
  • F
    license
    Not graded
    quality
    D
    maintenance
    A vulnerable-by-design MCP server pair (NotesServer and VaultServer) for testing MCP security tools, featuring confused-deputy, prompt injection, and authorization bypass scenarios.
    -
  • -
    license
    Not graded
    quality
    Not graded
    maintenance
    Enables ethical security testing and attack surface management through SSL certificate validation, CVE queries, subdomain enumeration, security header analysis, and comprehensive reconnaissance capabilities. Designed for authorized penetration testing workflows with responsible disclosure practices.
    -