PentesterBLOCK
Elevate your AI assistants (like Claude & Cursor) into autonomous cybersecurity experts. Pentester-MCP integrates 200+ pentesting tools via the Model Context Protocol (MCP) using a secure Docker sandbox.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Pentester-MCP
Empower your AI assistants with the ultimate open-source penetration testing arsenal.
Overview
Pentester-MCP provides Model Context Protocol (MCP) integration for over 200+ of the most popular open-source cybersecurity and penetration testing tools.
By adding Pentester-MCP to an AI assistant (like Claude Desktop, Cursor, or specialized agents), the AI gains the autonomous ability to act as a penetration tester:
- It can run
nmapscans, analyze open ports, and automatically decide to runffufon discovered web servers. - It can execute
sqlmapagainst parameters it identifies as vulnerable. - It understands tool arguments, required flags, and syntaxes thanks to AI-optimized documentation strings injected into every MCP tool.
All 235 Python *_mcp.py tools were generated intelligently from cheat sheets to ensure safe execution (e.g., preventing shell injection, enforcing timeouts, and handling huge terminal outputs).
The Arsenal
The tools/ directory includes MCP servers for almost every category:
- Reconnaissance:
nmap,masscan,recon-ng,amass,subfinder,nuclei - Web Exploitation:
sqlmap,commix,ffuf,gobuster,dirsearch,nikto - Active Directory & Network:
impacket(full suite),bloodhound,responder,evil-winrm - Brute-Forcing & Password:
hydra,medusa,john,hashcat,nxc - And 200+ more covering WiFi, Cloud, Kubernetes, Android, and reversing.
Installation & Usage
Because of the massive amount of tools, installing everything on your host mac
f7898763d6c8OBSERVED · 2026-10-08Exposed tools (200)
17 read · 311 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_pcap | read | |
convert_ticket | read | |
dnscat_client | read | |
execute_weevely_module | write | |
generate_weevely_agent | read | |
identify_hash | read | |
john_prepare | read | |
launch_xsser_gui | read | |
list_nikto_plugins | read | |
manage_brew | read | |
manage_dirb_dictionaries | read | |
manage_mounts | read | |
manage_sliver_daemon | read | |
manage_wpprobe | read | |
monitor_fping | read | |
objection_explore | read | |
objection_patch | write | |
run_403bypasser | write | |
run_addcomputer | write | |
run_aircrack_action | write | |
run_aix | write | |
run_alterx | write | |
run_amass | write | |
run_apktool | write | |
run_arachni | write | |
run_arjun | write | |
run_asnmap | write | |
run_atexec | write | |
run_autobloody | write | |
run_autorecon | write | |
run_awk | write | |
run_bbot | write | |
run_binwalk | write | |
run_bloodhound | write | |
run_bloodhound_automation | write | |
run_bruteforce_luks | write | |
run_bruteshark_analysis | write | |
run_cariddi | write | |
run_cdncheck | write | |
run_cero | write | |
run_certipy | write | |
run_changeme | write | |
run_cloud_enum | write | |
run_cloudlist | write | |
run_coercer | write | |
run_commix | write | |
run_corsy | write | |
run_crlfuzz | write | |
run_crunch | write | |
run_cupp | write | |
run_dacledit | write | |
run_dalfox | write | |
run_describe_ticket | write | |
run_dig | write | |
run_dirb | write | |
run_dirsearch | write | |
run_dirstalk | write | |
run_dmitry | write | |
run_dnsenum | write | |
run_dnsrecon | write | |
run_dnsx | write | |
run_docker | write | |
run_dotdotpwn | write | |
run_dpapi | write | |
run_dpl4hydra | write | |
run_drupwn | write | |
run_dump_ntlm_info | write | |
run_enum4linux_ng | write | |
run_eyewitness | write | |
run_fatcat | write | |
run_fcrackzip | write | |
run_feroxbuster | write | |
run_ffuf | write | |
run_fierce | write | |
run_finalrecon | write | |
run_find | write | |
run_find_delegation | write | |
run_findomain | write | |
run_fping | write | |
run_gaia | write | |
run_gau | write | |
run_get_ad_computers | write | |
run_get_gpppassword | write | |
run_getadusers | write | |
run_getnpusers | write | |
run_getpac | write | |
run_getst | write | |
run_getuserspns | write | |
run_ghauri | write | |
run_git | write | |
run_gitleaks | write | |
run_gobuster | write | |
run_goldenpac | write | |
run_gospider | write | |
run_gowitness | write | |
run_graphw00f | write | |
run_grep | write | |
run_gunzip | write | |
run_hakrawler | write | |
run_hashcat | write | |
run_hashdeep | write | |
run_hashid | write | |
run_httpx | write | |
run_hydra | write | |
run_impacket_changepasswd | write | |
run_impacket_dcomexec | write | |
run_impacket_esentutl | write | |
run_impacket_exchanger | write | |
run_impacket_getarch | write | |
run_impacket_getlapspassword | write | |
run_impacket_gettgt | write | |
run_impacket_keylistattack | write | |
run_impacket_mimikatz | write | |
run_impacket_mssqlinstance | write | |
run_impacket_net | write | |
run_impacket_ping | write | |
run_impacket_ping6 | write | |
run_impacket_reg | write | |
run_impacket_registry_read | write | |
run_impacket_services | write | |
run_impacket_tstool | write | |
run_jadx | write | |
run_john | write | |
run_jwt_tool | write | |
run_k8scan | write | |
run_katana | write | |
run_kerbrute | write | |
run_kiterunner | write | |
run_kubectl | write | |
run_kubernetes_task | write | |
run_lookupsid | write | |
run_lsassy | write | |
run_machine_role | write | |
run_mapcidr | write | |
run_masscan | write | |
run_medusa | write | |
run_mqtt_check | write | |
run_msfconsole | write | |
run_msfvenom | write | |
run_mssqlclient | write | |
run_naabu | write | |
run_nbtscan | write | |
run_ndiff | write | |
run_netcat_client | write | |
run_netdiscover_scan | write | |
run_nikto_scan | write | |
run_nmap | write | |
run_nmapautomator | write | |
run_nping | write | |
run_npm | write | |
run_ntfs_read | write | |
run_nuclei | write | |
run_nxc | write | |
run_onesixtyone | write | |
run_openredirex | write | |
run_owneredit | write | |
run_pacu | write | |
run_paramspider | write | |
run_passdetective | write | |
run_php | write | |
run_plumhound | write | |
run_psexec | write | |
run_pw_inspector | write | |
run_pwncat_scan | write | |
run_pywhisker | write | |
run_qsfuzz | write | |
run_raise_child | write | |
run_rbcd | write | |
run_rdp_check | write | |
run_recon_ng | write | |
run_rpcclient | write | |
run_rpcmap | write | |
run_sambapipe | write | |
run_scp | write | |
run_sherlock | write | |
run_shuffledns | write | |
run_sliver_action | write | |
run_smbclient | write | |
run_smbexec | write | |
run_smbmap | write | |
run_smtp_user_enum | write | |
run_smugglex | write | |
run_snmp_check | write | |
run_snmpwalk | write | |
run_spiderfoot | write | |
run_sprayhound | write | |
run_sqlmap | write | |
run_ssh_command | write | |
run_sslscan | write | |
run_ssrfmap | write | |
run_sstimap | write | |
run_subfinder | write | |
run_subjack | write | |
run_tar | write | |
run_tcpdump | write | |
run_theharvester | write | |
run_ticketer | write | |
run_tldfinder | write | |
run_tlsx | write | |
run_trivy | write |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (11 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (16)
exploit-config.yaml
cmd_args.append("--insecure")callback_url: str = None,
if callback_url:
cmd_args.extend(["-b", callback_url])
if beacon_mode: cmd_args.append("--beacon")proxy_url: str = "http://127.0.0.1:8080",
proxy_url: str = "http://127.0.0.1:8080",
proxy_url: str = "http://127.0.0.1:8080",
proxy_url: str = "http://127.0.0.1:8080",
proxy_url: str = "http://127.0.0.1:8080",
- Decryption & PAC Analysis: To reveal group memberships and SIDs, provide the service account credentials. Use `password` for cleartext, `nt_hash` (RC4), or `aes_key` (AES128/256) along with `user` a
nt_hash : RC4 key / NT hash for decryption.
cmd_args.extend(["--rc4", nt_hash])
- Use the 'threads' parameter to control speed (default 50) and 'downgrade' to force RC4 encryption for legacy compatibility or evasion.
downgrade : Force the use of RC4 encryption (arcfour-hmac-md5).
Gates applied: no_behavioural_pass.
f7898763d6c8full audit observations/trust-audit/mcp-server/halilkirazkaya__pentester.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f7898763d6c8 | BLOCK | D | 69 | first audit |
Questions
What is the Pentester MCP server?
Elevate your AI assistants (like Claude & Cursor) into autonomous cybersecurity experts. Pentester-MCP integrates 200+ pentesting tools via the Model Context Protocol (MCP) using a secure Docker sandbox.
What tools does Pentester expose?
200 in total: 17 read-only, 311 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Pentester safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Pentester need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (f7898763d6c8), read on 2026-10-08. The repository is watched and re-audited when it changes.