Skip to main content
Glama
94,482 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"The mcprating.io gateway page" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    D
    maintenance
    Enables searching and querying HackTricks pentesting documentation directly from Claude, with tools for quick lookup, grouped search results, page outlines, section extraction, and cheatsheet mode.
    7
    54 npm
    10
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    This server enables AI-assisted APK reverse-engineering entirely on-device, orchestrating jadx, apktool, adb, frida, and APKiD through a job/workflow engine, and exposing those agents as native MCP tools for Claude without any cloud dependency.
    38
    19
    7
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Enables AI assistants to perform password security auditing using John the Ripper on a remote Kali system via SSH, supporting cracking, hash management, and session control.
    12
    MIT
  • F
    license
    A
    quality
    B
    maintenance
    Enables AI assistants and the WYRE Conduit gateway to access Telivy's security assessment data for MSPs, including external scans, deep-scan risk assessments, device inventory, M365/Google Workspace user exposure, PII summaries, and finding-level details.
    16
    -
  • F
    license
    B
    quality
    C
    maintenance
    Enables users to query BloodHound Active Directory graph data using natural language, finding attack paths, Kerberoastable accounts, and other AD security insights.
    23
    -
  • A
    license
    C
    quality
    C
    maintenance
    Community MCP server for the Cymulate security validation platform. It exposes the full Cymulate REST API (337 endpoints) as 106 semantic tools for BAS, exposure validation, attack surface management, and platform administration.
    100
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Provides MCP clients like Claude with tools to query and manage security scans, CVEs, assets, findings, threat intel, and generate polished reports by acting as a lightweight adapter over the CVEasy backend API.
    3
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server for complyeah that enables AI assistants to list domains and scans, read findings, and start external penetration tests through the complyeah API.
    16 npm
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI assistants to perform reconnaissance tasks using the reconFTW framework, supporting full, passive, subdomain, vulnerability, and OSINT scans through MCP tools.
    21
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables users to statically analyze regular expressions for catastrophic-backtracking (ReDoS) risk through real AST parsing rather than executing the pattern, flagging nested quantifiers, ambiguous alternation, and backreferences. It also generates candidate proof-of-concept attack strings with a timeout-guarded test snippet and suggests JavaScript-safe rewrites.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Exposes the ASC APK-as-database analysis engine as MCP tools, enabling AI clients to run fast cross-reference searches, string/secret recon, class and member inspection, manifest and component extraction, and parallel batch queries across many APKs without full decompilation. All tools are stateless and process-isolated, so multiple clients can query single or multiple APK analysis sessions concurrently.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables querying SAP Security Note metadata including Patch Day releases, CVSS scores, CVEs, affected components, and actively-exploited status via the Model Context Protocol.
    2
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Config-driven MCP server that exposes Kali Linux penetration testing tools to AI agents, with automatic tool discovery, man page integration, and local/remote execution modes.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server that acts as a boundary agent, giving LLMs and automation systems controlled SSH-based access to remote machines for tasks like administration, diagnostics, and security research.
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables authorized web/API security analysis as a stateful, multi-stage workflow with persistent session state, human-controlled validation, candidate versus confirmed finding tracking, and stop conditions.
    1
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Gorgon Scout is a Windows web-application and API security scanner (DAST). This connector exposes it as MCP tools, so your AI assistant can record a target you are authorised to test, run the scan, stream findings, and produce a report. Capture needs no proxy or certificate setup, and it intercepts HTTP/1.1, HTTP/2, and HTTP/3 (QUIC). Works with the free Claude Desktop plan.
    -