Security ToolsCAUTION
MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF, NMAP, Masscan and more. Integrate security testing and penetration testing into AI workflows.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[!WARNING] This repository is no longer actively maintained. All tools have been migrated to [Bolt](https://github.com/cyberstrikeus/bolt) — a fully rewritten, Docker-supported MCP security tool server. Please use Bolt instead: https://github.com/cyberstrikeus/bolt
[](LICENSE) [](https://github.com/cyproxio/mcp-for-security/stargazers) [](https://github.com/cyproxio/mcp-for-security/releases) ---
About Cyprox — The Future of AI-Driven Cybersecurity
Cyprox is pioneering the future of cybersecurity by combining artificial intelligence and security tools to empower organizations with next-level threat detection and automated response.
"The Future of Cybersecurity Humans and AI, Working Together..."
Cyprox
- 🚀 AI Driven Solutions: Cybersecurity solutions using Agentic-AI systems with an AI-driven approach
- 🌐 Community-Driven: Open-source projects fostering collaboration and rapid evolution.
- ⚡ Speed & Precision: Automated threat detection that reduces human latency.
- 🔒 Secure & Transparent: Trustworthy platform built with open standards.
Explore more at https://cyprox.io
🚀 Project Overview
MCP for Security repository contains Model Context Protocol (MCP) server implementations for various security testing tools, making them accessible through a standardized interface.
🌐 Installation
Docker
You can use all MCP servers through Docker using the cyprox/mcp-for-security Docker image. It can also be used from any MCP client with Docker support, such as the Cyprox platfor
194d242be8caOBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add wpscan-mcp -- npx -y [email protected]
{
"mcpServers": {
"wpscan-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (32)
17 read · 14 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
amass | read | Advanced subdomain enumeration and reconnaissance tool |
analyze-http-header | read | |
crtsh | read | Discovers subdomains from SSL certificate logs |
do-alterx | write | Execute Alterx, a tool that generates domain wordlists using pattern-based permutations for subdomain discovery and DNS enumeration |
do-arjun | write | Run Arjun to discover hidden HTTP parameters |
do-assetfinder | read | Find related domains and subdomains using assetfinder for a given target. |
do-cero | write | Execute Cero, a high-performance certificate-based subdomain enumeration tool. It connects to specified targets over TLS, extracts domain names from certificates (e.g., SAN fields), and outputs discovered hostnames. Useful for reconnaissance and OSINT tasks. |
do-commix | write | Run Smuggler to detect HTTP Request Smuggling vulnerabilities |
do-ffuf | write | Run ffuf with specified URL |
do-katana | read | Performs fast and configurable web crawling on the given target URLs, identifying endpoints, parameters, and JS-based links. |
do-masscan | write | Run masscan with specified target MASSCAN is a fast port scanner. The primary input parameters are the IP addresses/ranges you want to scan, and the port numbers. |
do-nmap | write | Run nmap with specified taget |
do-nuclei | write | Execute Nuclei, an advanced vulnerability scanner that uses YAML-based templates to detect security vulnerabilities, misconfigurations, and exposures in web applications and infrastructure. Nuclei offers fast scanning with a vast template library covering various security checks. |
do-scoutsuite-aws | read | Performs an AWS cloud security audit using Scout Suite for the given target settings, allowing service/region filtering and multiple authentication methods. |
do-smuggler | write | Run Smuggler to detect HTTP Request Smuggling vulnerabilities |
do-sqlmap | write | Run sqlmap with specified URL |
do-sslscan | read | |
do-waybackurls | write | Execute Waybackurls, a tool that fetches known URLs from the Wayback Machine archive for a given domain. This helps in discovering historical endpoints, forgotten API paths, and potentially vulnerable URLs that might not be directly accessible or linked from the current version of the website. |
do-wpscan | write | Run wpscan to analyze wordpress web sites |
get-nuclei-tags | read | Get Nuclei Tags |
getJsonReport | read | Generate and retrieve a comprehensive security analysis report in JSON format for a scanned mobile application. This report includes detailed findings about security vulnerabilities, permissions, API calls, and other security-relevant information. |
getRecentScans | read | Retrieve a list of recently performed security scans on the MobSF server, showing mobile applications that have been analyzed, their statuses, and basic scan information. |
getScanLogs | read | Retrieve detailed scan logs for a previously analyzed mobile application using its hash value. These logs contain information about the scanning process and any issues encountered. |
gowitness-batch-screenshot | read | Capture screenshots of multiple URLs using gowitness scan file command |
gowitness-list-screenshots | read | List all screenshot files in a directory |
gowitness-read-binary | read | Read a screenshot file and return it as binary data |
gowitness-report | read | Generate a report from gowitness screenshots and data |
gowitness-screenshot | write | Capture screenshot of the given URL using gowitness scan single. Can save to directory or return as binary data. |
httpx | read | Scans the given target domains and detects active HTTP/HTTPS services on ports like 80 and 443. |
scanFile | read | Scan a file that has already been uploaded to MobSF. This tool analyzes the uploaded mobile application for security vulnerabilities and provides a comprehensive security assessment report. |
shuffledns | destructive | DNS Brute force |
uploadFile | write | Upload a mobile application file (APK, IPA, or APPX) to MobSF for security analysis. This is the first step before scanning and must be done prior to using other analysis functions. |
Trust audit
CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (13 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
.DS_Store
-x Proxy URL (SOCKS5 or HTTP). For example: http://127.0.0.1:8080 or socks5://127.0.0.1:8080
-x Proxy URL (SOCKS5 or HTTP). For example: http://127.0.0.1:8080 or socks5://127.0.0.1:8080
proxy: z.string().optional().describe("Proxy server to route requests through. Format: protocol://IP:port (e.g., http://127.0.0.1:8080). Supported protocols depend on installed cURL version"),shuffledns
.DS_Store
proxy: "http://127.0.0.1:8080",
- `proxy`: Proxy to route traffic through (e.g., http://127.0.0.1:8080)
@modelcontextprotocol/sdk, zod, @types/node, typescript
@modelcontextprotocol/sdk, zod, @types/node, typescript
@modelcontextprotocol/sdk, zod, @types/node, typescript
@modelcontextprotocol/sdk, node-pty, zod, @types/node, typescript
@modelcontextprotocol/sdk, node-pty, zod, @types/node, typescript
Gates applied: no_behavioural_pass.
194d242be8cafull audit observations/trust-audit/mcp-server/cyproxio__security-tools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 194d242be8ca | CAUTION | B | 84 | first audit |
Questions
What is the Security Tools MCP server?
MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF, NMAP, Masscan and more. Integrate security testing and penetration testing into AI workflows.
What tools does Security Tools expose?
32 in total: 17 read-only, 14 that write, and 1 that can delete or overwrite (shuffledns). Every one is listed on this page with its risk.
Is Security Tools safe to connect to an agent?
With care. The audit graded it B (84/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Security Tools need?
No credential environment variables were found in its source, so it appears to need none.
How does Security Tools run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as wpscan-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (194d242be8ca), read on 2026-09-28. The repository is watched and re-audited when it changes.