Skip to main content
Glama
83,380 servers. Updated

Matching MCP tools:

Matching MCP Connectors:

  • A
    license
    A
    quality
    D
    maintenance
    Model Context Protocol server for npm registry. Enables searching packages, checking security, comparing versions, and validating compatibility.
    12
    57
    3
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Audits npm packages for supply-chain attacks (typosquatting, malicious install scripts, credential exfiltration) before installation, returning a SAFE/SUSPICIOUS/DANGEROUS verdict.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables conversational management of Nginx Proxy Manager, including reverse-proxy routing, TLS certificates, access lists, and stream forwards, with built-in safety guardrails for production use.
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Enables AI agents to interact with the npm registry, covering package intel, dist-tags, trusted publisher configuration, access and team governance, tokens, security advisories, and publishing, with read-only tools by default.
    3
    0
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    A Model Context Protocol server that enables AI-powered analysis of NPM packages through multiple tools for security vulnerability scanning, dependency analysis, package comparison, and quality assessment.
    19
    1,195
    18
    TypeScript
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Pre-install risk gate for npm packages. Stops AI coding agents from running malicious or lifecycle scripts run.
    1
    2
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    MCP security firewall (stdio): vet advertised tool definitions through static-scan → threat-feed → origin → pinning before they reach the model. Zero npm runtime deps. No secrets.
    6
    372
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Visual CVE audit dashboard for npm, Python, Go, and Rust projects. Scans your project manifests (package-lock.json, requirements.txt, go.sum, Cargo.lock) against OSV.dev live data, opens a browser dashboard for human review, then applies fixes only after explicit confirmation. Supports multi-service monorepos in one command.
    4
    12
    4
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    An MCP server that provides cross-validated npm dependency fitness verdicts, including deprecation, malicious detection, and safe migration target inference.
    2
    70
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    An MCP server that scans your lockfiles (npm, PyPI, Go, Rust, Ruby, PHP) for known vulnerabilities, enriches with EPSS exploit probability scores, and recommends fix versions. $14/mo — not per-seat.
    9
    1
    MIT
  • A
    license
    A
    quality
    B
    maintenance
    Enables AI coding agents and CI to vet npm dependencies before they reach the lockfile, flagging hallucinated, slopsquatted, or otherwise risky packages with evidence-backed verdicts.
    2
    0
    1
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Pre-install trust scoring & safety scanning for MCP servers, AI skills & npm packages — 15 signals incl. OSV/KEV/EPSS vuln intel and an auto-gate go/no-go.
    9
    128
    1
    MIT
  • F
    license
    A
    quality
    B
    maintenance
    Verifies which domain officially belongs to a software product, AI tool, or company, so the agent stops handing users lookalike download sites. Ownership only, never safety. Every verdict is backed by reproducible evidence; results carry the sentence the agent should say. Tools: get_official_url(name), verify_url(url). npm: @realurls/mcp; remote endpoint: https://api.realurls.org/mcp
    2
    -
  • A
    license
    A
    quality
    D
    maintenance
    Automatically scans project dependencies (npm, Composer) for security vulnerabilities using the OSV.dev database, providing real-time alerts and detailed remediation guidance directly in your IDE.
    1
    11
    1
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Lightweight Node.js dependency vulnerability audit tool with CLI and MCP Server modes. Supports npm/pnpm, full dependency chain tracing, remote GitHub repo auditing, and generates Markdown/HTML reports.
    1
    20
    1
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Tenant-bound MCP server for agent spend authorization, policy guardrails, evidence, escrow settlement, and portable receipts. Works with Cursor and Claude Code via stdio; npm (@paybond/kit) and Python (paybond-kit).
    31
    122
    1
    Apache 2.0
  • A
    license
    A
    quality
    D
    maintenance
    MCP security trust layer. Continuously monitors 800+ MCP packages on npm for install scripts, command injection, hardcoded secrets, capability drift, and publisher posture. Ships a GitHub Action policy gate for PR-level allow/warn/block decisions. 5 MCP tools, no API key required.
    8
    91
    1
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Verifies npm package names for safety, detecting typosquats and nonexistent packages before your coding agent installs them.
    2
    19
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    The MCP ecosystem is growing fast. Not every server on npm is safe. mcp-shield lets Claude audit any MCP server — local or from npm — before you trust it with your files, keys, and context.
    4
    138
    2
    MIT