Skip to main content
Glama
85,457 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, September 2026Ranked from 1,553 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"How to use GitHub" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    B
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    B
    quality
    C
    maintenance
    Enables deterministic security testing of AI agents that use tools by serving synthetic MCP environments with poisoned data, fake secrets, and privileged actions. Records agent tool calls and evaluates security invariants (e.g., canary leaks, forbidden access, approval binding) without an LLM judge or real systems.
    8
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Scan-as-a-Service for MCP servers. Wraps the compuute-scan static security scanner with HTTP and MCP endpoints to analyze public GitHub repos for MCP-specific vulnerabilities.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables MCP clients to drive IDA Pro through a stability-hardened server that hosts multiple headless idalib instances, with per-session isolation, configurable HTTP/stdio transports, and API-key authentication.
    111
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A proof-of-concept tool that integrates AI into security operations, allowing users to perform offensive security tasks like network scanning and reconnaissance through natural language commands to GitHub Copilot.
    5
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables autonomous AI agents and penetration testers to conduct authorized security audits with persistent cross-session memory, zero-trust secret scrubbing, dynamic OWASP/ASVS checklists, and hallucination-free exploit PoC generation from captured traffic.
    1
    MIT
  • A
    license
    Not graded
    quality
    Not graded
    maintenance
    Enables AI assistants to drive OWASP ZAP for authorized penetration testing and bug-bounty workflows, including authenticated scans and vulnerability triage through 67 curated safety-gated tools.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    AI-powered security scanner for Python projects and GitHub repositories. Detects vulnerabilities, secrets, and provides AI risk assessment.
    11
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server that enables LLMs to query and reason over Active Directory attack graphs collected by BloodHound, providing attack paths, blast radius analysis, choke points, and defender remediation advice.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A Model Context Protocol server that enables AI assistants to search and retrieve information about security exploits and vulnerabilities from the Exploit Database, enhancing cybersecurity research capabilities.
    29
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Fully automated MCP server built to communicate with JADX-AI-MCP Plugin to analyze Android APKs using LLMs like Claude — uncover vulnerabilities, parse manifests, and reverse engineer effortlessly.
    1
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server for AI security analysis, enabling vulnerability scanning, sensitive information leak detection, and GitHub code leak monitoring via 48 tools.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server that measures how effectively hashing tool definitions detects unauthorized changes, evaluating 20 policies across field sets and canonicalization methods. It demonstrates that approval-dialog-based pins miss most attacks, with structural/semantic normalization being free but text folding trading detection for fewer false alarms.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI assistants to run WordPress site reconnaissance, malware/CVE security scans, SEO-spam/cloaking detection, and end-to-end natural-language goals through a stdio MCP interface, with the target site configured via environment variables.
    MIT