Skip to main content
Glama
457,387 tools. Updated 2026-08-14 10:25

"OWASP" matching MCP tools:

Matching MCP Servers

Matching MCP Connectors

  • Scan project files for OWASP Top-10 vulnerabilities using pattern matching. Returns rule, severity, CWE, file, line, and message.
    MIT
  • Run a comprehensive security scan on a repository using multiple parallel scanners to detect vulnerabilities, secrets, and dependency CVEs, and receive a deduplicated severity-ranked report.
    MIT
  • Run a low-cost reality check on any claim to assess its plausibility and consistency. Receive a verdict, confidence score, and reasoning, with an abstention when uncertain.
    MIT
  • Scan MCP servers from registry or repository URL to detect vulnerabilities including tool poisoning, command injection, and data exfiltration. Maps results to OWASP Agentic and MCP Top 10.
    Apache 2.0
  • Map a regulatory requirement to its equivalents across frameworks such as EU AI Act, NIST AI RMF, and ISO 42001. See overlap strength and practitioner notes to reduce duplicate compliance work.
    Apache 2.0
  • Scans an API against OWASP API Security Top 10 rules (BOLA, broken authentication, etc.) using an OpenAPI 3.x spec and returns a findings report with remediation hints.
    MIT
  • Verify high-stakes claims via live web search and AI synthesis, returning verdict, confidence, reasoning, cited evidence; abstains rather than guessing.
    MIT
  • Analyzes a user query to recommend the most helpful MCP servers and pre-built workflow templates, providing rationale and cost estimates for efficient tool selection.
    Apache 2.0
  • Fetch OWASP ZAP vulnerability alerts, filter by URL and risk level, and view risk details, solutions, and evidence.
    MIT
  • Track untrusted data flows from sources to dangerous sinks, flag unsanitized paths with CWE IDs and fix suggestions. Framework-aware triage for data-flow security analysis.
    MIT
  • Generate a security findings report by aggregating taint analysis results and mapping them to a compliance framework such as OWASP, CWE, PCI DSS, or STIG.
    MIT
  • Map security findings or observations to OWASP LLM Top 10 (2025) categories with rule-based keyword and regex matching, returning top matches with evidence snippets and confidence scores.
    MIT
  • Search across indexed offline security knowledge bases from HackTricks, OWASP, and more. Retrieve ranked matches with source and snippet to ground answers in real documentation.
    MIT
  • Send crafted requests to a target URL to actively discover vulnerabilities via OWASP ZAP. Returns scan status and alert count.
    MIT