Atlas / MCP servers / halilkirazkaya / Pentester

PentesterBLOCK

mcp/halilkirazkaya/pentester

Elevate your AI assistants (like Claude & Cursor) into autonomous cybersecurity experts. Pentester-MCP integrates 200+ pentesting tools via the Model Context Protocol (MCP) using a secure Docker sandbox.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
200 17r · 311w · 0d
Transport
—
License
MIT
Stars
55
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Pentester-MCP

Empower your AI assistants with the ultimate open-source penetration testing arsenal.

Overview

Pentester-MCP provides Model Context Protocol (MCP) integration for over 200+ of the most popular open-source cybersecurity and penetration testing tools.

By adding Pentester-MCP to an AI assistant (like Claude Desktop, Cursor, or specialized agents), the AI gains the autonomous ability to act as a penetration tester:

  • It can run nmap scans, analyze open ports, and automatically decide to run ffuf on discovered web servers.
  • It can execute sqlmap against parameters it identifies as vulnerable.
  • It understands tool arguments, required flags, and syntaxes thanks to AI-optimized documentation strings injected into every MCP tool.

All 235 Python *_mcp.py tools were generated intelligently from cheat sheets to ensure safe execution (e.g., preventing shell injection, enforcing timeouts, and handling huge terminal outputs).

The Arsenal

The tools/ directory includes MCP servers for almost every category:

  • Reconnaissance: nmap, masscan, recon-ng, amass, subfinder, nuclei
  • Web Exploitation: sqlmap, commix, ffuf, gobuster, dirsearch, nikto
  • Active Directory & Network: impacket (full suite), bloodhound, responder, evil-winrm
  • Brute-Forcing & Password: hydra, medusa, john, hashcat, nxc
  • And 200+ more covering WiFi, Cloud, Kubernetes, Android, and reversing.

Installation & Usage

Because of the massive amount of tools, installing everything on your host mac

Read from source at commit f7898763d6c8OBSERVED · 2026-10-08
02

Exposed tools (200)

17 read · 311 write · 0 destructive.

ToolRiskDescription
analyze_pcapread
convert_ticketread
dnscat_clientread
execute_weevely_modulewrite
generate_weevely_agentread
identify_hashread
john_prepareread
launch_xsser_guiread
list_nikto_pluginsread
manage_brewread
manage_dirb_dictionariesread
manage_mountsread
manage_sliver_daemonread
manage_wpproberead
monitor_fpingread
objection_exploreread
objection_patchwrite
run_403bypasserwrite
run_addcomputerwrite
run_aircrack_actionwrite
run_aixwrite
run_alterxwrite
run_amasswrite
run_apktoolwrite
run_arachniwrite
run_arjunwrite
run_asnmapwrite
run_atexecwrite
run_autobloodywrite
run_autoreconwrite
run_awkwrite
run_bbotwrite
run_binwalkwrite
run_bloodhoundwrite
run_bloodhound_automationwrite
run_bruteforce_lukswrite
run_bruteshark_analysiswrite
run_cariddiwrite
run_cdncheckwrite
run_cerowrite
run_certipywrite
run_changemewrite
run_cloud_enumwrite
run_cloudlistwrite
run_coercerwrite
run_commixwrite
run_corsywrite
run_crlfuzzwrite
run_crunchwrite
run_cuppwrite
run_dacleditwrite
run_dalfoxwrite
run_describe_ticketwrite
run_digwrite
run_dirbwrite
run_dirsearchwrite
run_dirstalkwrite
run_dmitrywrite
run_dnsenumwrite
run_dnsreconwrite
run_dnsxwrite
run_dockerwrite
run_dotdotpwnwrite
run_dpapiwrite
run_dpl4hydrawrite
run_drupwnwrite
run_dump_ntlm_infowrite
run_enum4linux_ngwrite
run_eyewitnesswrite
run_fatcatwrite
run_fcrackzipwrite
run_feroxbusterwrite
run_ffufwrite
run_fiercewrite
run_finalreconwrite
run_findwrite
run_find_delegationwrite
run_findomainwrite
run_fpingwrite
run_gaiawrite
run_gauwrite
run_get_ad_computerswrite
run_get_gpppasswordwrite
run_getaduserswrite
run_getnpuserswrite
run_getpacwrite
run_getstwrite
run_getuserspnswrite
run_ghauriwrite
run_gitwrite
run_gitleakswrite
run_gobusterwrite
run_goldenpacwrite
run_gospiderwrite
run_gowitnesswrite
run_graphw00fwrite
run_grepwrite
run_gunzipwrite
run_hakrawlerwrite
run_hashcatwrite
run_hashdeepwrite
run_hashidwrite
run_httpxwrite
run_hydrawrite
run_impacket_changepasswdwrite
run_impacket_dcomexecwrite
run_impacket_esentutlwrite
run_impacket_exchangerwrite
run_impacket_getarchwrite
run_impacket_getlapspasswordwrite
run_impacket_gettgtwrite
run_impacket_keylistattackwrite
run_impacket_mimikatzwrite
run_impacket_mssqlinstancewrite
run_impacket_netwrite
run_impacket_pingwrite
run_impacket_ping6write
run_impacket_regwrite
run_impacket_registry_readwrite
run_impacket_serviceswrite
run_impacket_tstoolwrite
run_jadxwrite
run_johnwrite
run_jwt_toolwrite
run_k8scanwrite
run_katanawrite
run_kerbrutewrite
run_kiterunnerwrite
run_kubectlwrite
run_kubernetes_taskwrite
run_lookupsidwrite
run_lsassywrite
run_machine_rolewrite
run_mapcidrwrite
run_masscanwrite
run_medusawrite
run_mqtt_checkwrite
run_msfconsolewrite
run_msfvenomwrite
run_mssqlclientwrite
run_naabuwrite
run_nbtscanwrite
run_ndiffwrite
run_netcat_clientwrite
run_netdiscover_scanwrite
run_nikto_scanwrite
run_nmapwrite
run_nmapautomatorwrite
run_npingwrite
run_npmwrite
run_ntfs_readwrite
run_nucleiwrite
run_nxcwrite
run_onesixtyonewrite
run_openredirexwrite
run_ownereditwrite
run_pacuwrite
run_paramspiderwrite
run_passdetectivewrite
run_phpwrite
run_plumhoundwrite
run_psexecwrite
run_pw_inspectorwrite
run_pwncat_scanwrite
run_pywhiskerwrite
run_qsfuzzwrite
run_raise_childwrite
run_rbcdwrite
run_rdp_checkwrite
run_recon_ngwrite
run_rpcclientwrite
run_rpcmapwrite
run_sambapipewrite
run_scpwrite
run_sherlockwrite
run_shufflednswrite
run_sliver_actionwrite
run_smbclientwrite
run_smbexecwrite
run_smbmapwrite
run_smtp_user_enumwrite
run_smugglexwrite
run_snmp_checkwrite
run_snmpwalkwrite
run_spiderfootwrite
run_sprayhoundwrite
run_sqlmapwrite
run_ssh_commandwrite
run_sslscanwrite
run_ssrfmapwrite
run_sstimapwrite
run_subfinderwrite
run_subjackwrite
run_tarwrite
run_tcpdumpwrite
run_theharvesterwrite
run_ticketerwrite
run_tldfinderwrite
run_tlsxwrite
run_trivywrite
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (11 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (16)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
configs/exploit-config.yaml
exploit-config.yaml
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
tools/feroxbuster_mcp.py:131
cmd_args.append("--insecure")
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
tools/dalfox_mcp.py:14
callback_url: str = None,
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
tools/dalfox_mcp.py:90
if callback_url:
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
tools/dalfox_mcp.py:91
cmd_args.extend(["-b", callback_url])
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
tools/sliver_mcp.py:146
if beacon_mode: cmd_args.append("--beacon")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
tools/403bypasser_mcp.py:15
proxy_url: str = "http://127.0.0.1:8080",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
tools/cariddi_mcp.py:23
proxy_url: str = "http://127.0.0.1:8080",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
tools/crlfuzz_mcp.py:15
proxy_url: str = "http://127.0.0.1:8080",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
tools/drupwn_mcp.py:20
proxy_url: str = "http://127.0.0.1:8080",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
tools/emailharvester_mcp.py:14
proxy_url: str = "http://127.0.0.1:8080",
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tools/impacket-describeticket_mcp.py:27
- Decryption & PAC Analysis: To reveal group memberships and SIDs, provide the service account credentials. Use `password` for cleartext, `nt_hash` (RC4), or `aes_key` (AES128/256) along with `user` a
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tools/impacket-describeticket_mcp.py:37
nt_hash      : RC4 key / NT hash for decryption.
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tools/impacket-describeticket_mcp.py:58
cmd_args.extend(["--rc4", nt_hash])
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tools/kerbrute_mcp.py:34
- Use the 'threads' parameter to control speed (default 50) and 'downgrade' to force RC4 encryption for legacy compatibility or evasion.
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tools/kerbrute_mcp.py:49
downgrade     : Force the use of RC4 encryption (arcfour-hmac-md5).

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f7898763d6c8full audit observations/trust-audit/mcp-server/halilkirazkaya__pentester.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f7898763d6c8BLOCKD69first audit
05

Questions

What is the Pentester MCP server?

Elevate your AI assistants (like Claude & Cursor) into autonomous cybersecurity experts. Pentester-MCP integrates 200+ pentesting tools via the Model Context Protocol (MCP) using a secure Docker sandbox.

What tools does Pentester expose?

200 in total: 17 read-only, 311 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Pentester safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Pentester need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (f7898763d6c8), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement