Skip to main content
Glama
97,619 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Sauce Labs" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to drive live Hack The Box labs through the real HTB Labs API — spawning, resetting and extending machines, submitting user and root flags with difficulty ratings, browsing challenges, and switching or downloading VPN configurations for the authenticated account. Every call hits the live API rather than cached content, with destructive actions annotated so hosts can gate them behind consent.
    22
    297 npm
    1
    MIT
  • F
    license
    B
    quality
    C
    maintenance
    A security research MCP server for testing tool call safety with deterministic policies like allowlists, path boundary enforcement, SSRF prevention, output redaction, and prompt injection detection, without requiring external LLMs or API keys.
    6
    -
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables users to statically analyze regular expressions for catastrophic-backtracking (ReDoS) risk through real AST parsing rather than executing the pattern, flagging nested quantifiers, ambiguous alternation, and backreferences. It also generates candidate proof-of-concept attack strings with a timeout-guarded test snippet and suggests JavaScript-safe rewrites.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables users to scan AI agent skills and configuration files for hidden Unicode instructions, prompt injection, download-and-execute payloads, exfiltration patterns, and overly broad permissions before installation. It provides static audit tools for skill files, agent configs, and revealing hidden text without executing or fetching the input.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    AI-agent-optimized CVE exploit discovery toolkit that provides 19 tools for finding proof-of-concept exploits, CTF labs, bug bounty reports, and vulnerability intelligence from a single interface.
    110 PyPI
    6
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables users to audit other MCP servers' tool definitions for agentic attack classes such as tool poisoning, sensitive-path references in metadata, and tool shadowing via invisible Unicode or homoglyphs. It can analyze a tools/list payload, check a single description string, or connect to a public remote MCP URL to fetch and audit its tool list.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A rogue MCP server (~90 lines) that demonstrates prompt injection via tool responses to achieve remote code execution on a developer's machine.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI agents to perform endpoint security scanning using AlienVault OTX and VirusTotal, including multi-platform scans, threat intelligence queries, and scan data persistence.
    25 npm
    3
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    A deliberately vulnerable MCP server demonstrating API key exposure through hardcoding, plaintext logging, and returning secrets to the model, part of the OWASP MCP Top 10 security lab.
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables hands-on exploration of common MCP security vulnerabilities through locally runnable vulnerable and fixed servers with accompanying exploits and a dashboard.
    -