Skip to main content
Glama
96,958 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Finding Financial Reports" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • F
    license
    A
    quality
    Not graded
    maintenance
    Enables management of penetration testing reports and vulnerabilities through a REST API, supporting CVSS 3.1 scoring, HTML formatting, and secure JWT authentication for comprehensive security assessment documentation.
    9
    3 npm
    -
  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that scans local codebases for quantum-vulnerable cryptography (secp256k1, Ed25519, RSA, etc.) and CI signing commands, classifying each finding as quantum-broken, post-quantum, or neither. It runs entirely locally with no network calls, providing a deterministic inventory for AI agents.
    5
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    Enables LLM agents to browse and triage vulnerability observations, manage products, branches and rules, import scan reports and SBOMs, run scans and background jobs, and generate VEX documents via SecObserve's REST API.
    18
    107 PyPI
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Connects MCP clients to pre-submission review that argues against a draft bug-bounty report or smart-contract finding the way a triager would, tying every claim to a supplied file and line and returning a submit, rewrite-then-submit, prove-first, hold-duplicate or drop verdict. Exposes tools to list review profiles, prepare reviews for the agent's own model, build hash-verified review packets, and — with a connection token — run hosted profiles on your own provider key.
    6
    2
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Lets MCP clients browse bug bounty programmes, manage reports, and triage issues on BugSecure with user-approved OAuth permissions, including read-only mode.
    33
    437 npm
    1
    Apache 2.0
  • A
    license
    A
    quality
    F
    maintenance
    Provides Claude Code with access to a comprehensive bug bounty knowledge base including techniques, payloads, wordlists, and real-world reports through 14 tools for searching, retrieving payloads, and assessing report quality.
    14
    20
    GPL 3.0
  • A
    license
    A
    quality
    D
    maintenance
    MCP server for DefectDojo vulnerability management, exposing 24 tools for managing products, engagements, tests, findings, scan imports, and finding lifecycle through the Model Context Protocol.
    24
    40 PyPI
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Bawbel MCP Server lets any agent scan MCP servers and skill files for security vulnerabilities mid-conversation. Seven tools covering server-card scanning, conformance scoring, rug pull detection, and AVE threat intelligence queries. Powered by the AVE standard with OWASP MCP Top 10 mapping on every finding. Free, Apache 2.0, no API key required.
    10
    36 PyPI
    2
    Apache 2.0
  • A
    license
    A
    quality
    D
    maintenance
    Scans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.
    5
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables AI assistants to perform reverse engineering and debugging of Windows executables through x64dbg, with tools for loading executables, controlling execution, analyzing memory and security, and generating reports.
    39
    107 npm
    6
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for the YesWeHack bug bounty platform that lets Claude query private and public programs, reports, and the hacktivity feed directly from a conversation.
    12
    1
    -
  • A
    license
    A
    quality
    C
    maintenance
    A read-only MCP server that lets an agent browse the HackerOne Hacker API using an authenticated hacker account, exposing programs, policies, scope, reports, and payments. It cannot create, update, or submit reports.
    15
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Safe, self-hosted OWASP ZAP operator for guided AI security scans, findings, and reports. Requires a separately running OWASP ZAP daemon.
    20
    67
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    This local MCP server keeps vulnerability intelligence, research scope, scanner results, evidence receipts, Bugcrowd VRT assessments, and report drafts in one SQLite ledger. It is built for authorized defensive research and does not scan, exploit, or submit reports.
    19
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables LLMs to conduct passive attack-surface research by collecting public information, referencing saved reports, and verifying evidence through MCP tools.
    6
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server that provides passive and low-impact active reconnaissance tools for authorized bug bounty and security assessments, enabling LLMs to perform structured recon and generate reports.
    11
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Enables read-only interaction with YesWeHack hunter accounts via MCP, allowing consultation of programs, scopes, reports, and credits using email/password/TOTP authentication.
    18
    3
    MIT