Skip to main content
Glama
89,913 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Free APIs and services without commercial fees" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    A
    maintenance
    Domain security reconnaissance for AI agents — 13 tools (DNS+DNSSEC, SSL/TLS, HTTP security headers, SPF/DKIM/DMARC email auth, port scan, ASN, RDAP/WHOIS) plus a one-shot security_scan returning a 0–100 Health Score (A–F). Free, no API key.
    15
    70 npm
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to perform passive security scans on domains, checking email spoofing (DMARC/SPF/DKIM), TLS weaknesses, security headers, exposed files, and subdomain-takeover risk without needing an API key.
    7
    47 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A minimal, dependency-free MCP server that gives AI agents three real, read-only security-orchestration tools: cve_lookup, shodan_host_lookup, and nuclei_scan.
    3
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables coding agents to perform network diagnostics and lookups, including subnet calculations, port and MAC vendor information, DNS and blocklist checks, TLS certificate inspection, and public IP discovery, all without needing an account or sending telemetry.
    11
    MIT
  • F
    license
    A
    quality
    C
    maintenance
    Automates Android app analysis using Frida via AI commands, connecting a rooted Android phone to a computer and running dynamic analysis scripts without manual command execution.
    10
    16
    -
  • A
    license
    A
    quality
    A
    maintenance
    Enables interactive Ghidra reverse-engineering inside an AI client by rendering live decompiler, function browser, and call graph views. Users can click symbols to rename them and follow calls to navigate, all without leaving the conversation.
    10
    78 npm
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    MCP server that enables LLMs to operate Acunetix/Invicti web vulnerability scanners through 15 tools, covering authentication, target management, scanning, vulnerability retrieval, and reporting via GraphQL and REST APIs.
    15
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables any MCP-capable AI to headlessly launch and dynamically instrument Windows executables via IDA Pro's PIN tracer, with tools for breakpoints, register/memory access, execution control, and instruction tracing without opening the IDA GUI.
    15
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables guided security evaluation of a virtual lab machine, including network scanning, HTTP/TLS analysis, OWASP Top 10 assessment, and Markdown report generation, without performing exploitation.
    8
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    This server enables AI-assisted APK reverse-engineering entirely on-device, orchestrating jadx, apktool, adb, frida, and APKiD through a job/workflow engine, and exposing those agents as native MCP tools for Claude without any cloud dependency.
    6
    19
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables testing API authentication and authorization by probing endpoints with and without Authorization headers, suggesting auth test matrices for roles, and showing current test configuration.
    3
    ISC
  • A
    license
    B
    quality
    B
    maintenance
    Enables MCP-capable LLM agents to control YADS queues, manage tags, and trigger scans through YADS's API-authenticated /api/v1 interface without dashboard access. All actions respect tenant isolation and scan limits.
    31
    MIT
  • F
    license
    B
    quality
    C
    maintenance
    A security research MCP server for testing tool call safety with deterministic policies like allowlists, path boundary enforcement, SSRF prevention, output redaction, and prompt injection detection, without requiring external LLMs or API keys.
    6
    -
  • A
    license
    B
    quality
    C
    maintenance
    Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.
    8
    MIT