Skip to main content
Glama
72,300 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

"ZAP" matching MCP servers:

  • A
    license
    -
    quality
    C
    maintenance
    Safe, self-hosted OWASP ZAP operator for guided AI security scans, findings, and reports. Requires a separately running OWASP ZAP daemon.
    63
    Apache 2.0
  • A
    license
    -
    quality
    C
    maintenance
    Integrates OWASP ZAP security testing with AI assistants through MCP, enabling automated vulnerability scanning and AI-powered security analysis during development. Supports multiple scan types including active, passive, and AJAX spider scans with real-time status updates.
    5
    MIT
  • F
    license
    -
    quality
    C
    maintenance
    A lightweight MCP server that wraps OWASP ZAP's REST API as Model Context Protocol tools, enabling AI agents to perform automated security scanning.
  • A
    license
    A
    quality
    D
    maintenance
    Connects Claude to SAP Cloud Platform Integration (CPI) to diagnose failed messages, review iFlows, deploy artifacts, and check credentials directly from your conversation.
    13
    6
    MIT
  • A
    license
    B
    quality
    D
    maintenance
    An MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.
    6
    MIT
  • A
    license
    B
    quality
    A
    maintenance
    AI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.
    47
    38
    MIT
  • F
    license
    B
    quality
    D
    maintenance
    Enables security auditing, penetration testing, and compliance validation with tools like Semgrep, Trivy, Gitleaks, and OWASP ZAP. Features strict project boundary enforcement and supports OWASP, CIS, and NIST compliance frameworks.
    7
  • A
    license
    -
    quality
    B
    maintenance
    Enables querying SAP Security Note metadata including Patch Day releases, CVSS scores, CVEs, affected components, and actively-exploited status via the Model Context Protocol.
    2
    Apache 2.0
  • A
    license
    -
    quality
    D
    maintenance
    Enables AI assistants to perform real-time SAP security audits and risk assessments by analyzing user roles, system parameters, and segregation of duties via RFC integration. It provides 17 specialized tools for monitoring security compliance and generating comprehensive audit reports directly from SAP systems.
    2
    Apache 2.0
  • F
    license
    -
    quality
    B
    maintenance
    An MCP server that exposes over 20 standard penetration testing utilities, such as Nmap, SQLMap, and OWASP ZAP, as callable tools for AI agents. It enables natural language control over complex security workflows for automated and interactive penetration testing.
    90
  • F
    license
    -
    quality
    C
    maintenance
    An MCP server over Streamable HTTP that exposes two SAP help-desk operations to an AI agent: sap_reset_password and sap_unlock_users.
  • F
    license
    -
    quality
    B
    maintenance
    Backend server that issues and validates alphanumeric software licenses tied to hardware IDs for SAP MCP servers (hana-b1, sap-btp, sap-cpi), storing products, licenses, and telemetry in PostgreSQL with online validation of expiry, revocation, and hardware matching.
  • A
    license
    A
    quality
    D
    maintenance
    A modular MCP server for analyzing PCAP files using protocol-specific analysis tools, enabling LLMs to read and analyze network packet captures from local paths or remote URLs.
    4
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Local MCP server for macOS that scans AI coding tool history (Claude Code, Cursor, Copilot, Cline, Codex, Gemini CLI) for leaked secrets. Finds API keys in chat transcripts, redacts with sieve:// placeholders, and runs commands with Keychain-injected secrets - no plaintext values ever returned.
    9
    1
    MIT