Skip to main content
Glama
642,901 tools. Updated 2026-10-05 23:05

"An open-source penetration testing framework" matching MCP tools:

  • Discover the investment-thesis catalog. Each entry is a descriptive case study that pairs an economic framework with a rule-based portfolio and the synthetic + historical stress evidence for that allocation. Returns one compact summary per thesis (slug, title, one-liner, tags, risk tiers, framework summary, headline finding). Call get_investment_thesis(slug) for the full framework / portfolio / stress evidence, or read the thesis://{slug} resource. Descriptive, not advisory — the agent decides what is suitable.
    ConnectorNo auth
  • Public mode returns FS AI RMF framework reference data only — not org-specific scoring. Use when assessing an organization FS AI RMF governance maturity stage or preparing a regulatory AI roadmap presentation. Returns INITIAL, MINIMAL, EVOLVING, or EMBEDDED classification with stage criteria and remediation priorities. Example: EVOLVING stage organizations have documented AI policies but lack systematic model validation — typical gap to EMBEDDED is 18-24 months and 12-15 additional controls. Connect org MCP for org-specific scoring. Source: FS AI Risk Management Framework. $0.02 USDC per call.
    ConnectorNo auth
  • List the framework ids this server covers (langchain, llamaindex, ollama, xrpl) with display names, aliases, homepages, and catalog topics. Use when you do not know which framework string to pass. Free tools/call (no x402). Not a docs search (search_ai_framework_docs) and not a deprecation dump (list_known_deprecations). Catalog-backed.
    ConnectorNo auth
  • Public mode returns FS AI RMF framework reference data only — not org-specific scoring. Use when assessing an organization FS AI RMF governance maturity stage or preparing a regulatory AI roadmap presentation. Returns INITIAL, MINIMAL, EVOLVING, or EMBEDDED classification with stage criteria and remediation priorities. Example: EVOLVING stage organizations have documented AI policies but lack systematic model validation — typical gap to EMBEDDED is 18-24 months and 12-15 additional controls. Connect org MCP for org-specific scoring. Source: FS AI Risk Management Framework. $0.02 USDC per call.
    ConnectorNo auth
  • Public mode returns FS AI RMF framework reference data only — not org-specific scoring. Use when assessing an organization FS AI RMF governance maturity stage or preparing a regulatory AI roadmap presentation. Returns INITIAL, MINIMAL, EVOLVING, or EMBEDDED classification with stage criteria and remediation priorities. Example: EVOLVING stage organizations have documented AI policies but lack systematic model validation — typical gap to EMBEDDED is 18-24 months and 12-15 additional controls. Connect org MCP for org-specific scoring. Source: FS AI Risk Management Framework. $0.02 USDC per call.
    ConnectorNo auth
  • Public mode returns FS AI RMF framework reference data only — not org-specific scoring. Use when assessing an organization FS AI RMF governance maturity stage or preparing a regulatory AI roadmap presentation. Returns INITIAL, MINIMAL, EVOLVING, or EMBEDDED classification with stage criteria and remediation priorities. Example: EVOLVING stage organizations have documented AI policies but lack systematic model validation — typical gap to EMBEDDED is 18-24 months and 12-15 additional controls. Connect org MCP for org-specific scoring. Source: FS AI Risk Management Framework. $0.02 USDC per call.
    ConnectorNo auth

Matching MCP Servers

Matching MCP Connectors

  • Read, write, and conversationally review open-source flashcards through split read/write MCP tools.

  • Unofficial MCP server for the Ionic Framework documentation, components and blog.

  • Public mode returns FS AI RMF framework reference data only — not org-specific scoring. Use when assessing an organization FS AI RMF governance maturity stage or preparing a regulatory AI roadmap presentation. Returns INITIAL, MINIMAL, EVOLVING, or EMBEDDED classification with stage criteria and remediation priorities. Example: EVOLVING stage organizations have documented AI policies but lack systematic model validation — typical gap to EMBEDDED is 18-24 months and 12-15 additional controls. Connect org MCP for org-specific scoring. Source: FS AI Risk Management Framework. $0.02 USDC per call.
    ConnectorNo auth
  • Public mode returns FS AI RMF framework reference data only — not org-specific scoring. Use when assessing an organization FS AI RMF governance maturity stage or preparing a regulatory AI roadmap presentation. Returns INITIAL, MINIMAL, EVOLVING, or EMBEDDED classification with stage criteria and remediation priorities. Example: EVOLVING stage organizations have documented AI policies but lack systematic model validation — typical gap to EMBEDDED is 18-24 months and 12-15 additional controls. Connect org MCP for org-specific scoring. Source: FS AI Risk Management Framework. $0.02 USDC per call.
    ConnectorNo auth
  • Public mode returns FS AI RMF framework reference data only — not org-specific scoring. Use when assessing an organization FS AI RMF governance maturity stage or preparing a regulatory AI roadmap presentation. Returns INITIAL, MINIMAL, EVOLVING, or EMBEDDED classification with stage criteria and remediation priorities. Example: EVOLVING stage organizations have documented AI policies but lack systematic model validation — typical gap to EMBEDDED is 18-24 months and 12-15 additional controls. Connect org MCP for org-specific scoring. Source: FS AI Risk Management Framework. $0.02 USDC per call.
    ConnectorNo auth
  • Return the Wheel of Heaven interpretive framework's reading of a topic — explicitly the project's own Raëlian-canon-centred position, NOT mainstream consensus. Accepts a framework topic (overview, hypothesis, terminology, timeline, sources, method) for the curated narrative documents, or any other term to get the framework reading from the closest wiki entry. Use fact-layer tools (get_passage, compare_traditions) for source-grounded data without this framing.
    ConnectorNo auth
  • Submits an enquiry to LEV Testing Cost — NOT a purchase, NOT a guaranteed quote. Step 1: call with the answers (keyed by field key from enquiry_fields) and consent=true; it validates and returns a summary, the consent line and a confirmation token — show the person the summary and the consent line. Step 2: only if the person agrees, call again with the same answers, consent=true and the confirmation token; the enquiry is then submitted, and the person receives an email with a link they must click before any provider sees it. Consent means the person has read and agreed to: "Send my contact details to up to three relevant LEV testing companies, chosen by LEV Testing Cost, who'll contact me directly. I'll be emailed each firm's name as my details go to it, and can stop any more firms getting them."
    ConnectorNo auth
  • Submits an enquiry to Penetration Testing Cost — NOT a purchase, NOT a guaranteed quote. Step 1: call with the answers (keyed by field key from enquiry_fields) and consent=true; it validates and returns a summary, the consent line and a confirmation token — show the person the summary and the consent line. Step 2: only if the person agrees, call again with the same answers, consent=true and the confirmation token; the enquiry is then submitted, and the person receives an email with a link they must click before any provider sees it. Consent means the person has read and agreed to: "Send my contact details to up to three relevant penetration testing providers, chosen by Penetration Testing Cost, who'll contact me directly. I'll be emailed each firm's name as my details go to it, and can stop any more firms getting them."
    ConnectorNo auth
  • A random sample of 12 records from the curated live feed of open defense/technology opportunities (multi-country, multi-source, deduplicated by country+source). Served entirely from a background-refreshed cache; if the cache is cold the tool returns a retryable 'warming_up' error rather than an empty list. No arguments. Requires a GlobalGov plan with API access (sign in with GlobalGov or connect an X-API-Key); anonymous callers get an 'unavailable_for_tier' result.
    ConnectorOAuth
  • Fact-check one specific marketing or capability claim about an agent against Hlido's independent testing. Returns Hlido's verdict (PASS/FAIL/PARTIAL/UNKNOWN) with a quoted evidence snippet and its source surface — or an honest null when that exact claim wasn't tested (absence of evidence, not proof). Use this to validate a vendor's specific promise before you rely on it.
    ConnectorNo auth
  • Get a source document from a SEC filing, served by ko.io. Returns a ko.io LINK to the rendered document (open in a browser) plus, optionally, an extracted text excerpt. Never returns the whole file — for full content, open the link or request a specific section. Requires a paid ko.io plan (Pro): on Free or keyless access the call returns an explicit plan-limit error. Use sec_list_filings / sec_get_filing_index (open on every plan) to find filings and their files.
    ConnectorNo auth
  • Returns SaaSDossier's two-state evidence framework: Documented and Question surfaced. A Question surfaced is not a finding of absence. SaaSDossier is the vendor's own record, made reviewable: a finished, dated, source-linked, human-reviewed evidence workproduct built only from vendor-published sources, recording 55 fixed fields across 10 domains for each vendor, with a source register listing every vendor page reviewed. Documented means the reviewed vendor-published sources established the field for the evidence date; Question surfaced means they did not, and each one becomes a buyer-ready follow-up question. Each dossier includes a SHA-256 identifier tied to the reviewed evidence record used for that release. Use this tool to understand what a state means, what the framework covers and where its boundaries are, before quoting or acting on any field.
    ConnectorNo auth
  • Fetch the full content of a chapter by loop slug and node. Loops not marked open require entitlement; every published loop is currently open and free. Does not log an invocation; run_chapter is the variant that runs the framework and logs.
    ConnectorNo auth
  • Create a NEW knowledge artifact from Anima's knowledge-base template. Returns a ready artifact; never edits an existing one. Call with no arguments, or with an optional name (defaults to "Untitled project") and workspaceId. No files, ZIP upload, framework, or artifact type are accepted. The template supplies the initial files and determines the framework. Returns the sessionId, initial revision, artifactUrl, name, framework, fileCount, skippedFiles, and applicable preview URLs and Git access. Share artifactUrl with the human. Use artifact-explore and artifact-edit to inspect and change its contents. Only use artifact-publish when the user explicitly asks for a public deployment.
    ConnectorOAuth
  • List the WebDriver sessions currently open on the testing grid, with their ids and negotiated capabilities. Use it to recover a sessionId you lost track of, or to see what is still holding a node before opening another session. Covers browser and mobile sessions alike. This is not a device list — for the phones and tablets available to drive, use device_list.
    ConnectorOAuth
  • Find records in a dated snapshot of the public vnish.global firmware catalog. Use the exact model ID; narrow by board code and version if known. Returns file size, SHA-256 and source links. A catalog record does not establish device compatibility, package authenticity, or successful hardware testing. Does not download or install firmware.
    ConnectorNo auth
  • Read the Bridge integration guide for a topic — the supported, opinionated way to consume Bridge from application code. Call this BEFORE writing or changing app code that reads a feature flag, renders billing or team UI, or wires authentication, and before hand-rolling anything against the SDK: the SDKs ship declarative surfaces for these cases (components, route guards, decorators) and reimplementing them against SDK internals is the most common integration mistake. Per-framework topics (framework REQUIRED): integration (first-time setup) | auth | feature-flags | billing | team | branding. Framework-agnostic MASTER topics (framework is IGNORED — omit it): master, the end-to-end auth integration prompt served by `bridge guide`, which orchestrates project discovery and then routes to the per-framework guides; flags-master and billing-master, the same orchestration for a flags-only or billing-only integration; mechanisms, how limits, upgrades and customization work; orientation, what Bridge does (the same map get_started returns); fit-together, how roles, plans, limits and flags fit together; integration-success, the message to show the developer when an integration is done. Before setting up flags, roles, plans or limits, read topic=fit-together. Start at topic=master when integrating Bridge into a project for the first time. framework: svelte | react | angular | nextjs | nestjs | express — pass the one the target app actually uses; this server cannot detect it. Returns the guide as markdown plus its source URL. Guidance is a default, not a mandate — follow the user's stated preference when it differs.
    ConnectorOAuth