Skip to main content
Glama
88,127 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, September 2026Ranked from 1,639 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"How to list a remote MCP server on GitHub's MCP directory" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • F
    license
    Not graded
    quality
    B
    maintenance
    Simulates sensitive internal tools as a honeypot to detect unauthorized access and AI agent behaviors using Canarytokens, deployed as a serverless Cloudflare Worker with MCP protocol support.
    21
    -
  • A
    license
    Not graded
    quality
    D
    maintenance
    Scans MCP servers for security vulnerabilities, prompt injection, and tool poisoning, providing risk scores and protection.
    4
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI-assisted penetration testing by connecting MCP clients to execute terminal commands on a Kali Linux machine, supporting tools like Nmap, Metasploit, and custom commands.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server that measures how effectively hashing tool definitions detects unauthorized changes, evaluating 20 policies across field sets and canonicalization methods. It demonstrates that approval-dialog-based pins miss most attacks, with structural/semantic normalization being free but text folding trading detection for fewer false alarms.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    AI-powered penetration testing through 36 MCP tools on a containerized Kali Linux, enabling automated reconnaissance, web testing, exploitation, and evidence collection.
    1
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for the IssueHunt bug bounty platform. Enables LLMs like Claude to interact with IssueHunt to list organizations, programs, and vulnerability reports, as well as perform triage actions.
    -
  • A
    license
    A
    quality
    D
    maintenance
    Connects AI assistants to Solodit's 49,000+ blockchain vulnerability database, enabling search, browse, and lookup of audit findings directly from your AI workflow.
    4
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables searching and querying HackTricks pentesting documentation directly from Claude, with tools for quick lookup, grouped search results, page outlines, section extraction, and cheatsheet mode.
    7
    36 npm
    10
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server for AgentMinds collective intelligence platform, enabling AI agents to scan websites for security/SEO/performance issues, pull personalized recommendations, and share findings across the network.
    7
    4 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    MCP server that provides AI-native access to BeVigil's OSINT API, enabling mobile app security research and asset discovery through tools for hosts, subdomains, S3 buckets, URLs, wordlists, and multi-step investigations.
    6
    7
    24 npm
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A minimal, dependency-free MCP server that gives AI agents three real, read-only security-orchestration tools: cve_lookup, shodan_host_lookup, and nuclei_scan.
    3
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Provides Claude Code with access to a comprehensive bug bounty knowledge base including techniques, payloads, wordlists, and real-world reports through 14 tools for searching, retrieving payloads, and assessing report quality.
    14
    18
    GPL 3.0
  • A
    license
    A
    quality
    C
    maintenance
    A Model Context Protocol (MCP) server for interacting with the Intigriti bug bounty platform's Researcher API. It enables AI assistants to manage bug bounty programs, submissions, and research workflow.
    8
    4
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables AI assistants to scan websites, public repositories, and OpenClaw/CLAW skills for security vulnerabilities, including local skill-package analysis before installation, cloud scans, and remediation guidance.
    10
    31 npm
    MIT