Skip to main content
Glama
90,500 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"How to connect to Document360" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables searching past scans and submitting URLs for scanning via urlscan.io, with both keyless and key-based operations.
    2 npm
    MIT
  • F
    license
    A
    quality
    C
    maintenance
    Enables AI agents to interact with the FlagForge REST API, allowing them to search solved CTF challenges, work on live event challenges, record evidence, submit flag candidates, and write markdown writeups.
    19
    -
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI applications to invoke 58 popular Kali Linux security tools for network scanning, web exploitation, password attacks, reconnaissance, Metasploit, evasion, forensics, post-exploitation, and miscellaneous tasks through the Model Context Protocol.
    59
    1
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables deep security auditing of web applications directly from AI IDEs including Cursor and Claude Code. Scans URLs for vulnerabilities, returns security scores with SHIP/BLOCK verdicts, and provides specific fix prompts for remediation.
    3
    -
  • A
    license
    Not graded
    quality
    A
    maintenance
    Provides MCP clients like Claude with tools to query and manage security scans, CVEs, assets, findings, threat intel, and generate polished reports by acting as a lightweight adapter over the CVEasy backend API.
    3
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Wraps the ScanMalware.com API to enable phishing triage, malware scanning, and certificate inspection through natural language, allowing users to submit scans, retrieve results, and analyze threats via MCP tools.
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to perform pay-per-call security verification of wallets, tokens, contracts, dApps, agents, and more via a remote endpoint with no installation.
    2
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Exposes the ASC APK-as-database analysis engine as MCP tools, enabling AI clients to run fast cross-reference searches, string/secret recon, class and member inspection, manifest and component extraction, and parallel batch queries across many APKs without full decompilation. All tools are stateless and process-isolated, so multiple clients can query single or multiple APK analysis sessions concurrently.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI-assisted penetration testing by connecting MCP clients to execute terminal commands on a Kali Linux machine, supporting tools like Nmap, Metasploit, and custom commands.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables MCP clients to drive IDA Pro through a stability-hardened server that hosts multiple headless idalib instances, with per-session isolation, configurable HTTP/stdio transports, and API-key authentication.
    454
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables MCP clients to query projects, fetch findings, trigger analysis, upload CycloneDX BOMs, and check async token status against an OWASP Dependency-Track instance via stdio.
    7 npm
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Config-driven MCP server that exposes Kali Linux penetration testing tools to AI agents, with automatic tool discovery, man page integration, and local/remote execution modes.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Connects AI assistants to HackerOne to pull bug bounty history, program scopes, and report details into a local SQLite database, exposing tools for searching, analyzing, and generating attack briefings using both personal and public disclosed reports.
    353
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Read-only observation of a single live URL: parses static HTML to report security posture, forms, links, accessibility signals, and leaks, with described fixes. SSRF-gated and safe, never executes JavaScript.
    45 npm
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to capture raw HTTP requests/responses and command executions as report-ready screenshots with preserved evidence bundles via MCP.
    1
    Apache 2.0