Skip to main content
Glama
76,938 servers. Updated
20 Best GitHub MCP Servers — compared and ranked, August 2026Ranked from 1,620 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"Exploring AI Tools and Resources on GitHub" matching MCP servers:

  • A
    license
    C
    quality
    C
    maintenance
    Community MCP server for the Cymulate security validation platform. It exposes the full Cymulate REST API (337 endpoints) as 106 semantic tools for BAS, exposure validation, attack surface management, and platform administration.
    100
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    MCP server for AI-driven VAPT orchestration, enabling agents to plan and execute authorized security scans through a control plane that enforces scope, sanitization, budget, rate limits, human approval, and audit logging.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Integrates 7 security tools (nmap, nuclei, dirsearch, sqlmap, hydra, Acunetix, Metasploit) via MCP protocol for AI-assisted penetration testing with enterprise-grade safety features.
    1
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables natural-language-driven security testing by orchestrating multiple pen-testing tools through MCP, with automated scan execution and AI-assisted vulnerability summarization.
  • F
    license
    Not graded
    quality
    F
    maintenance
    An MCP server that integrates various penetration testing tools, enabling security professionals to perform reconnaissance, vulnerability scanning, and API testing through natural language commands in compatible LLM clients like Claude Desktop.
    7
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server that integrates multiple security and reconnaissance tools (Nmap, Cariddi, ParamSpider, Metasploit, web scraping) for AI systems, enabling automated network scanning, API discovery, vulnerability testing, and remote access via ngrok.
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    A production-ready HTTP API server for security testing and reconnaissance, integrating nmap, cariddi, paramspider, metasploit, and web scraping via FastAPI. It supports optional ngrok tunneling and exposes tools through REST endpoints.
    Apache 2.0
  • F
    license
    Not graded
    quality
    B
    maintenance
    Exposes a hardened Docker container with Kali Linux security tools (nmap, sqlmap, dig, whois, etc.) as MCP tools, enabling network reconnaissance, web analysis, and vulnerability scanning through natural language commands.
  • F
    license
    Not graded
    quality
    B
    maintenance
    Provides security tools (prompt injection detection, CVE lookup, version impact assessment) for MCP clients like Claude.