Skip to main content
Glama
94,522 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Files formatted in JSON" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to perform passive security scans on domains, checking email spoofing (DMARC/SPF/DKIM), TLS weaknesses, security headers, exposed files, and subdomain-takeover risk without needing an API key.
    7
    77 npm
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that lets an AI agent probe a live URL and confirm whether sensitive files (e.g., .git, .env, source maps) are genuinely served by fetching and validating the content, avoiding false positives.
    2
    18 npm
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables users to scan MCP servers for security threats, check installed servers, and analyze config files for risks, all from AI assistants like Claude, Cursor, or Windsurf.
    5
    10 npm
    4
    -
  • A
    license
    A
    quality
    D
    maintenance
    GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check.
    4
    54 npm
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Connects an AI assistant to an already-running mitmweb session so it can read, search, diff, replay, and generate code from the same network flows shown in the UI.
    10
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables AI coding agents to search a security corpus, scan Terraform plan JSON for cited findings, and list sources via MCP tools grounded in CIS AWS Foundations and OWASP Top 10 CI/CD risks.
    3
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Security scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.
    55
    160 npm
    6
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    An MCP server that enables AI assistants to analyze Android APK and iOS IPA files for security issues through natural language conversation, including permission auditing, secret detection, and SDK enumeration.
    12
    17 npm
    5
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server exposing LIEF for cross-format binary analysis, enabling parsing, section listing, imports/exports, disassembly, and string extraction for PE, ELF, MachO, DEX, ART, and OAT files.
    17
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Provides an MCP interface to a full Kali Linux environment running in Docker, enabling AI assistants to execute security tools like nmap, sqlmap, and metasploit. It allows users to start/stop the container, run shell commands, and transfer files for security testing and educational purposes.
    7
    13 npm
    5
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Connects AI assistants to AttackForge's Self-Service API with full endpoint coverage, response size optimization, and local caching for efficient use in long conversations.
    11
    -
  • A
    license
    A
    quality
    B
    maintenance
    A self-contained stdio JSON-RPC 2.0 server that brings AI capabilities to any MCP client, primarily for Pentool, enabling tasks like picking checks, bypassing WAF, and finding non-obvious endpoints.
    3
    1
    AGPL 3.0