Skip to main content
Glama
97,619 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

  • F
    license
    A
    quality
    C
    maintenance
    AgentAvow scans any MCP server, package (npm/PyPI/crates/Docker/Hugging Face), or GitHub repo and returns a signed, offline-recomputable 0–100 trust score with a plain safe / needs-review verdict. Authless and read-only, no account.
    10
    5
    -
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server that scans your lockfiles (npm, PyPI, Go, Rust, Ruby, PHP) for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. $14/mo — not per-seat.
    9
    84 PyPI
    1
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Package intelligence for AI coding agents that checks npm and PyPI package health, deprecation, vulnerabilities, bundle size, and compares alternatives.
    5
    -
  • A
    license
    A
    quality
    D
    maintenance
    Acts as a security checkpoint for AI coding agents by intercepting package installations to verify existence, check against CVE databases, and block vulnerable or hallucinated dependencies before they reach your codebase. Provides seven security tools including pre-install gates, full project audits, safe version recommendations, and deep transitive dependency scanning for npm and PyPI packages.
    7
    39 npm
    4
    MIT
  • A
    license
    B
    quality
    A
    maintenance
    Pre-install gate for AI coding agents. Checks npm, PyPI and crates.io package names before an install runs and blocks names that do not exist, were registered after models invented them, or sit one keystroke from a popular package. CLI, GitHub Action and MCP server. Apache 2.0.
    1
    1
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Deterministic supply-chain provenance, SBOM/AI-BOM generation, and dependency risk analysis for npm and PyPI packages, with 14 security rules and verifiable reports.
    1
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    deptrust is a CLI that checks package versions for known vulnerabilities across npm, PyPI, crates.io, Go modules, RubyGems, NuGet, Maven, Packagist, pub.dev, CocoaPods, Hex.pm, Hackage, GitHub Actions, and more. It runs locally as a CLI and as an MCP server. It calls public package registry and OSV APIs directly; there is no hosted deptrust service to trust or configure.
    192 npm
    61
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI agents to vet npm and PyPI packages before installation, reporting typosquats, vulnerabilities in the selected version, publisher changes, and names that don't exist or were published within the last 30 days. It also exposes DNS, WHOIS, email, JWT and file/image utilities as tools over Streamable HTTP, with no signup or API key required.
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    MCP server for comprehensive PyPI package intelligence, providing tools for dependency analysis, security scanning, health scoring, license compliance, and trend tracking.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables users to look up package versions, scan for vulnerabilities, and analyze dependencies across multiple registries (npm, Maven, PyPI, etc.) using exact version recommendations for security.
    4
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables checking whether specific symbols exist in a given npm/PyPI package version, whether packages exist, and which imports a diff adds, by querying published package artifacts without running code.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    An MCP server that verifies npm and PyPI packages before installation, checking for existence, known vulnerabilities, OpenSSF scorecard, and typosquatting, returning an ALLOW/WARN/BLOCK verdict.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    An MCP server that enables coding agents to safely verify npm/PyPI packages, retrieve cited briefs, discover GitHub repos, and fetch canonical docs, with fail-closed OSV vulnerability checks and injection-hardened output.
    143 npm
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Scans npm, PyPI, and GitHub for typosquatting and brand impersonation, risk-scores findings, and drafts takedown notices.
    -