Pentest MCP: Professional Penetration Testing Toolkit

by DMontgomery40

138 1.1k downloads Not rated yet MIT

About

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR, hashcat, wordlist building, and more.

Details

License
MIT

Explore

- 20+ penetration testing tools including nmap, John the Ripper, hashcat, gobuster, nikto, subfinder, httpx, ffuf, nuclei, hydra, sqlmap, tcpdump
- Modern transport support: stdio (default), Streamable HTTP (recommended), and deprecated SSE
- Bearer-token authentication with optional OIDC JWKS and introspection support
- Engagement record tracking and automated report generation with scope-of-work (SoW) handling
- Built-in MCP Inspector launcher – no separate install required
- Docker deployment with all tools pre-installed
- Supports interactive and template-based SoW capture for client reports

npm install -g pentest-mcp
pentest-mcp inspector

You can forward Inspector flags directly:

pentest-mcp inspector --help

Set these env vars when using MCP_TRANSPORT=http (or sse if needed):

```bash
MCP_AUTH_ENABLED=true
MCP_AUTH_MODE=bearer
MCP_AUTH_SCOPES=read,write
MCP_AUTH_AUDIENCE=
MCP_OIDC_ISSUER=https://issuer.example.com
MCP_OIDC_JWKS_URL=https://issuer.example.com/.well-known/jwks.json

For users who want reproducible and lower-noise MCP usage, start with a codemode-oriented setup:
- codemode-mcp (jx-codes)
- UTCP

Practical caveat: even with strong setup, model behavior can still be inconsistent across providers and versions. Keep retries, guardrails, and deterministic fallbacks in place.

nmapScan

`runJohnTheRipper`

runHashcat

`gobuster`

nikto

`subfinderEnum`

httpxProbe

`ffufScan`

nucleiScan

`trafficCapture`

hydraBruteforce

`privEscAudit`

extractionSweep

`generateWordlist`

listEngagementRecords

`getEngagementRecord`

createClientReport

`cancelScan`

- nmapScan
- runJohnTheRipper
- runHashcat
- gobuster
- nikto
- subfinderEnum
- httpxProbe
- ffufScan
- nucleiScan
- trafficCapture
- hydraBruteforce
- privEscAudit
- extractionSweep
- generateWordlist
- listEngagementRecords
- getEngagementRecord
- createClientReport
- cancelScan

Ensure the binaries are in PATH:

which nmap john hashcat gobuster nikto subfinder httpx-toolkit ffuf nuclei hydra sqlmap tcpdump

If httpx-toolkit is not installed, a validated ProjectDiscovery httpx binary is accepted as fallback.

smithery badge
Verified on MseeP

Professional penetration-testing MCP server with modern transport/auth support and expanded recon tooling.

What Changed in 0.9.0

- Upgraded MCP SDK to @modelcontextprotocol/sdk@^1.26.0
- Kept MCP Inspector at the latest release (@modelcontextprotocol/inspector@^0.20.0) with bundled launcher
- Streamable HTTP is now the primary network transport (MCP_TRANSPORT=http)
- SSE is still available only as a deprecated compatibility mode
- Added bearer-token auth with OIDC JWKS and introspection support
- Added first-class tools: subfinderEnum, httpxProbe, ffufScan, nucleiScan, trafficCapture, hydraBruteforce, privEscAudit, extractionSweep
- Added report-admin tools: listEngagementRecords, getEngagementRecord
- Added SoW capture flow for reports using MCP elicitation (scopeMode=ask) with safe template fallback
- Hardened command resolution so web probing uses httpx-toolkit (preferred) or validated ProjectDiscovery httpx, avoiding Python httpx CLI collisions
- Integrated bundled MCP Inspector launcher (pentest-mcp inspector)
- Runtime baseline is now Node.js 22.7.5+
- Added invocation metadata in new tool outputs when auth/session context is available

Included Tools

- nmapScan
- runJohnTheRipper
- runHashcat
- gobuster
- nikto
- subfinderEnum
- httpxProbe
- ffufScan
- nucleiScan
- trafficCapture
- hydraBruteforce
- privEscAudit
- extractionSweep
- generateWordlist
- listEngagementRecords
- getEngagementRecord
- createClientReport
- cancelScan

Quick Start

Install

npm install -g pentest-mcp

Run locally (stdio)

pentest-mcp

Launch bundled MCP Inspector (no separate install)

pentest-mcp inspector

You can forward Inspector flags directly:

pentest-mcp inspector --help

Run over network (Streamable HTTP)

MCP_TRANSPORT=http MCP_SERVER_HOST=0.0.0.0 MCP_SERVER_PORT=8000 pentest-mcp

Run legacy SSE mode (deprecated)

MCP_TRANSPORT=sse MCP_SERVER_PORT=8001 pentest-mcp

Transport Notes

- stdio: default for local MCP clients.
- http: modern network transport. Recommended.
- sse: compatibility only. Deprecated and will be removed in a future major release.

Inspector Integration

- pentest-mcp inspector launches the bundled @modelcontextprotocol/inspector CLI.
- It auto-targets this MCP server over stdio by spawning:
- node <this-package-entrypoint> stdio
- You do not need to install Inspector separately.

Auth Configuration (Bearer + OIDC)

Set these env vars when using MCP_TRANSPORT=http (or sse if needed):

```bash
MCP_AUTH_ENABLED=true
MCP_AUTH_MODE=bearer
MCP_AUTH_SCOPES=read,write
MCP_AUTH_AUDIENCE=
MCP_OIDC_ISSUER=https://issuer.example.com
MCP_OIDC_JWKS_URL=https://issuer.example.com/.well-known/jwks.json

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.