Skip to main content
Glama
88,283 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Finding MCP servers with high ratings and no API key required" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    Not graded
    quality
    A
    maintenance
    Scan-as-a-Service for MCP servers. Wraps the compuute-scan static security scanner with HTTP and MCP endpoints to analyze public GitHub repos for MCP-specific vulnerabilities.
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Provides a disposable, hardened Kali Linux sandbox with an MCP interface for LLM-driven security analysis of REST APIs, confining blast radius via container isolation.
    -
  • A
    license
    B
    quality
    B
    maintenance
    Enables AI assistants to perform automated security audits on APIs, detecting BOLA/IDOR vulnerabilities by comparing responses across user tokens.
    11
    1
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    Enables security teams to run controlled adversarial penetration tests against authorized ML/LLM API endpoints, scoring responses and generating evidence for compliance frameworks such as SOC 2, ISO 27001, and GDPR.
    6
    2
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Exposes AI-augmented network reconnaissance and evasion capabilities as callable FastMCP tools, enabling natural language orchestration of host discovery, service fingerprinting, CVE mapping, and attack chain synthesis.
    1
    -
  • A
    license
    A
    quality
    A
    maintenance
    Query Microsoft Patch Tuesday security updates from the official MSRC API — monthly rollups, CVE/KB lookups, supersedence chains, and urgency-ranked triage enriched with EPSS scores and the CISA KEV catalog. No API keys required.
    1
    4
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Bawbel MCP Server lets any agent scan MCP servers and skill files for security vulnerabilities mid-conversation. Seven tools covering server-card scanning, conformance scoring, rug pull detection, and AVE threat intelligence queries. Powered by the AVE standard with OWASP MCP Top 10 mapping on every finding. Free, Apache 2.0, no API key required.
    10
    1
    Apache 2.0
  • A
    license
    C
    quality
    A
    maintenance
    Connects AI coding assistants to Snyk API & Web for onboarding scan targets, configuring authentication, running DAST scans, and triaging findings through natural language.
    51
    25 PyPI
    8
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Scans MCP servers for security vulnerabilities, prompt injection, and tool poisoning, providing risk scores and protection.
    4
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables certificate transparency log search via crt.sh, allowing users to query SSL/TLS certificates, enumerate subdomains, and retrieve certificate details with no API key required.
    BSD Zero Clause
  • A
    license
    Not graded
    quality
    A
    maintenance
    npm audit for MCP servers. Point it at an MCP server and get a security grade (A–F) covering missing auth, SSRF surface, high-privilege tools, prompt-injection-prone tool descriptions, and leaked secrets.
    12 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A security linter for MCP that audits other MCP servers for compliance with the MCP specification and OWASP security standards, providing detailed findings and remediation.
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Domain security reconnaissance for AI agents — 13 tools (DNS+DNSSEC, SSL/TLS, HTTP security headers, SPF/DKIM/DMARC email auth, port scan, ASN, RDAP/WHOIS) plus a one-shot security_scan returning a 0–100 Health Score (A–F). Free, no API key.
    15
    70 npm
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    MCP security firewall (stdio): vet advertised tool definitions through static-scan → threat-feed → origin → pinning before they reach the model. Zero npm runtime deps. No secrets.
    6
    95 npm
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables scanning of Claude Code skills, plugins, or MCP servers for malware before installation via static analysis.
    1
    6 npm
    MIT