Skip to main content
Glama
80,976 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"How to read document contents" matching MCP servers:

GET /v1/servers — MCP directory API reference
  • A
    license
    A
    quality
    C
    maintenance
    A minimal, dependency-free MCP server that gives AI agents three real, read-only security-orchestration tools: cve_lookup, shodan_host_lookup, and nuclei_scan.
    3
    MIT
  • F
    license
    A
    quality
    B
    maintenance
    A local, read-only MCP server that connects your HackerOne researcher account to Claude Desktop and Claude Code, helping you find targets, analyze program scopes, review reports and earnings, and draft bug reports.
    17
    4
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server for complyeah that enables AI assistants to list domains and scans, read findings, and start external penetration tests through the complyeah API.
    16
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables MCP clients to drive IDA Pro through a stability-hardened server that hosts multiple headless idalib instances, with per-session isolation, configurable HTTP/stdio transports, and API-key authentication.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Read-only observation of a single live URL: parses static HTML to report security posture, forms, links, accessibility signals, and leaks, with described fixes. SSRF-gated and safe, never executes JavaScript.
    82
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    MCP server for SUSE NeuVector container security, exposing inventory, vulnerability, compliance, event, and policy data as 72 typed tools. Read-only by default, with optional mutating toolsets behind a confirmation handshake.
    Apache 2.0
  • A
    license
    Not graded
    quality
    A
    maintenance
    Audits MCP server configurations for security risks including capability inventory, SSRF, prompt injection, and drift detection. Works in read-only mode and can also be used as an MCP server to let AI agents audit their own attack surface.
    4
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables querying CVE vulnerability data from the NIST National Vulnerability Database, including CVE lookup, product/version search via CPE filters, CVSS severity scores, and recent high-severity disclosures.
    1
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables MCP-compatible AI applications to perform read-only npm package and project dependency safety scans, returning proceed, caution, or block verdicts without executing package code.
    77
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables security agents to interact with the Kuroko web security testing platform through MCP, providing access to traffic history, site graph entities, findings, and scan jobs with read-only defaults and scoped, approved tools for testing operations.
    1
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Voyager-net is a read-only, authorized network auditing MCP server that scans a single host or domain for DNS, port, TLS, and HTTP hygiene issues, returning findings with severity and suggested fixes. It enables AI agents to audit infrastructure safely without mutation, requiring explicit authorization.
    134
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server that enables LLMs to query and reason over Active Directory attack graphs collected by BloodHound, providing attack paths, blast radius analysis, choke points, and defender remediation advice.
    MIT