Skip to main content
Glama
97,619 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, October 2026Ranked from 1,788 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"GitHub Actions" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables LLMs to access realtime CVE intelligence aggregated from NVD, CISA KEV, EPSS, GitHub advisories, PoC discovery, and Metasploit/Nuclei tooling, providing vulnerability details, exploitation signals, and prioritized triage verdicts.
    12
    14 npm
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to drive live Hack The Box labs through the real HTB Labs API — spawning, resetting and extending machines, submitting user and root flags with difficulty ratings, browsing challenges, and switching or downloading VPN configurations for the authenticated account. Every call hits the live API rather than cached content, with destructive actions annotated so hosts can gate them behind consent.
    22
    297 npm
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables agents and CI pipelines to audit MCP servers and agent tool-chains by statically scanning repositories, local checkouts, tools/list exports, or live endpoints for risks such as destructive actions without confirmation, mismatched safety annotations, injection surfaces, credential or PII exposure, and unguarded command, path, or URL sinks. All checks are read-only and never execute the scanned code or call tools/call.
    3
    MIT
  • A
    license
    B
    quality
    B
    maintenance
    Enables MCP-capable LLM agents to control YADS queues, manage tags, and trigger scans through YADS's API-authenticated /api/v1 interface without dashboard access. All actions respect tenant isolation and scan limits.
    31
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    Provides AI agents with structured access to the OWASP Bug Logging Tool (BLT) ecosystem for logging bugs, triaging issues, and managing security workflows. It enables actions like submitting vulnerabilities, tracking contributor leaderboards, and awarding gamified bacon points through a unified interface.
    4
    9
    AGPL 3.0
  • A
    license
    B
    quality
    C
    maintenance
    Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.
    8
    MIT
  • A
    license
    B
    quality
    C
    maintenance
    Enables AI agents to query and act on Microsoft Defender XDR incidents, alerts, advanced hunting data, Entra ID logs, threat indicators, device response actions, and vulnerability management via Microsoft Graph and Defender for Endpoint APIs.
    66
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Scan-as-a-Service for MCP servers. Wraps the compuute-scan static security scanner with HTTP and MCP endpoints to analyze public GitHub repos for MCP-specific vulnerabilities.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables an AI agent to perform authorized penetration testing through raw HTTP interaction, Python scripting, and shell commands, while providing an authorization wrapper to keep actions within an approved engagement context.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A proof-of-concept tool that integrates AI into security operations, allowing users to perform offensive security tasks like network scanning and reconnaissance through natural language commands to GitHub Copilot.
    5
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    An MCP server for agent authorization that tests the full effect surface and enforces control over consequential actions before dispatch, emitting verifiable execution evidence.
    2
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    MCP server that integrates with ARXsec.io API to execute security scans, compliance checks, secrets management, and remediation actions with policy enforcement, audit logging, and human approval workflows.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    AI-powered security scanner for Python projects and GitHub repositories. Detects vulnerabilities, secrets, and provides AI risk assessment.
    11
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server for AI security analysis, enabling vulnerability scanning, sensitive information leak detection, and GitHub code leak monitoring via 48 tools.
    MIT