Atlas / MCP servers / mordavid / ExternalAttacker

ExternalAttackerSAFE

mcp/mordavid/externalattacker

A modular external attack surface mapping tool integrating tools for automated reconnaissance and bug bounty workflows.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 8r · 0w · 0d
Transport
stdio
License
—
Stars
77
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Model Context Protocol (MCP) Server for External Attack Surface Management

ExternalAttacker is a powerful integration that brings automated scanning capabilities with natural language interface for comprehensive external attack surface management and reconnaissance.

🔍 Automated Attack Surface Management with AI! Scan domains, analyze infrastructure, and discover vulnerabilities using natural language.

🔍 What is ExternalAttacker?

ExternalAttacker combines the power of:

  • Automated Scanning: Comprehensive toolset for external reconnaissance
  • Model Context Protocol (MCP): An open protocol for creating custom AI tools
  • Natural Language Processing: Convert plain English queries into scanning commands

📱 Community

Join our Telegram channel for updates, tips, and discussion:

✨ Features

  • Natural Language Interface: Run scans using plain English
  • Comprehensive Scanning Categories:
  • 🌐 Subdomain Discovery (subfinder)
  • 🔢 Port Scanning (naabu)
  • 🌍 HTTP Analysis (httpx)
  • 🛡️ CDN Detection (cdncheck)
  • 🔐 TLS Analysis (tlsx)
  • 📁 Directory Fuzzing (ffuf, gobuster)
  • 📝 DNS Enumeration (dnsx)

📋 Prerequisites

  • Python 3.8 or higher
  • Go (for installing tools)
  • MCP Client

🔧 Installation

  1. Clone this repository:
git clone https://github.com/mordavid/ExternalAttacker-MCP.git
cd ExternalAttacker
  1. Install Python dependencies:
pip install -r requirements.txt
  1. Install required Go tools:
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
go install -v github.com/projectdiscovery/naabu/v2/cmd/naabu@latest
go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest
go install -v github.com/projectdiscovery/cdncheck/cmd/cdncheck@latest
go install -v 
Read from source at commit e9a659c2335dOBSERVED · 2026-10-07
02

Exposed tools (8)

8 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_http_servicesread
analyze_tls_configread
detect_cdnread
enumerate_assetsread
fuzz_endpointsread
resolve_dnsread
scan_portsread
scan_subdomainsread
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha e9a659c2335dfull audit observations/trust-audit/mcp-server/mordavid__externalattacker.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07e9a659c2335dSAFEB89first audit
05

Questions

What is the ExternalAttacker MCP server?

A modular external attack surface mapping tool integrating tools for automated reconnaissance and bug bounty workflows.

What tools does ExternalAttacker expose?

8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ExternalAttacker safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does ExternalAttacker need?

It reads API_KEY and FLASK_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ExternalAttacker run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (e9a659c2335d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement