Skip to main content
Glama
81,811 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"How to connect with my Notion account" matching MCP servers:

GET /v1/servers — MCP directory API reference
  • F
    license
    A
    quality
    B
    maintenance
    A local, read-only MCP server that connects your HackerOne researcher account to Claude Desktop and Claude Code, helping you find targets, analyze program scopes, review reports and earnings, and draft bug reports.
    17
    4
  • A
    license
    Not graded
    quality
    A
    maintenance
    Provides MCP clients like Claude with tools to query and manage security scans, CVEs, assets, findings, threat intel, and generate polished reports by acting as a lightweight adapter over the CVEasy backend API.
    2
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables threat intelligence for SOC and DFIR workflows, including IOC enrichment, CVE and threat actor lookup, domain scanning, and account-based scan management.
    1
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for integrating with StackHawk's security scanning platform. Helps developers set up StackHawk, run security scans, and triage findings to fix vulnerabilities — all from within an LLM-powered IDE or chat.
    9
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    AI-Powered Red Team MCP Server enabling autonomous penetration testing via Model Context Protocol with 44+ security tools for AI agents.
    14
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables MCP clients to drive IDA Pro through a stability-hardened server that hosts multiple headless idalib instances, with per-session isolation, configurable HTTP/stdio transports, and API-key authentication.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Config-driven MCP server that exposes Kali Linux penetration testing tools to AI agents, with automatic tool discovery, man page integration, and local/remote execution modes.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Read-only observation of a single live URL: parses static HTML to report security posture, forms, links, accessibility signals, and leaks, with described fixes. SSRF-gated and safe, never executes JavaScript.
    109
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables network security scanning using Nmap through MCP protocol. Supports quick port scans, full port scans with service detection, and custom Nmap commands with async task management.
    3
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Gorgon Scout is a Windows web-application and API security scanner (DAST). This connector exposes it as MCP tools, so your AI assistant can record a target you are authorised to test, run the scan, stream findings, and produce a report. Capture needs no proxy or certificate setup, and it intercepts HTTP/1.1, HTTP/2, and HTTP/3 (QUIC). Works with the free Claude Desktop plan.
  • A
    license
    Not graded
    quality
    D
    maintenance
    Automatically generates pocsuite3-compliant POC (Proof of Concept) code from vulnerability information, with built-in safety features to prevent harmful payloads and ensure secure security testing.
    4
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables LLM clients like Claude to interact with IDA Pro for binary analysis, decompilation, cross-references, patching, and more via 41 MCP tools, 8 resources, and 7 guided prompts.
    50
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to conduct authorized penetration tests by providing scope-enforced access to Metasploit Framework's RPC, with tools for reconnaissance, exploitation, session management, and post-exploitation.
    3
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Audits HAR captures locally with MCP tools for triage, findings, vendor blast radius, CSP generation, and sanitization—no network calls, redacted by default.
    88
    1
    MIT