Skip to main content
Glama
83,694 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"How to take notes on my local machine and on Notion" matching MCP servers:

GET /v1/servers — MCP directory API reference
  • A
    license
    C
    quality
    C
    maintenance
    A deliberately vulnerable MCP server for practicing exploitation of tool poisoning, command injection, and path traversal. Includes fixed versions and an agent demo to reproduce the issues in a controlled environment.
    2
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables querying SAP Security Note metadata including Patch Day releases, CVSS scores, CVEs, affected components, and actively-exploited status via the Model Context Protocol.
    2
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to execute security testing tools on a Kali Linux machine over SSH, including reconnaissance, web app scanning, and static/dynamic analysis.
    10
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A rogue MCP server (~90 lines) that demonstrates prompt injection via tool responses to achieve remote code execution on a developer's machine.
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Exposes a hardened Docker container with Kali Linux security tools (nmap, sqlmap, dig, whois, etc.) as MCP tools, enabling network reconnaissance, web analysis, and vulnerability scanning through natural language commands.
    -
  • A
    license
    A
    quality
    B
    maintenance
    Privacy-first OSINT scanning MCP server that aggregates ~25 sources into a risk report, running locally with no data leaving your machine.
    5
    1
    AGPL 3.0
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to perform passive security scans on domains, checking email spoofing (DMARC/SPF/DKIM), TLS weaknesses, security headers, exposed files, and subdomain-takeover risk without needing an API key.
    7
    1,018
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check.
    4
    49
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.
    7
    391
    44
    Apache 2.0
  • F
    license
    A
    quality
    C
    maintenance
    Enables bug bounty hunters to browse programs, inspect scope details, track scope changes over time, and receive personalized, recency-boosted program recommendations based on their skill profile.
    4
    -
  • A
    license
    A
    quality
    B
    maintenance
    A scope-aware bug-bounty & reconnaissance MCP server that works out of the box on the Python standard library and augments itself with your favourite CLI tools when they're present.
    22
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    A Model Context Protocol (MCP) server for Gobuster that enables AI assistants to perform directory/file, DNS, virtual host, S3 bucket, and TFTP enumeration on a remote Kali Linux host via SSH.
    10
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Enables dynamic management and execution of proxy chains on a remote Linux host via SSH, allowing AI assistants to route network traffic through proxies for privacy and security testing.
    10
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    A universal digital fingerprinting MCP server that combines 103 techniques across TCP, TLS, SSH, HTTP, DNS, and more into a single interface for AI agents, enabling full-spectrum fingerprinting on demand.
    13
    43
    3
    AGPL 3.0