Security HubSAFE
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/FuzzingLabs/mcp-security-hub/actions/workflows/build.yml) [](https://github.com/FuzzingLabs/mcp-security-hub/actions/workflows/security-scan.yml) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io/)
Production-ready, Dockerized MCP (Model Context Protocol) servers for offensive security tools. Enable AI assistants like Claude to perform security assessments, vulnerability scanning, and binary analysis.
Features
- 38 MCP Servers covering reconnaissance, web security, binary analysis, blockchain security, cloud security, code security, secrets detection, threat intelligence, OSINT, Active Directory, fuzzing, and more
- 300+ Security Tools accessible via natural language through Claude or other MCP clients
- Production Hardened - Non-root containers, minimal images, Trivy-scanned
- Docker Compose orchestration for multi-tool workflows
- CI/CD Ready with GitHub Actions for automated builds and security scanning
Quick Start
# Clone the repository git clone https://github.com/FuzzingLabs/mcp-security-hub cd mcp-security-hub # Build all MCP servers docker-compose build # Start specific servers docker-compose up nmap-mcp nuclei-mcp -d # Verify health docker-compose ps
Configure Claude Desktop / Claude Code
Important: You must build the image
dddbfe993d4dOBSERVED · 2026-09-27Exposed tools (69)
61 read · 8 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
binwalk_entropy | read | Analyze file entropy to detect compressed or encrypted sections. |
binwalk_extract | read | Extract embedded files and filesystems from firmware. |
binwalk_hexdump | read | Display hex dump of a file section. Useful for examining |
binwalk_scan | read | Scan a firmware file for embedded files, filesystems, and signatures. |
boofuzz_create_script | write | Create and save a Boofuzz Python script on the server. The script should accept |
boofuzz_get_results | read | Retrieve the crash log or audit results from a fuzzing session. |
boofuzz_list_scripts | read | List all saved fuzzer scripts. |
boofuzz_run_fuzzer | write | Execute a saved Boofuzz fuzzer script against a target. Runs asynchronously with a timeout. |
capa_analyze | read | Analyze a binary file for capabilities using Mandiant |
damlviewer_generate_table | read | Generate a DAML access-control markdown table from a project directory or a single `.daml` file. |
dharma_generate | read | Generate test cases using a Dharma grammar file located on the server. |
dharma_generate_custom | read | Generate test cases from a custom Dharma grammar provided as a string. Useful for dynamically generated grammars or quick testing without saving files. |
fetch_wayback_urls | read | Fetch all URLs from the Wayback Machine for a given domain. |
ffuf_custom | read | Custom fuzzing with full control over all options. |
ffuf_dir | read | Directory and file discovery fuzzing. |
ffuf_param | read | Parameter fuzzing. |
ffuf_vhost | read | Virtual host discovery. |
get_analysis_results | read | Retrieve results from a previous analysis. |
get_fetch_results | read | Retrieve results from a previous waybackurls fetch by fetch ID. |
get_fuzz_results | read | Retrieve results from a previous fuzzing session by scan ID. |
get_run_results | write | Retrieve results from a previous run by run ID. |
get_scan_results | read | Retrieve results from a previous scan by scan ID. |
gitleaks_detect | read | Quick scan provided content (text/code) for secrets. |
gitleaks_scan_dir | read | Scan a directory for secrets without git history analysis. |
gitleaks_scan_repo | read | Scan a git repository for secrets and credentials. |
list_active_fetches | read | List currently running waybackurls fetches. |
list_active_runs | read | List currently running DAML viewer jobs. |
list_active_scans | read | List currently running scans. |
list_checks | read | List available security checks for a cloud provider. |
list_compliance_frameworks | read | List available compliance frameworks for each cloud provider. |
list_extractions | read | List all completed extractions with their file contents. |
list_recent_searches | read | List recent exploit searches. |
list_rulesets | read | List available YARA rule sets and their details. |
list_runs | read | List completed DAML viewer runs (most recent first). |
list_templates | read | List available Nuclei template categories and common tags. |
list_wordlists | read | List available wordlists for fuzzing. |
masscan_scan | read | Fast port scan using masscan. Can scan millions of hosts per minute. |
masscan_top_ports | read | Scan the top 20 most common ports on target(s). |
medusa_fuzz | write | Run the Medusa fuzzing process. |
medusa_get_config | read | Read medusa.json. |
medusa_init | read | Initialize Medusa in the current directory. |
medusa_update_config | write | Update medusa.json fields. |
nuclei_scan | read | Comprehensive vulnerability scan using Nuclei templates. |
os_detection | read | Fingerprint the operating system of the target. |
port_scan | read | Scan ports on a target host or network. |
prowler_compliance | read | Check cloud environment against compliance frameworks |
prowler_scan | write | Run security assessment on AWS, Azure, GCP, or Kubernetes. |
quick_scan | read | Fast scan of the 100 most common ports with service detection. |
script_scan | write | Run NSE (Nmap Scripting Engine) scripts against target. |
searchsploit_examine | read | Get the code/content of a specific exploit by EDB-ID. |
searchsploit_search | read | Search Exploit-DB for exploits by keyword. |
service_scan | read | Detect service versions on target ports. |
solazy_dotting | read | Reinsert functions (clusters) into a reduced CFG `.dot` using a JSON config. |
solazy_fetcher | read | Fetch a deployed program bytecode (or account) from a Solana RPC endpoint. |
solazy_recap | read | Generate an audit-friendly markdown recap for an Anchor project. |
solazy_reverse | read | Reverse engineer a compiled Solana sBPF `.so` file. |
solazy_sast | write | Run SAST (Starlark rules) on an Anchor or SBF project directory. |
sql_dump | read | Dump data from database tables. Use responsibly and only on authorized targets. |
sql_enumerate | read | Enumerate databases, tables, or columns from a vulnerable target. |
sql_scan | read | Scan a URL for SQL injection vulnerabilities. |
sql_test | read | Quick test to check if a parameter is injectable. |
template_scan | read | Scan with specific template categories. |
trivy_generate_sbom | read | Generate a Software Bill of Materials (SBOM) for an image. |
trivy_scan_config | read | Scan IaC files (Terraform, Dockerfile, Kubernetes YAML, etc.) |
trivy_scan_filesystem | read | Scan a filesystem path or git repository for vulnerabilities |
trivy_scan_image | read | Scan a container image for vulnerabilities. |
whatweb_scan | read | Identify web technologies, CMS, frameworks, and server software. |
yara_scan | read | Scan files or directories using YARA rules for malware detection |
yara_scan_with_rules | read | Scan files using custom inline YARA rules. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
"description": "Target URL (e.g., https://10.10.10.10)",
.trivyignore
2. Configure Claude Desktop to connect to `http://127.0.0.1:9876`
mcp, pydantic, pydantic-settings
mcp, pydantic, pydantic-settings
mcp, pydantic, pydantic-settings
mcp, pydantic, pydantic-settings
mcp, pydantic, pydantic-settings
Gates applied: no_behavioural_pass.
dddbfe993d4dfull audit observations/trust-audit/mcp-server/fuzzinglabs__security-hub.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | dddbfe993d4d | SAFE | B | 89 | first audit |
Questions
What is the Security Hub MCP server?
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
What tools does Security Hub expose?
69 in total: 61 read-only, 8 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Security Hub safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Security Hub need?
No credential environment variables were found in its source, so it appears to need none.
How does Security Hub run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (dddbfe993d4d), read on 2026-09-27. The repository is watched and re-audited when it changes.