Skip to main content
Glama
92,371 servers. Updated
20 Best GitHub MCP Servers: compared and ranked, September 2026Ranked from 1,676 matching servers on stars, growth, downloads and maintenance. Updated .

Matching MCP tools:

Matching MCP Connectors:

"Trending GitHub repositories" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables LLMs to access realtime CVE intelligence aggregated from NVD, CISA KEV, EPSS, GitHub advisories, PoC discovery, and Metasploit/Nuclei tooling, providing vulnerability details, exploitation signals, and prioritized triage verdicts.
    12
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Exposes PatrowlIntel vulnerability intelligence (CVEs, EPSS, CISA KEV, public exploits, trending attacks) via MCP tools like search_cves, get_cve, and list_trending_attacks.
    3
    2
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables agents and CI pipelines to audit MCP servers and agent tool-chains by statically scanning repositories, local checkouts, tools/list exports, or live endpoints for risks such as destructive actions without confirmation, mismatched safety annotations, injection surfaces, credential or PII exposure, and unguarded command, path, or URL sinks. All checks are read-only and never execute the scanned code or call tools/call.
    3
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Scan-as-a-Service for MCP servers. Wraps the compuute-scan static security scanner with HTTP and MCP endpoints to analyze public GitHub repos for MCP-specific vulnerabilities.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A proof-of-concept tool that integrates AI into security operations, allowing users to perform offensive security tasks like network scanning and reconnaissance through natural language commands to GitHub Copilot.
    5
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    AI-powered security scanner for Python projects and GitHub repositories. Detects vulnerabilities, secrets, and provides AI risk assessment.
    11
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    An MCP server for AI security analysis, enabling vulnerability scanning, sensitive information leak detection, and GitHub code leak monitoring via 48 tools.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables querying aggregated vulnerability records from CIRCL's Vulnerability-Lookup, resolving IDs across multiple feeds such as MITRE CVE, NVD, GitHub Security Advisories, PySec, and vendor CSAF, with tools for lookup, search, and recent records.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides deterministic, 100%-file-coverage security findings by running Semgrep, gitleaks, and osv-scanner on code repositories, enabling thorough security assessment of every file.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    SecHelix is an evidence-first AppSec MCP server for reviewing repositories you own or are authorized to test. It verifies candidate findings, refutes false positives, and exposes a root-confined local MCP interface with no shell or arbitrary command execution.
    51 PyPI
    1
    Apache 2.0
  • F
    license
    Not graded
    quality
    B
    maintenance
    Provides a set of MCP tools to clone and analyze arbitrary MCP server repositories, run static and dynamic security probes in isolated Docker containers, and produce vulnerability verdicts with a human-in-the-loop approval step before filing public reports.
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    Unified vulnerability search MCP server for penetration testing agents, integrating 5 data sources (NVD, OSV, EPSS, CISA KEV, Exploit-DB+GitHub) and 10 MCP tools for CVE query, keyword search, batch query, EPSS scoring, KEV checking, exploit search, and comprehensive assessment with Chinese output.
    2
    -