Skip to main content
Glama
74,254 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"MCP servers that don't require API keys" matching MCP servers:

  • F
    license
    -
    quality
    B
    maintenance
    Provides a disposable, hardened Kali Linux sandbox with an MCP interface for LLM-driven security analysis of REST APIs, confining blast radius via container isolation.
  • A
    license
    B
    quality
    B
    maintenance
    Enables AI assistants to perform automated security audits on APIs, detecting BOLA/IDOR vulnerabilities by comparing responses across user tokens.
    11
    MIT
  • A
    license
    B
    quality
    C
    maintenance
    Enables security teams to run controlled adversarial penetration tests against authorized ML/LLM API endpoints, scoring responses and generating evidence for compliance frameworks such as SOC 2, ISO 27001, and GDPR.
    6
    2
    MIT
  • A
    license
    C
    quality
    A
    maintenance
    Connects AI coding assistants to Snyk API & Web for onboarding scan targets, configuring authentication, running DAST scans, and triaging findings through natural language.
    51
    7
    Apache 2.0
  • A
    license
    -
    quality
    C
    maintenance
    A security linter for MCP that audits other MCP servers for compliance with the MCP specification and OWASP security standards, providing detailed findings and remediation.
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Query Microsoft Patch Tuesday security updates from the official MSRC API — monthly rollups, CVE/KB lookups, supersedence chains, and urgency-ranked triage enriched with EPSS scores and the CISA KEV catalog. No API keys required.
    1
    4
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables users to scan MCP servers for security threats, check installed servers, and analyze config files for risks, all from AI assistants like Claude, Cursor, or Windsurf.
    5
    24
    3
  • A
    license
    A
    quality
    B
    maintenance
    GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check.
    4
    73
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Bawbel MCP Server lets any agent scan MCP servers and skill files for security vulnerabilities mid-conversation. Seven tools covering server-card scanning, conformance scoring, rug pull detection, and AVE threat intelligence queries. Powered by the AVE standard with OWASP MCP Top 10 mapping on every finding. Free, Apache 2.0, no API key required.
    10
    1
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    Security scanning for MCP servers from the inside out. Provides runtime inspection, AST-based static analysis, config audit, dependency analysis, and OWASP MCP Top 10 compliance in a single MCP server.
    55
    62
    5
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Scans MCP servers for prompt-injection, tool-poisoning, and SSRF vulnerabilities using 30+ canonical rules across 5 severity tiers, with optional signed safety reports for procurement.
    5
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A security gate MCP server that audits agent extensions (skills, MCP servers, tools) by scanning for risks, adversarial analysis, and sandbox execution, returning a trust verdict of allow, quarantine, or block.
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Adds security capabilities like port scanning, TLS inspection, DNS enumeration, process monitoring, secrets scanning, HTTP header auditing, and CVE checking to Claude Code and Cursor.
    23
    32
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables querying the WPScan API for WordPress plugin, theme, core vulnerabilities, and specific vulnerability lookups through MCP tools.
    4
    12
    MIT