Atlas / MCP servers / mcpcap / Mcpcap

McpcapSAFE

mcp/mcpcap/mcpcap-1

Network analysis for the AI age

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
51
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A modular Python MCP (Model Context Protocol) server for analyzing PCAP files. mcpcap exposes protocol-specific analysis tools that accept a local file path or remote HTTP URL at call time, so the server stays stateless and works cleanly with MCP clients.

Overview

mcpcap uses a modular architecture to analyze different network protocols found in PCAP files. Each module provides specialized analysis tools that can be called independently with any PCAP file, making it perfect for integration with Claude Desktop and other MCP clients.

Key Features

  • Stateless MCP Tools: Each analysis call supplies its own PCAP path or URL
  • Modular Architecture: DNS, DHCP, ICMP, TCP, SIP, and CapInfos modules with easy extensibility for new protocols
  • Advanced TCP Analysis: Connection lifecycle, traffic patterns, retransmissions, and flow inspection
  • Local & Remote PCAP Support: Analyze files from local storage or HTTP URLs
  • Scapy Integration: Leverages scapy's comprehensive packet parsing capabilities
  • Specialized Analysis Prompts: Security, networking, and forensic analysis guidance
  • JSON Responses: Structured data format optimized for LLM consumption

Installation

mcpcap requires Python 3.10 or greater.

Using pip

pip install mcpcap

Using uv

uv add mcpcap

Using uvx (for one-time usage)

uvx mcpcap

Using Docker

Build the image from the repository root:

docker build -t mcpcap .

Run it over HTTP for MCP clients that connect to a network endpoint:

docker run --rm \
-p 127.0.0.1:8080:8080 \
-v "$(pwd)/examples:/pcaps:ro" \
mcpcap --transport http --host 0.0.0.0 --port 8080 --allow-unauthenticated-http

Run it over stdio for clients that can spawn `docker

Read from source at commit 1ef0f9b8c52dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add mcpcap -- None mcpcap==0.6.1
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (15)

LOWInventory / provenance · inv.binary · CWE-1104
examples/dhcp.pcap
dhcp.pcap
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
examples/dns.pcap
dns.pcap
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.readthedocs.yaml
.readthedocs.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/source/conf.py:9
sys.path.insert(0, os.path.abspath("../../src"))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/source/conf.py:12
with open("../../pyproject.toml", "rb") as f:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/workflows/test.yml:86
if curl --silent --show-error --output /dev/null http://127.0.0.1:8080/mcp; then
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:88
This pulls `ghcr.io/mcpcap/mcpcap:latest`, publishes `http://127.0.0.1:8080/mcp` only on host loopback, and mounts `./examples` into the container as `/pcaps`.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:146
http://127.0.0.1:8080/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/source/index.rst:50
This pulls ``ghcr.io/mcpcap/mcpcap:latest`` and exposes ``http://127.0.0.1:8080/mcp`` with ``./examples`` mounted as ``/pcaps``.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/source/user-guide/installation.md:80
This pulls `ghcr.io/mcpcap/mcpcap:latest`, starts mcpcap on host loopback at `http://127.0.0.1:8080/mcp`, and mounts `./examples` as `/pcaps` inside the container.
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:172
Clients must send `Authorization: Bearer <secret>` on every request. Use a TLS reverse proxy and an HTTPS URL for remote clients. A configured token also protects loopback endpoints; stdio is unaffect
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/source/user-guide/mcp-integration.md:94
Configure the client to send `Authorization: Bearer <secret>` on every request. Use HTTPS through a TLS reverse proxy for remote clients; plain HTTP exposes bearer credentials and capture data on the
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
readme-assets/mcpcap-logo.png
readme-assets/mcpcap-logo.png
Why it matters. 1566607 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 1ef0f9b8c52dfull audit observations/trust-audit/mcp-server/mcpcap__mcpcap-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-081ef0f9b8c52dSAFEB89first audit
05

Questions

What is the Mcpcap MCP server?

Network analysis for the AI age

Is Mcpcap safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Mcpcap need?

It reads MCPCAP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mcpcap run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcpcap.

How current is this page?

The grade is for one exact copy of the source (1ef0f9b8c52d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement