Skip to main content
Glama
97,619 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"Using a localhost API for development" matching MCP servers:

GET /v1/servers – MCP directory API reference
  • F
    license
    Not graded
    quality
    B
    maintenance
    Provides a disposable, hardened Kali Linux sandbox with an MCP interface for LLM-driven security analysis of REST APIs, confining blast radius via container isolation.
    -
  • A
    license
    A
    quality
    C
    maintenance
    Enables testing API authentication and authorization by probing endpoints with and without Authorization headers, suggesting auth test matrices for roles, and showing current test configuration.
    3
    12 npm
    ISC
  • A
    license
    B
    quality
    B
    maintenance
    Enables AI assistants to perform automated security audits on APIs, detecting BOLA/IDOR vulnerabilities by comparing responses across user tokens.
    11
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Scan-as-a-Service for MCP servers. Wraps the compuute-scan static security scanner with HTTP and MCP endpoints to analyze public GitHub repos for MCP-specific vulnerabilities.
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    GDB Enhanced Features MCP server for remote debugging and CTF exploitation with 41 specialized tools including ROP search, format-string detection, and memory patching.
    10
    -
  • A
    license
    B
    quality
    D
    maintenance
    Enables security teams to run controlled adversarial penetration tests against authorized ML/LLM API endpoints, scoring responses and generating evidence for compliance frameworks such as SOC 2, ISO 27001, and GDPR.
    6
    2
    MIT
  • F
    license
    B
    quality
    C
    maintenance
    Enables LLMs to perform automated penetration testing and Active Directory reconnaissance through Mythic, with tools for executing PowerShell, AD recon, domain user enumeration, and Kerberoasting.
    12
    -
  • A
    license
    C
    quality
    A
    maintenance
    Connects AI coding assistants to Snyk API & Web for onboarding scan targets, configuring authentication, running DAST scans, and triaging findings through natural language.
    51
    8
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    A read-only MCP server for the Qualys PCI Merchant API that lets LLM assistants answer questions about PCI compliance posture, such as which hosts are failing PCI or listing high findings.
    7
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    Domain security reconnaissance for AI agents — 13 tools (DNS+DNSSEC, SSL/TLS, HTTP security headers, SPF/DKIM/DMARC email auth, port scan, ASN, RDAP/WHOIS) plus a one-shot security_scan returning a 0–100 Health Score (A–F). Free, no API key.
    23
    374 npm
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables AI coding assistants to scan projects for security issues such as leaked API keys, missing Supabase RLS, open Firebase rules, unauthenticated routes, and hallucinated packages, then fix and verify the results.
    8
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    GhostHunt is an MCP server that scans your development machine for API keys, tokens, and credentials hiding in places you forgot to check.
    4
    59 npm
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Provides passive OSINT reconnaissance for domains and IPs using public sources, with tools for WHOIS/RDAP, DNS, subdomain enumeration, Wayback Machine, HTTP headers, Shodan InternetDB, email security, TLS certificates, and ASN lookups, all without requiring API keys.
    2
    15
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to drive live Hack The Box labs through the real HTB Labs API — spawning, resetting and extending machines, submitting user and root flags with difficulty ratings, browsing challenges, and switching or downloading VPN configurations for the authenticated account. Every call hits the live API rather than cached content, with destructive actions annotated so hosts can gate them behind consent.
    22
    297 npm
    1
    MIT