Skip to main content
Glama
91,154 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Resources and tools for difficult CTF (Capture The Flag) cybersecurity challenges" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • F
    license
    Not graded
    quality
    B
    maintenance
    GDB Enhanced Features MCP server for remote debugging and CTF exploitation with 41 specialized tools including ROP search, format-string detection, and memory patching.
    11
    -
  • A
    license
    Not graded
    quality
    Not graded
    maintenance
    Exposes common CTF and cybersecurity tools (crypto, forensics, malware analysis, steganography, reverse engineering, pwn, OSINT) so LLMs can help solve capture-the-flag challenges in a controlled lab environment.
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    A local MCP daemon that turns an agentic coding client into a bug bounty operator, with 103 tools for offensive security testing including MITM proxy, traffic analysis, and OOB callbacks.
    6 npm
    2
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Enables AI assistants to perform password security auditing using John the Ripper on a remote Kali system via SSH, supporting cracking, hash management, and session control.
    12
    MIT
  • A
    license
    C
    quality
    C
    maintenance
    Community MCP server for the Cymulate security validation platform. It exposes the full Cymulate REST API (337 endpoints) as 106 semantic tools for BAS, exposure validation, attack surface management, and platform administration.
    100
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables guardrail and trust testing by exposing realistic malicious tool patterns such as shell execution, credential dumping, and data exfiltration, all without network access.
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    Provides essential security and CTF tools including hash identification, encoding/decoding, XOR bruteforce, JWT decoding, reverse shell generation, SQL injection payloads, CVE lookup, and port service identification for learning security concepts and solving challenges.
    3
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables MCP clients to invoke common Kali Linux pentesting tools directly as tool calls, with each binary executed safely without a shell.
    1
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables authorized web/API security analysis as a stateful, multi-stage workflow with persistent session state, human-controlled validation, candidate versus confirmed finding tracking, and stop conditions.
    1
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Integrates 7 security tools (nmap, nuclei, dirsearch, sqlmap, hydra, Acunetix, Metasploit) via MCP protocol for AI-assisted penetration testing with enterprise-grade safety features.
    1
    MIT