DMontgomery40/pentest-mcp

View on GitHub ↗

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR, hashcat, wordlist building, and more.

141 ★28 forksJavaScriptUpdated 5mo ago

What you need to know

Professional penetration-testing MCP server with built-in recon and exploitation tooling (nmap, ffuf, nuclei, hydra, etc.) and report generation.

Install

npm install -g pentest-mcp

Usage

  • Run `pentest-mcp` (stdio) or MCP_TRANSPORT=http for Streamable HTTP; required host tools must be on PATH.

Key features

  • 18 tools including recon/exploit/report
  • engagement records that cut admin overhead
  • OIDC/JWKS bearer auth (HTTP mode)
  • bundled MCP Inspector launcher

Caveats

  • Authorized use only; run against systems only with explicit written permission
Clients: Claude Code · Codex · Cursor

Reviewed 2026-08-11

Topics

cybersecuritydirbustergobusterhashcathttp-streamingjohn-the-ripperjtrmcpmcp-servermodel-context-protocolniktonmappentestingpentesting-toolsredteamsse-serversse-streamingstdio
Stars
141★
Forks
28
Language
JavaScript
License
MIT
Created
2025-04-04
Last push
2026-03-23