Skip to main content
Glama
521,397 tools. Updated 2026-09-06 11:00

"OWASP" matching MCP tools:

  • Scan Electron source code to detect dangerous patterns: shell.openExternal with user input, disabled webSecurity, missing navigation restrictions, and unrestricted window creation. Fix OWASP-style vulnerabilities before deployment.
    MIT
  • Retrieve OWASP category details by ID for mobile app security testing. Provides specific OWASP Mobile Top 10 information to identify vulnerabilities.
    MIT
  • Run a low-cost reality check on any claim to assess its plausibility and consistency. Receive a verdict, confidence score, and reasoning, with an abstention when uncertain.
    MIT
  • Scan MCP servers from registry or repository URL to detect vulnerabilities including tool poisoning, command injection, and data exfiltration. Maps results to OWASP Agentic and MCP Top 10.
    Apache 2.0

Matching MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables querying OWASP security standards, including Top 10 lists for web, API, LLM, and mobile, ASVS 5.0 verification requirements, and defensive cheat sheets via MCP tools or plain-language questions.
    15
    MIT

Matching MCP Connectors

  • OWASP MCP — keyless.

  • Scan GitHub-hosted AI skills for vulnerabilities: prompt injection, malware, OWASP LLM Top 10.

  • Map a regulatory requirement to its equivalents across frameworks such as EU AI Act, NIST AI RMF, and ISO 42001. See overlap strength and practitioner notes to reduce duplicate compliance work.
    Apache 2.0
  • Scans an API against OWASP API Security Top 10 rules (BOLA, broken authentication, etc.) using an OpenAPI 3.x spec and returns a findings report with remediation hints.
    MIT
  • Verify high-stakes claims via live web search and AI synthesis, returning verdict, confidence, reasoning, cited evidence; abstains rather than guessing.
    MIT
  • Analyzes a user query to recommend the most helpful MCP servers and pre-built workflow templates, providing rationale and cost estimates for efficient tool selection.
    Apache 2.0
  • Fetch OWASP ZAP vulnerability alerts, filter by URL and risk level, and view risk details, solutions, and evidence.
    MIT
  • Generate a security findings report by aggregating taint analysis results and mapping them to a compliance framework such as OWASP, CWE, PCI DSS, or STIG.
    MIT
  • Map security findings or observations to OWASP LLM Top 10 (2025) categories with rule-based keyword and regex matching, returning top matches with evidence snippets and confidence scores.
    MIT
  • Search across indexed offline security knowledge bases from HackTricks, OWASP, and more. Retrieve ranked matches with source and snippet to ground answers in real documentation.
    MIT
  • Send crafted requests to a target URL to actively discover vulnerabilities via OWASP ZAP. Returns scan status and alert count.
    MIT
  • Scan SKILL.md packages and agent tool definitions for security vulnerabilities including tool poisoning, command injection, data exfiltration, and prompt injection. Maps findings to OWASP Agentic and MCP Top 10.
    Apache 2.0
  • Check OpenAPI or Swagger specs for API security flaws such as missing authentication, plaintext servers, and object ID enumeration. Outputs SECURE, REVIEW, or INSECURE verdict.
    MIT
  • Map security observations to OWASP LLM Top 10 categories using keyword and regex pattern matching. Returns top matching categories with evidence and confidence scores.
    MIT
  • Analyze code snippets for security vulnerabilities including OWASP Top 10, XSS, and SQL injection. Specify code and language to get results.
    Apache 2.0
  • Generate a comprehensive security assessment report by aggregating configuration scans and permission audits into a prioritized remediation plan with OWASP LLM Top 10 compliance notes.
    MIT
  • Verify a signed verdict receipt to confirm authenticity and detect tampering. Check Ed25519 signature against public key for cryptographic proof.
    MIT