Atlas / MCP servers / ramkansal / Pentest

PentestBLOCK

mcp/ramkansal/pentest-4

pentestMCP: AI-Powered Penetration Testing via MCP, an MCP designed for penetration testers.

Verdict
BLOCK
Grade
F
Trust score
46 /100
Exposed tools
36 29r · 7w · 0d
Transport
streamable-http
License
—
Stars
108
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/ram001-code-pentestmcp)

[](https://opensource.org/licenses/MIT)

pentestMCP provides a powerful bridge between Large Language Models (LLMs) and practical penetration testing tools through the Model Context Protocol (MCP). This project functions as an MCP Server, exposing a curated suite of over 20 standard security assessment utilities (Nmap, Nuclei, ZAP, SQLMap, etc.) as callable 'tools'. This allows AI agents within MCP-compatible clients (like Claude Desktop or specific VS Code setups) to leverage these utilities for automated and interactive security analysis tasks.

The goal is to enable natural language control over complex security workflows, making pentesting capabilities more accessible and integrated into AI-driven environments. This work is inspired by Laurie Kirk's GhidraMCP.

Table of Contents

  • Core Concepts & Architecture
  • Key Features
  • Prerequisites
  • [Installation & Setup](#install
Read from source at commit f0b6e067139dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add pentest-mcp -- uvx pentest-mcp
claude-desktop
{
  "mcpServers": {
    "pentest-mcp": {
      "command": "uvx",
      "args": [
        "pentest-mcp"
      ]
    }
  }
}
03

Exposed tools (36)

29 read · 7 write · 0 destructive.

ToolRiskDescription
ad_asreproastread
ad_bloodhound_collectread
ad_certipy_enumread
ad_check_credentialsread
ad_coerce_petitpotamread
ad_coerce_printerbugread
ad_dcsyncread
ad_kerberoastread
ad_ldap_dumpread
ad_password_sprayread
ad_relay_setupread
ad_responder_poisonread
ad_secrets_dumpread
ad_shares_enumread
ad_smb_signing_checkread
ad_user_enumread
check_gobuster_statusread
check_harvester_outputread
check_sqlmap_statusread
fetch_arjun_resultsread
fetch_fileread
fetch_gofang_resultsread
fetch_nmap_resultsread
fetch_nuclei_resultsread
fetch_whois_dataread
launch_arjun_scanread
launch_gofang_scanread
launch_nmap_scanread
launch_nuclei_scanread
run_curl_toolwrite
run_dig_toolwrite
run_gobuster_scanwrite
run_harvesterwrite
run_searchsploitwrite
run_sqlmap_toolwrite
run_subfinderwrite
04

Trust audit

BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
seclists/Discovery/Web-Content/Public-Source-Repo-Issues.json:546
filename:id_rsa or filename:id_dsa
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
seclists/Discovery/Web-Content/Public-Source-Repo-Issues.json:555
filename:.git-credentials
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
seclists/Discovery/Web-Content/Public-Source-Repo-Issues.json:569
filename:.netrc password
Why it matters. touches a credential store
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
seclists/Discovery/Web-Content/dutch/new/26.txt:4101
jailbreak
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
seclists/Discovery/Web-Content/raft-large-words-lowercase.txt:85641
jailbreak
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.rtl_override · CWE-94, CWE-1427
seclists/Discovery/Web-Content/dutch/new/28.txt:40400
#staysafetogether
Why it matters. bidirectional override can render text differently from how it is read
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
seclists/Discovery/Web-Content/dutch/list_1.txt:27671
gut
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
seclists/Discovery/Web-Content/dutch/list_4.txt:8516
données
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
seclists/Discovery/Web-Content/dutch/list_4.txt:20282
avec
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
seclists/Discovery/Web-Content/dutch/new/1.txt:5862
e-mail
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
seclists/Discovery/Web-Content/dutch/new/1.txt:7423
fruit-
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
seclists/Discovery/Web-Content/api/api-endpoints-res.txt:3353
GHS_ListFrame_CallbackFunc_GetCount
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
seclists/Discovery/Web-Content/api/api-endpoints-res.txt:3354
GHS_ListFrame_CallbackFunc_UpdateItme
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
seclists/Discovery/Web-Content/api/api-endpoints-res.txt:3355
GHS_RewardFrame_CallbackFunc_GetCount
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
seclists/Discovery/Web-Content/api/api-endpoints-res.txt:3356
GHS_RewardFrame_CallbackFunc_UpdateItme
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
seclists/Discovery/Web-Content/api/api-seen-in-wild.txt:2754
GHS_ListFrame_CallbackFunc_GetCount
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
seclists/Discovery/Web-Content/CMS/Adobe-AEM_2021.txt:373
libs/cq/contentinsight/content/proxy.reportingservices.json;%0aa.css?url=http://169.254.169.254%23/api1.omniture.com/a&q=a
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
seclists/Discovery/Web-Content/CMS/Adobe-AEM_2021.txt:384
libs/cq/contentinsight/content/proxy.reportingservices.json/a.1.json?url=http://169.254.169.254%23/api1.omniture.com/a&q=a
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
seclists/Discovery/Web-Content/CMS/Adobe-AEM_2021.txt:385
libs/cq/contentinsight/content/proxy.reportingservices.json/a.css?url=http://169.254.169.254%23/api1.omniture.com/a&q=a
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
seclists/Discovery/Web-Content/CMS/Adobe-AEM_2021.txt:386
libs/cq/contentinsight/content/proxy.reportingservices.json/a.html?url=http://169.254.169.254%23/api1.omniture.com/a&q=a
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
seclists/Discovery/Web-Content/CMS/Adobe-AEM_2021.txt:387
libs/cq/contentinsight/content/proxy.reportingservices.json/a.ico?url=http://169.254.169.254%23/api1.omniture.com/a&q=a
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
seclists/Discovery/Web-Content/CMS/Adobe-AEM_2021.txt:373
libs/cq/contentinsight/content/proxy.reportingservices.json;%0aa.css?url=http://169.254.169.254%23/api1.omniture.com/a&q=a
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
seclists/Discovery/Web-Content/CMS/Adobe-AEM_2021.txt:384
libs/cq/contentinsight/content/proxy.reportingservices.json/a.1.json?url=http://169.254.169.254%23/api1.omniture.com/a&q=a
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
seclists/Discovery/Web-Content/CMS/Adobe-AEM_2021.txt:385
libs/cq/contentinsight/content/proxy.reportingservices.json/a.css?url=http://169.254.169.254%23/api1.omniture.com/a&q=a

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha f0b6e067139dfull audit observations/trust-audit/mcp-server/ramkansal__pentest-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07f0b6e067139dBLOCKF46first audit
06

Questions

What is the Pentest MCP server?

pentestMCP: AI-Powered Penetration Testing via MCP, an MCP designed for penetration testers.

What tools does Pentest expose?

36 in total: 29 read-only, 7 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Pentest safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (46/100) and found 11 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Pentest need?

No credential environment variables were found in its source, so it appears to need none.

How does Pentest run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as pentest-mcp.

How current is this page?

The grade is for one exact copy of the source (f0b6e067139d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement