CyberMCP - Cybersecurity API Testing with MCP

by ricauts

15 350 downloads Not rated yet MIT

About

CyberMCP is a Model Context Protocol (MCP) server designed for testing backend APIs for security vulnerabilities. It provides a set of specialized tools and resources that can be used by LLMs to identify common security issues in APIs.

Details

License
MIT

Explore

- 🔐 Authentication Testing - JWT analysis, bypass detection, OAuth2 flows
- 💉 Injection Testing - SQL injection, XSS vulnerability detection
- 📊 Data Protection - Sensitive data exposure, path traversal checks
- ⏱️ Rate Limiting - DoS vulnerability assessment
- 🛡️ Security Headers - OWASP security header validation
- 📚 Comprehensive Resources - Security checklists and testing guides


git clone https://github.com/your-username/CyberMCP.git
cd CyberMCP
npm install
npm run build

text
"Use basic_auth with username 'admin' and password 'secret123'
then use auth_bypass_check on https://api.example.com/users
to test for authentication bypass vulnerabilities"
```

The AI agent will:
1. Configure authentication credentials
2. Test the protected endpoint for bypass vulnerabilities
3. Provide detailed security analysis and recommendations

npm run quick-start

Category

Tools

| Category | Tools |
|----------|-------|
| Authentication | basic_auth, token_auth, oauth2_auth, api_login, auth_status, clear_auth, jwt_vulnerability_check, auth_bypass_check |
| Injection Testing | sql_injection_check, xss_check |
| Data Protection | sensitive_data_check, path_traversal_check |
| Infrastructure | rate_limit_check, security_headers_check |

AI-powered Cybersecurity API Testing with Model Context Protocol (MCP)

License: MIT
Node.js
TypeScript

CyberMCP is a Model Context Protocol (MCP) server that enables AI agents to perform comprehensive security testing on backend APIs. It provides 14 specialized security tools and 10 resources for identifying vulnerabilities like authentication bypass, injection attacks, data leakage, and security misconfigurations.

🚀 Quick Start

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.