Atlas / MCP servers / fuzzinglabs / Security Hub

Security HubSAFE

mcp/fuzzinglabs/security-hub

A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
69 61r · 8w · 0d
Transport
stdio
License
MIT
Stars
794
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/FuzzingLabs/mcp-security-hub/actions/workflows/build.yml) [](https://github.com/FuzzingLabs/mcp-security-hub/actions/workflows/security-scan.yml) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io/)

Production-ready, Dockerized MCP (Model Context Protocol) servers for offensive security tools. Enable AI assistants like Claude to perform security assessments, vulnerability scanning, and binary analysis.

Features

  • 38 MCP Servers covering reconnaissance, web security, binary analysis, blockchain security, cloud security, code security, secrets detection, threat intelligence, OSINT, Active Directory, fuzzing, and more
  • 300+ Security Tools accessible via natural language through Claude or other MCP clients
  • Production Hardened - Non-root containers, minimal images, Trivy-scanned
  • Docker Compose orchestration for multi-tool workflows
  • CI/CD Ready with GitHub Actions for automated builds and security scanning

Quick Start

# Clone the repository
git clone https://github.com/FuzzingLabs/mcp-security-hub
cd mcp-security-hub

# Build all MCP servers
docker-compose build

# Start specific servers
docker-compose up nmap-mcp nuclei-mcp -d

# Verify health
docker-compose ps

Configure Claude Desktop / Claude Code

Important: You must build the image

Read from source at commit dddbfe993d4dOBSERVED · 2026-09-27
02

Exposed tools (69)

61 read · 8 write · 0 destructive.

ToolRiskDescription
binwalk_entropyreadAnalyze file entropy to detect compressed or encrypted sections.
binwalk_extractreadExtract embedded files and filesystems from firmware.
binwalk_hexdumpreadDisplay hex dump of a file section. Useful for examining
binwalk_scanreadScan a firmware file for embedded files, filesystems, and signatures.
boofuzz_create_scriptwriteCreate and save a Boofuzz Python script on the server. The script should accept
boofuzz_get_resultsreadRetrieve the crash log or audit results from a fuzzing session.
boofuzz_list_scriptsreadList all saved fuzzer scripts.
boofuzz_run_fuzzerwriteExecute a saved Boofuzz fuzzer script against a target. Runs asynchronously with a timeout.
capa_analyzereadAnalyze a binary file for capabilities using Mandiant
damlviewer_generate_tablereadGenerate a DAML access-control markdown table from a project directory or a single `.daml` file.
dharma_generatereadGenerate test cases using a Dharma grammar file located on the server.
dharma_generate_customreadGenerate test cases from a custom Dharma grammar provided as a string. Useful for dynamically generated grammars or quick testing without saving files.
fetch_wayback_urlsreadFetch all URLs from the Wayback Machine for a given domain.
ffuf_customreadCustom fuzzing with full control over all options.
ffuf_dirreadDirectory and file discovery fuzzing.
ffuf_paramreadParameter fuzzing.
ffuf_vhostreadVirtual host discovery.
get_analysis_resultsreadRetrieve results from a previous analysis.
get_fetch_resultsreadRetrieve results from a previous waybackurls fetch by fetch ID.
get_fuzz_resultsreadRetrieve results from a previous fuzzing session by scan ID.
get_run_resultswriteRetrieve results from a previous run by run ID.
get_scan_resultsreadRetrieve results from a previous scan by scan ID.
gitleaks_detectreadQuick scan provided content (text/code) for secrets.
gitleaks_scan_dirreadScan a directory for secrets without git history analysis.
gitleaks_scan_reporeadScan a git repository for secrets and credentials.
list_active_fetchesreadList currently running waybackurls fetches.
list_active_runsreadList currently running DAML viewer jobs.
list_active_scansreadList currently running scans.
list_checksreadList available security checks for a cloud provider.
list_compliance_frameworksreadList available compliance frameworks for each cloud provider.
list_extractionsreadList all completed extractions with their file contents.
list_recent_searchesreadList recent exploit searches.
list_rulesetsreadList available YARA rule sets and their details.
list_runsreadList completed DAML viewer runs (most recent first).
list_templatesreadList available Nuclei template categories and common tags.
list_wordlistsreadList available wordlists for fuzzing.
masscan_scanreadFast port scan using masscan. Can scan millions of hosts per minute.
masscan_top_portsreadScan the top 20 most common ports on target(s).
medusa_fuzzwriteRun the Medusa fuzzing process.
medusa_get_configreadRead medusa.json.
medusa_initreadInitialize Medusa in the current directory.
medusa_update_configwriteUpdate medusa.json fields.
nuclei_scanreadComprehensive vulnerability scan using Nuclei templates.
os_detectionreadFingerprint the operating system of the target.
port_scanreadScan ports on a target host or network.
prowler_compliancereadCheck cloud environment against compliance frameworks
prowler_scanwriteRun security assessment on AWS, Azure, GCP, or Kubernetes.
quick_scanreadFast scan of the 100 most common ports with service detection.
script_scanwriteRun NSE (Nmap Scripting Engine) scripts against target.
searchsploit_examinereadGet the code/content of a specific exploit by EDB-ID.
searchsploit_searchreadSearch Exploit-DB for exploits by keyword.
service_scanreadDetect service versions on target ports.
solazy_dottingreadReinsert functions (clusters) into a reduced CFG `.dot` using a JSON config.
solazy_fetcherreadFetch a deployed program bytecode (or account) from a Solana RPC endpoint.
solazy_recapreadGenerate an audit-friendly markdown recap for an Anchor project.
solazy_reversereadReverse engineer a compiled Solana sBPF `.so` file.
solazy_sastwriteRun SAST (Starlark rules) on an Anchor or SBF project directory.
sql_dumpreadDump data from database tables. Use responsibly and only on authorized targets.
sql_enumeratereadEnumerate databases, tables, or columns from a vulnerable target.
sql_scanreadScan a URL for SQL injection vulnerabilities.
sql_testreadQuick test to check if a parameter is injectable.
template_scanreadScan with specific template categories.
trivy_generate_sbomreadGenerate a Software Bill of Materials (SBOM) for an image.
trivy_scan_configreadScan IaC files (Terraform, Dockerfile, Kubernetes YAML, etc.)
trivy_scan_filesystemreadScan a filesystem path or git repository for vulnerabilities
trivy_scan_imagereadScan a container image for vulnerabilities.
whatweb_scanreadIdentify web technologies, CMS, frameworks, and server software.
yara_scanreadScan files or directories using YARA rules for malware detection
yara_scan_with_rulesreadScan files using custom inline YARA rules.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
web-security/ffuf-mcp/server.py:362
"description": "Target URL (e.g., https://10.10.10.10)",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.trivyignore
.trivyignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
web-security/burp-mcp/README.md:79
2. Configure Claude Desktop to connect to `http://127.0.0.1:9876`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
binary-analysis/binwalk-mcp/requirements.txt
mcp, pydantic, pydantic-settings
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
binary-analysis/capa-mcp/requirements.txt
mcp, pydantic, pydantic-settings
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
binary-analysis/yara-mcp/requirements.txt
mcp, pydantic, pydantic-settings
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
blockchain/daml-viewer-mcp/requirements.txt
mcp, pydantic, pydantic-settings
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
blockchain/medusa-mcp/requirements.txt
mcp, pydantic, pydantic-settings
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha dddbfe993d4dfull audit observations/trust-audit/mcp-server/fuzzinglabs__security-hub.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-27dddbfe993d4dSAFEB89first audit
05

Questions

What is the Security Hub MCP server?

A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.

What tools does Security Hub expose?

69 in total: 61 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Security Hub safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Security Hub need?

No credential environment variables were found in its source, so it appears to need none.

How does Security Hub run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (dddbfe993d4d), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement