Skip to main content
Glama
94,597 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, October 2026Ranked from 1,731 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"GitHub repository JOJO-Adam/Stemem" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • F
    license
    Not graded
    quality
    C
    maintenance
    This server enables AI agents to delegate GitHub pull request diffs for automated security auditing, returning structured vulnerability and architecture feedback while routing requests through a resilient multi-provider fallback pipeline.
    -
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables LLMs to access realtime CVE intelligence aggregated from NVD, CISA KEV, EPSS, GitHub advisories, PoC discovery, and Metasploit/Nuclei tooling, providing vulnerability details, exploitation signals, and prioritized triage verdicts.
    12
    169 npm
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    A local MCP server that scans repository dependencies for known vulnerabilities (CVEs) using OSV.dev, enriches findings with NVD and CISA KEV data, and supports triage, remediation, and accepted risk management directly from an AI coding assistant.
    6
    30 npm
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables policy-first defensive security operations for MCP, providing repository and web-security analysis with controlled authorization, scoped execution, and auditability.
    9
    1
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Scan-as-a-Service for MCP servers. Wraps the compuute-scan static security scanner with HTTP and MCP endpoints to analyze public GitHub repos for MCP-specific vulnerabilities.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables agents to run static heuristic scans over a repository path via stdio, surfacing review candidates with file:line evidence for web3 auth and payment vulnerability patterns. Results can be used as CI-style gates or triage input without any dataflow analysis or external dependencies.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A proof-of-concept tool that integrates AI into security operations, allowing users to perform offensive security tasks like network scanning and reconnaissance through natural language commands to GitHub Copilot.
    5
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    AI-powered security scanner for Python projects and GitHub repositories. Detects vulnerabilities, secrets, and provides AI risk assessment.
    11
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server for AI security analysis, enabling vulnerability scanning, sensitive information leak detection, and GitHub code leak monitoring via 48 tools.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables querying aggregated vulnerability records from CIRCL's Vulnerability-Lookup, resolving IDs across multiple feeds such as MITRE CVE, NVD, GitHub Security Advisories, PySec, and vendor CSAF, with tools for lookup, search, and recent records.
    MIT
  • F
    license
    Not graded
    quality
    A
    maintenance
    Exposes 21 tools over stdio that let any MCP-capable AI agent run real Kali-container security tools (nmap, nuclei, sqlmap, Metasploit), search a local 59,000+ CVE vulnerability database, and browse a 5,266-entry GitHub security tool index. Built-in guardrails refuse government, education, and military domains, and only whitelisted in-container executables can be invoked.
    2
    -