Atlas / MCP servers / elitewa / AI DirScan

AI DirScanCAUTION

mcp/elitewa/ai-dirscan

可用于AI进行自动目录扫描的MCP辅助工具

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
2 2r · 0w · 0d
Transport
sse
License
—
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🔗 项目地址: https://github.com/Elitewa/ai_dirscan

📖 项目简介

本项目可以说是MCP+AI和传统安全融合的一个示范,鉴于现在关于MCP for Security的知识还不够完善,也算是抛砖引玉了,如果有更好的建议欢迎指出🤩

AI DirScan 是基于 MCP协议 的新一代智能安全扫描工具,创新性地将传统目录爆破工具 dirsearch 与大型语言模型(LLM)相结合,实现:

✨ 核心功能 ✅ 自动化目录扫描与状态码分析 ✅ 智能结果解析与漏洞关联分析 ✅ 主流大模型兼容支持(需自行配置API)

🚀 技术亮点

  • 采用 FastMCP 框架实现高并发处理
  • 使用mcp协议中的sse方案,增加对扫描工具超时优化
  • 支持 200/403/500 等状态码智能筛选分析
  • 可配合Cline进行扫描全流程自动化,产出相应md格式漏洞报告

🧑🏻💻 功能预览

该MCP工具可自动获取对话中的URL地址,并进行目录扫描

自动分析非200页面网页内容,可用于发现服务器版本泄露,框架类型版本泄露,网站绝对路径泄露等漏洞,并在分析完所有扫描得到的路径之后,会产出md格式漏洞报告(依赖于cline)

为节省LLM的api tokens,对扫描结果进行了数据筛选工作,以 状态码+返回包大小 作为判断标识,同样的组合仅保留分析一组

🛠️ 快速开始

环境要求

  • Python 3.10+
  • UV 虚拟环境工具
  • 支持的大模型API密钥
  • 新版Cline IDE插件

初始化环境

MacOS/Linux:

# 克隆仓库
git clone https://github.com/Elitewa/ai_dirscan.git
cd ai_dirscan
# 创建虚拟环境
uv venv .venv
# 激活环境
source .venv/bin/activate
# 安装虚拟环境依赖
uv add "mcp[cli]"
uv add requests
deactivate
# 退出虚拟环境,在系统主环境执行以下命令
cd dirsearch
pip install -r requirements.txt
pip install setuptools

Windows:

# 克隆仓库
git clone https://github.com/Elitewa/ai_dirscan.git
cd ai_dirscan
# 创建虚拟环境
uv venv .venv
# 激活环境
.venv\Scripts\activate.bat
# 安装依赖
uv add "mcp[cli]"
uv add requests
deactivate
# 退出虚拟环境,在系统主环境执行以下命令
cd dirsearch
pip install -r requirements.txt
pip install setuptools

对接Cline

进入项目目录,允许以下命令,开启sse服务

uv run main.py

如图便是开启成功

Vscode下载最新版Cline插件,进入远程MCP服务添加页面,名称自定义,URL填写 http://0.0.0.0:8000/sse,并保存

在已导入的MCP服务中,将超时时长设置为10min(视扫描时长而定),如果保存后无法连接mcp服务器,建议点击 Configu

Read from source at commit 74d6422ace0aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add ai-dirscan -- uvx ai-dirscan
claude-desktop
{
  "mcpServers": {
    "ai-dirscan": {
      "command": "uvx",
      "args": [
        "ai-dirscan"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
get_contentread
scan_dirread
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
dirsearch/lib/connection/requester.py:73
self.session.verify = False
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
sse
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:95
Vscode下载最新版Cline插件,进入远程MCP服务添加页面,名称自定义,URL填写 `http://0.0.0.0:8000/sse`,并保存
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
dirsearch/requirements.txt
PySocks, Jinja2, certifi, urllib3, cryptography, cffi, defusedxml, markupsafe
Why it matters. 18 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
assets/image-20250410162827424.png
assets/image-20250410162827424.png
Why it matters. 1212332 bytes not read
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
dirsearch/README.md:604
curl -fsSL https://get.docker.com | bash

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 74d6422ace0afull audit observations/trust-audit/mcp-server/elitewa__ai-dirscan.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0874d6422ace0aCAUTIONB84first audit
06

Questions

What is the AI DirScan MCP server?

可用于AI进行自动目录扫描的MCP辅助工具

What tools does AI DirScan expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is AI DirScan safe to connect to an agent?

With care. The audit graded it B (84/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does AI DirScan need?

No credential environment variables were found in its source, so it appears to need none.

How does AI DirScan run?

It speaks sse, so it runs as a service you connect to over the network. It is published on PyPI as ai-dirscan.

How current is this page?

The grade is for one exact copy of the source (74d6422ace0a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement