Skip to main content
Glama
96,351 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Understanding the term 'flux' or its various applications" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • A
    license
    Not graded
    quality
    C
    maintenance
    A local MCP daemon that turns an agentic coding client into a bug bounty operator, with 103 tools for offensive security testing including MITM proxy, traffic analysis, and OOB callbacks.
    8 npm
    2
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Enables AI assistants to perform password security auditing using John the Ripper on a remote Kali system via SSH, supporting cracking, hash management, and session control.
    12
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables authorized web/API security analysis as a stateful, multi-stage workflow with persistent session state, human-controlled validation, candidate versus confirmed finding tracking, and stop conditions.
    1
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    AI-native security research platform that integrates Claude with MCP to execute real offensive security tools in an isolated Docker container, enabling natural language-driven recon, CVE scanning, Active Directory enumeration, and cryptographic posture assessment.
    1
    MIT
  • F
    license
    B
    quality
    C
    maintenance
    Enables users to query BloodHound Active Directory graph data using natural language, finding attack paths, Kerberoastable accounts, and other AD security insights.
    23
    -
  • A
    license
    A
    quality
    D
    maintenance
    Enables scanning of Claude Code skills, plugins, or MCP servers for malware before installation via static analysis.
    1
    14 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables AI agents to access VirusTotal intelligence through MCP, supporting file, URL, domain, and IP lookups, plus analysis, via remote HTTP or local stdio.
    8
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Free deterministic security scan of a public git repository (GitHub, GitLab, Codeberg, Bitbucket): vulnerable dependencies via OSV.dev, secret patterns, and config lint, returned as structured JSON. Tools: scan_repository(url), audit_pricing(). Runs locally over stdio (python3 web/mcp_stdio.py or the Dockerfile) and is also hosted at https://project-feldspar.com/mcp. MIT licence, stdlib-only. Buil
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    A read-only MCP server for the Qualys PCI Merchant API that lets LLM assistants answer questions about PCI compliance posture, such as which hosts are failing PCI or listing high findings.
    7
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    Connects MCP clients to pre-submission review that argues against a draft bug-bounty report or smart-contract finding the way a triager would, tying every claim to a supplied file and line and returning a submit, rewrite-then-submit, prove-first, hold-duplicate or drop verdict. Exposes tools to list review profiles, prepare reviews for the agent's own model, build hash-verified review packets, and — with a connection token — run hosted profiles on your own provider key.
    6
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server for Android APK triage, providing tools to parse APK headers, list DEX classes, and decode AndroidManifest.xml using apktool or androguard backends.
    5
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables agents and CI pipelines to audit MCP servers and agent tool-chains by statically scanning repositories, local checkouts, tools/list exports, or live endpoints for risks such as destructive actions without confirmation, mismatched safety annotations, injection surfaces, credential or PII exposure, and unguarded command, path, or URL sinks. All checks are read-only and never execute the scanned code or call tools/call.
    3
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.
    10
    109 npm
    47
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Enables MCP clients to work with DefAudit, supporting project and scan listing, starting scans, retrieving results, and marking or unmarking false positives.
    7
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    A security gate MCP server that audits agent extensions (skills, MCP servers, tools) by scanning for risks, adversarial analysis, and sandbox execution, returning a trust verdict of allow, quarantine, or block.
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A read-only MCP server that lets an agent browse the HackerOne Hacker API using an authenticated hacker account, exposing programs, policies, scope, reports, and payments. It cannot create, update, or submit reports.
    15
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    An MCP server for identifying SQL injection vulnerabilities in web applications using various techniques like error-based, time-based, and union-based scanning. It supports bulk URL processing, WAF bypass strategies, and authenticated testing across multiple database systems.
    13
    -