Skip to main content
Glama
90,161 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

  • F
    license
    A
    quality
    B
    maintenance
    Enables AI shopping agents to verify a storefront's legitimacy before committing payment by checking domain registration, SSL certificate history, HTTPS validity, and known-scam blocklists, returning a trust score with explainable reasons and a clear recommendation.
    1
    42 npm
    -
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server that scans your lockfiles (npm, PyPI, Go, Rust, Ruby, PHP) for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. $14/mo — not per-seat.
    9
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables scanning Java (Maven) projects for known vulnerabilities via natural language, returning severity-sorted reports with CVSS scores and fix versions.
    3
    116 npm
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    A local MCP server that scans repository dependencies for known vulnerabilities (CVEs) using OSV.dev, enriches findings with NVD and CISA KEV data, and supports triage, remediation, and accepted risk management directly from an AI coding assistant.
    6
    19 npm
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Query CVEs, yanked releases, known exploits, and upgrade paths for any PostgreSQL version directly from your AI assistant.
    8
    Apache 2.0
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI agents to search, correlate, and monitor real-time vulnerability intelligence from NVD, CISA KEV, EPSS, and MITRE ATT&CK, including CVE details, critical CVE tracking, known exploited vulnerabilities, and exploitation probability scores.
    5
    2
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    A security filter that blocks dangerous code patterns by comparing normalized structural syntax trees against a blacklist of known threats using vector embeddings. It acts as a gatekeeper to prevent malicious code execution by identifying dangerous structures regardless of specific identifiers or literals.
    11
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Security scanner for vibe coders that checks npm packages for known vulnerabilities before installation, integrating with AI coding tools like Claude Code and Cursor.
    1
    -
  • A
    license
    B
    quality
    B
    maintenance
    Enables AI-assisted remote server diagnostics by auto-executing known read-only commands and routing high-risk changes to a real human for approval through DingTalk interactive cards. It uses structured argv instead of shell strings, default-deny policy, and HMAC-signed agent execution with hash-chained auditing so the model never holds SSH keys or approval power.
    7
    Apache 2.0
  • A
    license
    Not graded
    quality
    A
    maintenance
    deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, GitHub Actions, and more. It runs locally as a CLI and as an MCP server. It calls public package registry and OSV APIs directly; there is no hosted deptrust service to trust or configure.
    337 npm
    61
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Enables auditing an AI agent's guardrails by providing adversarial test prompts and scoring responses against known refusal/guardrail patterns.
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    A safety guard for AI assistants that inspects actions (file reads, queries, etc.) and classifies them as SAFE, SUSPICIOUS, or BLOCK with explanations, using both known-attack patterns and behavior-based zero-day detection.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    A keyless, defensive code-security auditor that scans codebases for hardcoded secrets, audits dependencies for known CVEs, and checks passwords against breach data using k-anonymity.
    1
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    MCP server to query and manage CISA Known Exploited Vulnerabilities catalog with EPSS overlay, enabling vulnerability checks and remediation deadline tracking.
    42 PyPI
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables CVE lookups and risk assessment by integrating CISA Known Exploited Vulnerabilities (KEV) data and CVSS metrics. It helps users prioritize patching efforts by ranking vulnerabilities based on exploitation status and calculated risk scores.
    MIT