Skip to main content
Glama
93,505 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Scraping Public Documents" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    A
    maintenance
    Enables LLM agents to browse and triage vulnerability observations, manage products, branches and rules, import scan reports and SBOMs, run scans and background jobs, and generate VEX documents via SecObserve's REST API.
    18
    1,698 PyPI
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Exposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.
    3
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables coding agents to perform network diagnostics and lookups, including subnet calculations, port and MAC vendor information, DNS and blocklist checks, TLS certificate inspection, and public IP discovery, all without needing an account or sending telemetry.
    11
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Provides passive OSINT reconnaissance for domains and IPs using public sources, with tools for WHOIS/RDAP, DNS, subdomain enumeration, Wayback Machine, HTTP headers, Shodan InternetDB, email security, TLS certificates, and ASN lookups, all without requiring API keys.
    11
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for the YesWeHack bug bounty platform that lets Claude query private and public programs, reports, and the hacktivity feed directly from a conversation.
    12
    1
    -
  • A
    license
    A
    quality
    C
    maintenance
    Enables LLMs to conduct passive attack-surface research by collecting public information, referencing saved reports, and verifying evidence through MCP tools.
    6
    MIT
  • F
    license
    B
    quality
    C
    maintenance
    Enables read-only interaction with HackerOne, providing tools for searching and analyzing reports, exploring programs and scope, accessing earnings, and retrieving public disclosures.
    25
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    Scan-as-a-Service for MCP servers. Wraps the compuute-scan static security scanner with HTTP and MCP endpoints to analyze public GitHub repos for MCP-specific vulnerabilities.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Connects AI assistants to HackerOne to pull bug bounty history, program scopes, and report details into a local SQLite database, exposing tools for searching, analyzing, and generating attack briefings using both personal and public disclosed reports.
    355
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server providing 15 OSINT tools over free, public sources for AI agents, enabling domain reconnaissance, subdomain discovery, DNS lookups, host profiling, CVE search, and more without API keys.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server that integrates multiple security and reconnaissance tools (Nmap, Cariddi, ParamSpider, Metasploit, web scraping) for AI systems, enabling automated network scanning, API discovery, vulnerability testing, and remote access via ngrok.
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables natural language queries across AWS multi-account security scan history, including infrastructure configurations, public exposures, and organizational relationships.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A high-performance local and public webhook inspector for testing SSRF, APIs, and out-of-band interactions with Cloudflare Quick Tunnel, dynamic mocks, and callback polling for AI agents.
    1
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables coding agents to scan a public URL in passive or authorized mode and receive only bounded, sanitized structured findings (severity, confidence, standard, evidence, remediation) with quarantined evidence instead of raw page dumps. A second tool lets agents inspect the scanner's safety boundaries and coverage without making any network request.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Provides CVE lookup, search, and exploit intelligence from public vulnerability sources (NVD, CISA KEV, EPSS) for AI agents to produce remediation guidance without consuming LLM tokens for data fetching.
    1
    MIT