Skip to main content
Glama
90,172 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, September 2026Ranked from 1,639 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"How to manage and create GitHub repositories" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • F
    license
    Not graded
    quality
    C
    maintenance
    This server enables AI agents to delegate GitHub pull request diffs for automated security auditing, returning structured vulnerability and architecture feedback while routing requests through a resilient multi-provider fallback pipeline.
    -
  • A
    license
    A
    quality
    B
    maintenance
    Enables LLM agents to browse and triage vulnerability observations, manage products, branches and rules, import scan reports and SBOMs, run scans and background jobs, and generate VEX documents via SecObserve's REST API.
    18
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables LLMs to access realtime CVE intelligence aggregated from NVD, CISA KEV, EPSS, GitHub advisories, PoC discovery, and Metasploit/Nuclei tooling, providing vulnerability details, exploitation signals, and prioritized triage verdicts.
    12
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A Model Context Protocol (MCP) server for interacting with the Intigriti bug bounty platform's Researcher API. It enables AI assistants to manage bug bounty programs, submissions, and research workflow.
    8
    4
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI assistants to scan websites, public repositories, and OpenClaw/CLAW skills for security vulnerabilities, including local skill-package analysis before installation, cloud scans, and remediation guidance.
    10
    33 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables agents and CI pipelines to audit MCP servers and agent tool-chains by statically scanning repositories, local checkouts, tools/list exports, or live endpoints for risks such as destructive actions without confirmation, mismatched safety annotations, injection surfaces, credential or PII exposure, and unguarded command, path, or URL sinks. All checks are read-only and never execute the scanned code or call tools/call.
    3
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables interaction with the APVISO AI-powered penetration testing platform to manage targets, initiate scans, and retrieve vulnerability findings. It allows developers to integrate security testing workflows directly into MCP-compatible tools like Claude Code and Cursor.
    18
    6 npm
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server that wraps the Frida dynamic instrumentation toolkit, allowing users to attach to processes, hook functions, enumerate modules and exports, and manage scripts through natural language.
    10
    1
    MIT
  • F
    license
    A
    quality
    B
    maintenance
    Enables AI assistants to natively execute and manage 600+ Kali Linux security, penetration testing, and forensic tools, including search, help documentation, structured scanners, and workspace management.
    8
    -
  • F
    license
    A
    quality
    D
    maintenance
    Exposes Burp Suite's REST API to AI assistants, enabling users to trigger vulnerability scans, monitor progress, and manage security tasks through natural language. It also provides programmatic access to Burp's security knowledge base for querying vulnerability definitions and remediation advice.
    8
    1
    -
  • F
    license
    A
    quality
    B
    maintenance
    Enables agents to store, search, and manage a personal penetration testing knowledge base via MCP, using BM25-ranked retrieval with Chinese tokenization, plus draft approval, deduplication, and sensitive-data redaction workflows.
    13
    -
  • A
    license
    A
    quality
    D
    maintenance
    Enables out-of-band interaction testing by integrating ProjectDiscovery's interactsh service as an MCP server. Allows AI agents to create callback domains, send probes, and capture DNS/HTTP interactions for security testing and verification workflows.
    4
    14 npm
    3
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A comprehensive MCP server for Frida dynamic instrumentation, enabling AI agents to manage devices, processes, scripts, memory, and ADB operations.
    39
    31
    MIT