Skip to main content
Glama
81,811 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Finding a Programmer with MCP Certification" matching MCP servers:

GET /v1/servers — MCP directory API reference
  • A
    license
    A
    quality
    A
    maintenance
    An MCP server that scans local codebases for quantum-vulnerable cryptography (secp256k1, Ed25519, RSA, etc.) and CI signing commands, classifying each finding as quantum-broken, post-quantum, or neither. It runs entirely locally with no network calls, providing a deterministic inventory for AI agents.
    2
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Bawbel MCP Server lets any agent scan MCP servers and skill files for security vulnerabilities mid-conversation. Seven tools covering server-card scanning, conformance scoring, rug pull detection, and AVE threat intelligence queries. Powered by the AVE standard with OWASP MCP Top 10 mapping on every finding. Free, Apache 2.0, no API key required.
    10
    1
    Apache 2.0
  • A
    license
    A
    quality
    D
    maintenance
    MCP server for DefectDojo vulnerability management, exposing 24 tools for managing products, engagements, tests, findings, scan imports, and finding lifecycle through the Model Context Protocol.
    24
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    A self-contained stdio JSON-RPC 2.0 server that brings AI capabilities to any MCP client, primarily for Pentool, enabling tasks like picking checks, bypassing WAF, and finding non-obvious endpoints.
    3
    1
    AGPL 3.0
  • A
    license
    B
    quality
    A
    maintenance
    AI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.
    47
    41
    MIT
  • A
    license
    B
    quality
    B
    maintenance
    Enables authorized pentest and bug bounty workflows from any MCP client, with scoped recon, per-host rate limits, and scanner output turned into deduplicated, triaged finding cards.
    9
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    Provides a Model Context Protocol server implementation that allows AI agents and other MCP clients to programmatically interact with DefectDojo, a vulnerability management tool, for managing findings, products, and engagements.
    11
    15
    MIT
  • F
    license
    B
    quality
    C
    maintenance
    Enables users to query BloodHound Active Directory graph data using natural language, finding attack paths, Kerberoastable accounts, and other AD security insights.
    23
  • A
    license
    Not graded
    quality
    A
    maintenance
    Provides MCP clients like Claude with tools to query and manage security scans, CVEs, assets, findings, threat intel, and generate polished reports by acting as a lightweight adapter over the CVEasy backend API.
    2
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for integrating with StackHawk's security scanning platform. Helps developers set up StackHawk, run security scans, and triage findings to fix vulnerabilities — all from within an LLM-powered IDE or chat.
    9
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Manual listener MCP server that bridges OpenCode with local security tools via a Flask HTTP service, enabling AI-assisted security operations.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Bridges AI agents with SafeBreach's Breach and Attack Simulation platform, enabling natural language queries and seamless integration through a multi-server architecture with specialized domains.
    7
    BSD 3-Clause
  • A
    license
    Not graded
    quality
    D
    maintenance
    Scans MCP servers for security vulnerabilities, prompt injection, and tool poisoning, providing risk scores and protection.
    4
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A TypeScript MCP server delivering a vendored 'dangerous skills' corpus and adversarial fixtures over MCP for security-research testing, supporting SEP-2640 skill delivery with archive-safety hardening.
    2
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables running Kali Linux security tools and commands in a containerized environment for semi-automated penetration testing, with background job management and out-of-band interaction detection.
    17
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI-assisted penetration testing by connecting MCP clients to execute terminal commands on a Kali Linux machine, supporting tools like Nmap, Metasploit, and custom commands.
    MIT