Atlas / MCP servers / cyproxio / Security Tools

Security ToolsCAUTION

mcp/cyproxio/security-tools

MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF, NMAP, Masscan and more. Integrate security testing and penetration testing into AI workflows.

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
32 17r · 14w · 1d
Transport
stdio
License
MIT
Stars
629
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[!WARNING] This repository is no longer actively maintained. All tools have been migrated to [Bolt](https://github.com/cyberstrikeus/bolt) — a fully rewritten, Docker-supported MCP security tool server. Please use Bolt instead: https://github.com/cyberstrikeus/bolt

[](LICENSE) [](https://github.com/cyproxio/mcp-for-security/stargazers) [](https://github.com/cyproxio/mcp-for-security/releases) ---

About Cyprox — The Future of AI-Driven Cybersecurity

Cyprox is pioneering the future of cybersecurity by combining artificial intelligence and security tools to empower organizations with next-level threat detection and automated response.

"The Future of Cybersecurity Humans and AI, Working Together..."

Cyprox

  • 🚀 AI Driven Solutions: Cybersecurity solutions using Agentic-AI systems with an AI-driven approach
  • 🌐 Community-Driven: Open-source projects fostering collaboration and rapid evolution.
  • ⚡ Speed & Precision: Automated threat detection that reduces human latency.
  • 🔒 Secure & Transparent: Trustworthy platform built with open standards.

Explore more at https://cyprox.io

🚀 Project Overview

MCP for Security repository contains Model Context Protocol (MCP) server implementations for various security testing tools, making them accessible through a standardized interface.

🌐 Installation

Docker

You can use all MCP servers through Docker using the cyprox/mcp-for-security Docker image. It can also be used from any MCP client with Docker support, such as the Cyprox platfor

Read from source at commit 194d242be8caOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add wpscan-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "wpscan-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (32)

17 read · 14 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
amassreadAdvanced subdomain enumeration and reconnaissance tool
analyze-http-headerread
crtshreadDiscovers subdomains from SSL certificate logs
do-alterxwriteExecute Alterx, a tool that generates domain wordlists using pattern-based permutations for subdomain discovery and DNS enumeration
do-arjunwriteRun Arjun to discover hidden HTTP parameters
do-assetfinderreadFind related domains and subdomains using assetfinder for a given target.
do-cerowriteExecute Cero, a high-performance certificate-based subdomain enumeration tool. It connects to specified targets over TLS, extracts domain names from certificates (e.g., SAN fields), and outputs discovered hostnames. Useful for reconnaissance and OSINT tasks.
do-commixwriteRun Smuggler to detect HTTP Request Smuggling vulnerabilities
do-ffufwriteRun ffuf with specified URL
do-katanareadPerforms fast and configurable web crawling on the given target URLs, identifying endpoints, parameters, and JS-based links.
do-masscanwriteRun masscan with specified target MASSCAN is a fast port scanner. The primary input parameters are the IP addresses/ranges you want to scan, and the port numbers.
do-nmapwriteRun nmap with specified taget
do-nucleiwriteExecute Nuclei, an advanced vulnerability scanner that uses YAML-based templates to detect security vulnerabilities, misconfigurations, and exposures in web applications and infrastructure. Nuclei offers fast scanning with a vast template library covering various security checks.
do-scoutsuite-awsreadPerforms an AWS cloud security audit using Scout Suite for the given target settings, allowing service/region filtering and multiple authentication methods.
do-smugglerwriteRun Smuggler to detect HTTP Request Smuggling vulnerabilities
do-sqlmapwriteRun sqlmap with specified URL
do-sslscanread
do-waybackurlswriteExecute Waybackurls, a tool that fetches known URLs from the Wayback Machine archive for a given domain. This helps in discovering historical endpoints, forgotten API paths, and potentially vulnerable URLs that might not be directly accessible or linked from the current version of the website.
do-wpscanwriteRun wpscan to analyze wordpress web sites
get-nuclei-tagsreadGet Nuclei Tags
getJsonReportreadGenerate and retrieve a comprehensive security analysis report in JSON format for a scanned mobile application. This report includes detailed findings about security vulnerabilities, permissions, API calls, and other security-relevant information.
getRecentScansreadRetrieve a list of recently performed security scans on the MobSF server, showing mobile applications that have been analyzed, their statuses, and basic scan information.
getScanLogsreadRetrieve detailed scan logs for a previously analyzed mobile application using its hash value. These logs contain information about the scanning process and any issues encountered.
gowitness-batch-screenshotreadCapture screenshots of multiple URLs using gowitness scan file command
gowitness-list-screenshotsreadList all screenshot files in a directory
gowitness-read-binaryreadRead a screenshot file and return it as binary data
gowitness-reportreadGenerate a report from gowitness screenshots and data
gowitness-screenshotwriteCapture screenshot of the given URL using gowitness scan single. Can save to directory or return as binary data.
httpxreadScans the given target domains and detects active HTTP/HTTPS services on ports like 80 and 443.
scanFilereadScan a file that has already been uploaded to MobSF. This tool analyzes the uploaded mobile application for security vulnerabilities and provides a comprehensive security assessment report.
shufflednsdestructiveDNS Brute force
uploadFilewriteUpload a mobile application file (APK, IPA, or APPX) to MobSF for security analysis. This is the first step before scanning and must be done prior to using other analysis functions.
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (13 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
ffuf-mcp/build/index.js:38
-x                  Proxy URL (SOCKS5 or HTTP). For example: http://127.0.0.1:8080 or socks5://127.0.0.1:8080
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
ffuf-mcp/src/index.ts:42
-x                  Proxy URL (SOCKS5 or HTTP). For example: http://127.0.0.1:8080 or socks5://127.0.0.1:8080
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
wpscan-mcp/src/index.ts:27
proxy: z.string().optional().describe("Proxy server to route requests through. Format: protocol://IP:port (e.g., http://127.0.0.1:8080). Supported protocols depend on installed cURL version"),
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
shuffledns
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
wpscan-mcp/readme.md:70
proxy: "http://127.0.0.1:8080",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
wpscan-mcp/readme.md:82
- `proxy`: Proxy to route traffic through (e.g., http://127.0.0.1:8080)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
alterx-mcp/package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
amass-mcp/package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
arjun-mcp/package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
assetfinder-mcp/package.json
@modelcontextprotocol/sdk, node-pty, zod, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
cero/package.json
@modelcontextprotocol/sdk, node-pty, zod, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 194d242be8cafull audit observations/trust-audit/mcp-server/cyproxio__security-tools.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28194d242be8caCAUTIONB84first audit
06

Questions

What is the Security Tools MCP server?

MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF, NMAP, Masscan and more. Integrate security testing and penetration testing into AI workflows.

What tools does Security Tools expose?

32 in total: 17 read-only, 14 that write, and 1 that can delete or overwrite (shuffledns). Every one is listed on this page with its risk.

Is Security Tools safe to connect to an agent?

With care. The audit graded it B (84/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Security Tools need?

No credential environment variables were found in its source, so it appears to need none.

How does Security Tools run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as wpscan-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (194d242be8ca), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement