Skip to main content
Glama
91,371 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Notes and related content" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that lets an AI agent probe a live URL and confirm whether sensitive files (e.g., .git, .env, source maps) are genuinely served by fetching and validating the content, avoiding false positives.
    2
    7 npm
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Open behavioral litmus for MCP servers — grades A–F across tool-output injection, egress, sensitive-data, and adversarial-input, with reproducible, content-addressed evidence. Tools: run_litmus, verify_attestation.
    4
    60 npm
    8
    Apache 2.0
  • A
    license
    A
    quality
    F
    maintenance
    Enables AI assistants to perform web content discovery scans using feroxbuster on a remote system via SSH, with support for recursive scanning, filtering, and background execution.
    8
    MIT
  • A
    license
    C
    quality
    C
    maintenance
    A deliberately vulnerable MCP server for practicing exploitation of tool poisoning, command injection, and path traversal. Includes fixed versions and an agent demo to reproduce the issues in a controlled environment.
    2
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables querying SAP Security Note metadata including Patch Day releases, CVSS scores, CVEs, affected components, and actively-exploited status via the Model Context Protocol.
    2
    Apache 2.0
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI assistants to drive OWASP ZAP for authorized penetration testing and bug-bounty workflows, including authenticated scans and vulnerability triage through 67 curated safety-gated tools.
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A local Python MCP server for safe, human-led bug bounty recon, providing lightweight helpers for scope checks, headers, robots.txt, sitemap.xml, JavaScript URL collection, endpoint extraction, URL deduplication, evidence notes, and manual test planning.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to locally scan untrusted third-party tool descriptions, configurations, and content for security threats before installing or trusting them, returning structured verdicts without network access.
    4
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to control and analyze RFID hardware through natural language: read, crack, emulate, and clone cards via MCP tools, with safety gates, offline dump analysis, and a host-side card library.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI assistants to perform Volatility 3 memory forensics through natural language, including process and network analysis, injection detection, and shellcode extraction from memory dumps.
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server for Frida dynamic instrumentation, enabling AI agents to enumerate devices/processes, attach, inject JavaScript, hook functions, read memory, and collect results via MCP tools.
    1
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables secure static analysis of Microsoft Office documents and related file types for malicious content, integrating with systems that support the MCP protocol.
    4
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    A deliberately vulnerable MCP server demonstrating API key exposure through hardcoding, plaintext logging, and returning secrets to the model, part of the OWASP MCP Top 10 security lab.
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    Provides access to the Exploit-DB database through the searchsploit tool, enabling AI assistants to search for exploits by keywords or CVE identifiers, retrieve exploit content, and manage the local exploit database.
    7
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    Provides social media content extraction and analysis tools via MCP (Reddit and LinkedIn), while demonstrating security risks and obfuscation techniques for educational purposes.
    19
    -