PwnoSAFE
MCP for Pwn
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
stateful system for autonomous pwn and binary research, designed for LLM agents.
Overview
pwno-mcp runs GDB + pwndbg in an isolated environment and exposes stateful debugging, exploit I/O, and helper tooling over MCP for agentic coding clients.
Features
- Stateful debugger sessions via GDB + pwndbg
- Deterministic execution control via GDB/MI
- Fast context snapshots for registers, stack, disassembly, source, and backtrace
- Interactive exploit-driver workflows with
pwncli - Multi-session support for parallel workflows
- Workspace automation helpers for commands, processes, Python, repos, and RetDec
- HTTP and stdio transport support
Documentation
The full documentation is available at docs.pwno.io.
Quick Start
Create a local workspace directory, put your target binary there, then run the container.
mkdir -p ./workspace cp ./path/to/your/binary ./workspace/chal chmod +x ./workspace/chal
docker run --rm -p 5500:5500 \ --cap-add=SYS_PTRACE \ --cap-add=SYS_ADMIN \ --security-opt seccomp=unconfined \ --security-opt apparmor=unconfined \ -v "$PWD/workspace:/workspace" \ ghcr.io/pwno-io/pwno-mcp:latest
Default MCP endpoint:
http://127.0.0.1:5500/mcp
For stdio mode, client configs, health checks, and attach-helper details, use the docs site: docs.pwno.io/quickstart.
Development
For local development, architecture, and contributing guidance, see docs.pwno.io/development.
Usage
- non-profit: yes
- commercial:
[email protected]
Future Enhancements
- WebSocket endpoint for streaming I/O
- Advanced memory analysis too
6b57f5e3b031OBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add pwno-mcp-docs -- npx -y pwno-mcp-docs
{
"mcpServers": {
"pwno-mcp-docs": {
"command": "npx",
"args": [
"-y",
"pwno-mcp-docs"
]
}
}
}Exposed tools (12)
7 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
execute_python_code | write | Execute Python code dynamically in the shared environment. |
execute_python_script | write | Execute an existing Python script within the shared environment. |
fetch_repo | read | Fetch a git repository into /workspace. |
get_decompiled_code | read | Return RetDec decompiled C code if available, or a status describing why not. |
get_process | read | Get information about a tracked background process by PID. |
get_retdec_status | read | Get the current RetDec decompilation status, lazily initializing as needed. |
install_python_packages | write | Install additional Python packages using the shared package manager (uv). |
kill_process | destructive | Send a signal to a tracked background process (default SIGTERM=15). |
list_processes | read | List all tracked background processes and their metadata (PID, command, log paths). |
list_python_packages | read | List all packages installed in the shared Python environment. |
run_command | write | Execute a system command and wait for completion. |
spawn_process | read | Spawn a long-running background process and return its PID and log paths. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
kill_process
interactive-exploit-loop.mdx
resolve_workspace_path("../../etc/passwd", workspace_root="/workspace")http://127.0.0.1:5500/mcp
claude mcp add --transport http --scope project pwno-mcp http://127.0.0.1:5500/mcp
url = "http://127.0.0.1:5500/mcp"
"url": "http://127.0.0.1:5500/mcp"
- Use `http://127.0.0.1:5500/mcp` for HTTP unless you changed the defaults.
Gates applied: no_behavioural_pass.
6b57f5e3b031full audit observations/trust-audit/mcp-server/pwno-io__pwno.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 6b57f5e3b031 | SAFE | B | 89 | first audit |
Questions
What is the Pwno MCP server?
MCP for Pwn
What tools does Pwno expose?
12 in total: 7 read-only, 4 that write, and 1 that can delete or overwrite (kill_process). Every one is listed on this page with its risk.
Is Pwno safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Pwno need?
No credential environment variables were found in its source, so it appears to need none.
How does Pwno run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as pwno-mcp-docs.
How current is this page?
The grade is for one exact copy of the source (6b57f5e3b031), read on 2026-10-05. The repository is watched and re-audited when it changes.