DMontgomery40/pentest-mcp
View on GitHub ↗NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR, hashcat, wordlist building, and more.
141 ★28 forksJavaScriptUpdated 5mo ago
What you need to know
Professional penetration-testing MCP server with built-in recon and exploitation tooling (nmap, ffuf, nuclei, hydra, etc.) and report generation.
Install
npm install -g pentest-mcp
Usage
- •Run `pentest-mcp` (stdio) or MCP_TRANSPORT=http for Streamable HTTP; required host tools must be on PATH.
Key features
- ✓18 tools including recon/exploit/report
- ✓engagement records that cut admin overhead
- ✓OIDC/JWKS bearer auth (HTTP mode)
- ✓bundled MCP Inspector launcher
Caveats
- ⚠Authorized use only; run against systems only with explicit written permission
Clients: Claude Code · Codex · Cursor
Reviewed 2026-08-11
Topics
cybersecuritydirbustergobusterhashcathttp-streamingjohn-the-ripperjtrmcpmcp-servermodel-context-protocolniktonmappentestingpentesting-toolsredteamsse-serversse-streamingstdio
- Stars
- 141★
- Forks
- 28
- Language
- JavaScript
- License
- MIT
- Created
- 2025-04-04
- Last push
- 2026-03-23