Atlas / MCP servers / commonhuman-lab / NyxStrike

NyxStrikeBLOCK

mcp/commonhuman-lab/nyxstrike

AI Powered penetration testing Platform for offensive security research

Verdict
BLOCK
Grade
F
Trust score
42 /100
Exposed tools
6 5r · 1w · 0d
Transport
—
License
NOASSERTION
Stars
156
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI-powered offensive security orchestration engine

What is NyxStrike?

NyxStrike connects LLM agents to real offensive security tools and executes full attack chains — from recon to exploitation.

200+ tools · 50+ categories · AI decision engine · Tamper-evident evidence chain

🚀 Quick Start (Installation)

Get a full offensive security environment running in minutes.
git clone https://github.com/CommonHuman-Lab/nyxstrike.git
cd nyxstrike

./nyxstrike.sh -a               # Setup + start server
./nyxstrike.sh -a -t            # + install external tools
Full flag reference: Wiki — Installation & Flags

Verify Setup

Open http://localhost:8888 to access the dashboard.

Some tools (e.g. nmap, masscan) require elevated privileges for specific scan modes. Use a dedicated test VM and least-privilege setup where possible.

🔌 AI Agent Integrations (MCP)

Connect NyxStrike to any MCP-compatible AI client — OpenCode, Cursor, Claude Desktop, VS Code Copilot, Roo Code, and more.

Open http://localhost:8888/#/help for help with configurations.

Universal MCP Command

/path/to/nyxstrike/nyxstrike-env/bin/python3 \
/path/to/nyxstrike/nyxstrike_mcp.py \
--server http://127.0.0.1:8888 \
--profile full

OpenCode

{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"nyxstrike": {
"type": "local",
"command": [
"/path/to/nyxstrike/nyxstrike-env/bin/python3",
"/path/to/nyxstrike/nyxstrike_mcp.py",
"--server",
"http://127.0.0.1:8888",
"--profile",
"full"
],
"enabled": true
}
}
}
Config snippets for Claude Desktop, Cursor, VS Code Copilot, and security options: [Wi
Read from source at commit 3f26b9c88a91OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add nyxstrike --env NYXSTRIKE_API_TOKEN=${NYXSTRIKE_API_TOKEN} --env NYXSTRIKE_CRED_ENC_KEY=${NYXSTRIKE_CRED_ENC_KEY} -- uvx nyxstrike
claude-desktop
{
  "mcpServers": {
    "nyxstrike": {
      "command": "uvx",
      "args": [
        "nyxstrike"
      ],
      "env": {
        "NYXSTRIKE_API_TOKEN": "${NYXSTRIKE_API_TOKEN}",
        "NYXSTRIKE_CRED_ENC_KEY": "${NYXSTRIKE_CRED_ENC_KEY}"
      }
    }
  }
}
03

Exposed tools (6)

5 read · 1 write · 0 destructive.

ToolRiskDescription
classify_taskread
nyxstrike_h2csmugglerread
nyxstrike_net_pingread
run_toolwrite
sshreadtry:
telnetreadtry:
04

Trust audit

BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (19 observation(s))
Network
declared (22 observation(s))
Shell
declared (11 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
backend/server_core/generators/ai_exploit_generator.py:283
b64decode( ... 
exec(
Why it matters. decodes a payload and executes it
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
frontend/ui/src/app/demo.ts:513
secret: '-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAA...(truncated)\n-----END OPENSSH PRIVATE KEY-----',
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
frontend/ui/src/api/types/payload-workbench.ts
payload-workbench.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHInventory / provenance · inv.suspicious_name · CWE-1104
frontend/ui/src/components/tool-run/payload.ts
payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp_client/registrar.py:76
exec(compile(src, f"<toolspec:{spec.name}>", "exec"), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
frontend/dashboard/assets/demo-BVWMV9-U.js:33
-----END OPENSSH PRIVATE KEY-----`,service:`ssh`,host:`10.0.0.55`,port:22,source_tool:`gobuster`,evidence:`Found at https://example.com/backup/.ssh/id_rsa (HTTP 200)`,tags:[`ssh`,`private-key`],verifi
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
frontend/dashboard/assets/demo-BVWMV9-U.js:42
region = us-east-1`,path:`/home/ubuntu/.aws/credentials`,host:`10.0.0.55`,source_tool:`nuclei`,tags:[`aws`,`cloud`,`credentials`],notes:`Exposed in public S3 bucket listing — rotate immediately`,sessi
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
frontend/ui/src/app/demo.ts:518
evidence: 'Found at https://example.com/backup/.ssh/id_rsa (HTTP 200)',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
frontend/ui/src/app/demo.ts:609
path: '/home/ubuntu/.aws/credentials',
Why it matters. touches a credential store
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
backend/server_core/workflows/bugbounty/workflow.py:155
{"name": "Cloud Metadata", "payloads": ["http://169.254.169.254/latest/meta-data/"]},
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
backend/server_api/web_framework/browser_agent.py:182
resp = requests.get(page_info.get('url', ''), timeout=10, verify=False)
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
backend/server_api/web_framework/browser_agent.py:262
r = requests.get(test_url, timeout=8, verify=False)
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
backend/server_core/tool_specs/web_scan.py:312
argv.append("--insecure")
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
mcp_client/api_client.py:24
self.session.verify = False  # Disable SSL verification for self-signed certs
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
backend/server_core/payload_workbench/registry.py:73
category_pkg = importlib.import_module(f"backend.server_core.payload_workbench.operations.{category_name}")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
backend/server_core/workbench/registry.py:76
category_pkg = importlib.import_module(f"backend.server_core.workbench.operations.{category_name}")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
mcp_client/registrar.py:84
module = importlib.import_module(f"backend.server_core.tool_specs.{category}")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/server_core/tool_specs/vuln_intel.py:390
valid_attack_types = ["rce", "privilege_escalation", "persistence", "exfiltration", "xss", "sqli", "lfi", "ssrf"]
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/server_core/tool_specs/vuln_intel.py:533
"Data staging and exfiltration",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/server_core/tool_specs/vuln_intel.py:583
"Data exfiltration indicators",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/server_core/tool_specs/vuln_intel.py:707
ParamSpec("attack_type", str, required=True, help_text="Type of attack (rce, privilege_escalation, persistence, exfiltration, xss, sqli)"),
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/server_core/tool_specs/wifi_pentest.py:401
ParamSpec("ssid_wordlist", str, default="", help_text="Wordlist of SSIDs for beacon flood mode"),
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
backend/server_api/web_framework/browser_agent.py:60
chrome_options.add_argument(f'--proxy-server=http://127.0.0.1:{proxy_port}')
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
backend/server_api/web_framework/http_framework.py:31
'http': f'http://127.0.0.1:{proxy_port}',
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
frontend/dashboard/assets/NoteModal-D4A7gZlA.js:24
outline: none; border-width: 0; outline: none; overflow: hidden; opacity: .05; filter: alpha(opacity=5);`;var m;c&&(m=i.ownerDocument.defaultView.scrollY),r.input.focus(),c&&i.ownerDocument.defaultVie

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 3f26b9c88a91full audit observations/trust-audit/mcp-server/commonhuman-lab__nyxstrike.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-073f26b9c88a91BLOCKF42first audit
06

Questions

What is the NyxStrike MCP server?

AI Powered penetration testing Platform for offensive security research

What tools does NyxStrike expose?

6 in total: 5 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is NyxStrike safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (42/100) and found 14 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does NyxStrike need?

It reads NYXSTRIKE_API_TOKEN and NYXSTRIKE_CRED_ENC_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (3f26b9c88a91), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement