PentestBLOCK
NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR, hashcat, wordlist building, and more.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@DMontgomery40/pentest-mcp) [](https://mseep.ai/app/fa558a10-f45c-4668-9bb6-15630dd51f27)
Professional penetration-testing MCP server with modern transport/auth support and expanded recon tooling.
What Changed in 0.9.0
- Upgraded MCP SDK to
@modelcontextprotocol/sdk@^1.26.0 - Kept MCP Inspector at the latest release (
@modelcontextprotocol/inspector@^0.20.0) with bundled launcher - Streamable HTTP is now the primary network transport (
MCP_TRANSPORT=http) - SSE is still available only as a deprecated compatibility mode
- Added bearer-token auth with OIDC JWKS and introspection support
- Added first-class tools:
subfinderEnum,httpxProbe,ffufScan,nucleiScan,trafficCapture,hydraBruteforce,privEscAudit,extractionSweep - Added report-admin tools:
listEngagementRecords,getEngagementRecord - Added SoW capture flow for reports using MCP elicitation (
scopeMode=ask) with safe template fallback - Hardened command resolution so web probing uses
httpx-toolkit(preferred) or validated ProjectDiscoveryhttpx, avoiding PythonhttpxCLI collisions - Integrated bundled MCP Inspector launcher (
pentest-mcp inspector) - Runtime baseline is now Node.js 22.7.5+
- Added invocation metadata in new tool outputs when auth/session context is available
Included Tools
nmapScanrunJohnTheRipperrunHashcatgobusterniktosubfinderEnumhttpxProbeffufScannucleiScantrafficCapturehydraBruteforceprivEscAuditextractionSweepgenerateWordlistlistEngagementRecordsgetEngagementRecordcreateClientReportcancelScan
Quick Start
Install
npm install -g pentest-mcp
Run locally (stdio)
pentest-mcp
Launch bundled MCP Inspector (no separate install)
pentest-mcp inspector
68e76b51087dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add pentest-mcp --env MCP_AUTH_AUDIENCE=${MCP_AUTH_AUDIENCE} --env MCP_AUTH_ENABLED=${MCP_AUTH_ENABLED} --env MCP_AUTH_MODE=${MCP_AUTH_MODE} --env MCP_AUTH_SCOPES=${MCP_AUTH_SCOPES} -- npx -y [email protected]{
"mcpServers": {
"pentest-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MCP_AUTH_AUDIENCE": "${MCP_AUTH_AUDIENCE}",
"MCP_AUTH_ENABLED": "${MCP_AUTH_ENABLED}",
"MCP_AUTH_MODE": "${MCP_AUTH_MODE}",
"MCP_AUTH_SCOPES": "${MCP_AUTH_SCOPES}"
}
}
}
}Exposed tools (19)
19 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cancelScan | read | |
createClientReport | read | |
extractionSweep | read | |
ffufScan | read | |
generateWordlist | read | |
getEngagementRecord | read | |
gobuster | read | |
httpxProbe | read | |
hydraBruteforce | read | |
listEngagementRecords | read | |
nikto | read | |
nmapScan | read | |
nucleiScan | read | |
privEscAudit | read | |
runHashcat | read | |
runJohnTheRipper | read | |
setMode | read | |
subfinderEnum | read | |
trafficCapture | read |
Trust audit
BLOCKgrade F · trust 32/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
argv-payload.d.ts
argv-payload.js
argv-payload.js.map
exec(sql: string): void;
exec(input?: URLPatternInput, baseURL?: string | URL): URLPatternResult | null;
var deprecatedfn = new Function('fn', 'log', 'deprecate', 'message', 'site','return function (' + args + ') {' +exec();
request ~ requests
ntypescript ~ typescript
# MIT License
.DS_Store
.DS_Store
.DS_Store
.DS_Store
.DS_Store
node_modules/.bin/acorn
node_modules/.bin/fxparser
node_modules/.bin/node-which
node_modules/.bin/ts-node
node_modules/.bin/ts-node-cwd
"chars": "€پ‚ƒ„...†‡ˆ‰ٹ‹Œچژڈگ‘’“”•–—کTMڑ›œں ،¢£¤¥¦§ ̈©ھ«¬® ̄°±23 ́μ¶· ̧1؛»1⁄41⁄23⁄4؟ہءآأؤإئابةتثجحخدذرزسشصض×طظعغـفقكàلâمنهوçèéêëىيîïًٌٍَôُِ÷ّùْûüے"
"chars": "«»...“”�•‘’� กขฃคฅฆงจฉชซฌญฎฏฐฑฒณดตถทธนบปผฝพฟภมยรฤลฦวศษสหฬอฮฯะัาําิีึืฺุู–—฿เแโใไๅๆ็่้๊๋์ํTM๏๐๑๒๓๔๕๖๗๘๙®©����"
<div style="background-color: white; padding: 4px; padding-bottom: 8px;" alt="stainless">
.DS_Store
Gates applied: no_behavioural_pass.
68e76b51087dfull audit observations/trust-audit/mcp-server/dmontgomery40__pentest-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 68e76b51087d | BLOCK | F | 32 | first audit |
Questions
What is the Pentest MCP server?
NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR, hashcat, wordlist building, and more.
What tools does Pentest expose?
19 in total: 19 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Pentest safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (32/100) and found 11 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Pentest need?
It reads MCP_AUTH_AUDIENCE, MCP_AUTH_ENABLED, MCP_AUTH_MODE, MCP_AUTH_SCOPES, MCP_OAUTH_CLIENT_ID, MCP_OAUTH_CLIENT_SECRET, MCP_OAUTH_ENABLED, MCP_OAUTH_PROVIDER_URL and MCP_OAUTH_SCOPES from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Pentest run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as pentest-mcp at 0.9.1.
How current is this page?
The grade is for one exact copy of the source (68e76b51087d), read on 2026-10-07. The repository is watched and re-audited when it changes.