Skip to main content
Glama
97,619 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, October 2026Ranked from 1,788 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"GitHub Pages" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables LLMs to access realtime CVE intelligence aggregated from NVD, CISA KEV, EPSS, GitHub advisories, PoC discovery, and Metasploit/Nuclei tooling, providing vulnerability details, exploitation signals, and prioritized triage verdicts.
    12
    14 npm
    2
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Scan-as-a-Service for MCP servers. Wraps the compuute-scan static security scanner with HTTP and MCP endpoints to analyze public GitHub repos for MCP-specific vulnerabilities.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A proof-of-concept tool that integrates AI into security operations, allowing users to perform offensive security tasks like network scanning and reconnaissance through natural language commands to GitHub Copilot.
    5
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    A JavaScript reverse engineering MCP server that enables AI coding assistants to debug and analyze JavaScript code in web pages.
    975 npm
    9
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    An MCP server that provides a complete interface to the GoPhish API for managing phishing campaigns, groups, templates, landing pages, SMTP profiles, and users through natural language commands.
    21
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    AI-powered security scanner for Python projects and GitHub repositories. Detects vulnerabilities, secrets, and provides AI risk assessment.
    11
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server for AI security analysis, enabling vulnerability scanning, sensitive information leak detection, and GitHub code leak monitoring via 48 tools.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables querying aggregated vulnerability records from CIRCL's Vulnerability-Lookup, resolving IDs across multiple feeds such as MITRE CVE, NVD, GitHub Security Advisories, PySec, and vendor CSAF, with tools for lookup, search, and recent records.
    15 npm
    MIT
  • F
    license
    Not graded
    quality
    A
    maintenance
    Exposes 21 tools over stdio that let any MCP-capable AI agent run real Kali-container security tools (nmap, nuclei, sqlmap, Metasploit), search a local 59,000+ CVE vulnerability database, and browse a 5,266-entry GitHub security tool index. Built-in guardrails refuse government, education, and military domains, and only whitelisted in-container executables can be invoked.
    2
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    Unified vulnerability search MCP server for penetration testing agents, integrating 5 data sources (NVD, OSV, EPSS, CISA KEV, Exploit-DB+GitHub) and 10 MCP tools for CVE query, keyword search, batch query, EPSS scoring, KEV checking, exploit search, and comprehensive assessment with Chinese output.
    2
    -