pentest-mcp

MCP.Pizza Chef: DMontgomery40

Nineteen tools are registered here, wrapping well-known security programs including Nmap, Nikto, Gobuster, ffuf, Nuclei, Subfinder, tcpdump, Hydra, John the Ripper and Hashcat. None of those ship with it: you install each one yourself first, which makes this a job for someone comfortable at a command line. Nothing checks whether a target belongs to you. The scope-of-work prompt only decorates the written report, and the password-guessing tool will hammer any host you name. Scanning systems you do not own is illegal in most countries.

Coding
Other

Use This MCP server To

Scan my own home network for open ports and services Check a website I own for known weaknesses List the subdomains belonging to my company's domain Recover a forgotten password from my own backup file Turn my scan results into a draft client report Watch what traffic a device on my network is sending

README

Pentest MCP

smithery badge Verified on MseeP

Professional penetration-testing MCP server with modern transport/auth support and expanded recon tooling.

What Changed in 0.9.0

  • Upgraded MCP SDK to @modelcontextprotocol/sdk@^1.26.0
  • Kept MCP Inspector at the latest release (@modelcontextprotocol/inspector@^0.20.0) with bundled launcher
  • Streamable HTTP is now the primary network transport (MCP_TRANSPORT=http)
  • SSE is still available only as a deprecated compatibility mode
  • Added bearer-token auth with OIDC JWKS and introspection support
  • Added first-class tools: subfinderEnum, httpxProbe, ffufScan, nucleiScan, trafficCapture, hydraBruteforce, privEscAudit, extractionSweep
  • Added report-admin tools: listEngagementRecords, getEngagementRecord
  • Added SoW capture flow for reports using MCP elicitation (scopeMode=ask) with safe template fallback
  • Hardened command resolution so web probing uses httpx-toolkit (preferred) or validated ProjectDiscovery httpx, avoiding Python httpx CLI collisions
  • Integrated bundled MCP Inspector launcher (pentest-mcp inspector)
  • Runtime baseline is now Node.js 22.7.5+
  • Added invocation metadata in new tool outputs when auth/session context is available

Included Tools

  • nmapScan
  • runJohnTheRipper
  • runHashcat
  • gobuster
  • nikto
  • subfinderEnum
  • httpxProbe
  • ffufScan
  • nucleiScan
  • trafficCapture
  • hydraBruteforce
  • privEscAudit
  • extractionSweep
  • generateWordlist
  • listEngagementRecords
  • getEngagementRecord
  • createClientReport
  • cancelScan

Quick Start

Install

npm install -g pentest-mcp

pentest-mcp FAQ

Is this repository still active?
Yes, though development is intermittent. The last code change landed in March 2026, and the project is still published and installable.
Do I need to sign up or pay for anything?
No account and no key are needed. What you do need is every underlying security program installed on your machine first — Nmap, Nikto, Gobuster, ffuf, Nuclei, Subfinder, Hydra, tcpdump, John the Ripper and Hashcat. The instructions do not mention this, but any tool whose program is missing simply fails.
Does it stop me from scanning something I am not allowed to touch?
No, and this matters. There is no scope check anywhere in the running code. The scope-of-work question you are asked only fills in text on the generated report; it never restricts which targets the scanning and password-guessing tools will attack.
Can other people on my network reach it?
Yes, if you run the network mode. It listens on every network interface by default and authentication is switched off unless you deliberately turn it on, which would leave the full attack toolkit open to anyone who can reach the port.
Can I use this to test my own company's website?
Yes, with written permission from whoever owns it. That is the intended use, and the report tool is built to save you the paperwork afterwards.
How hard is it to set up?
Hard. Expect an evening. You need a recent Node install, the package installed globally, and a working set of a dozen separate security programs before most tools do anything.
Will it run something destructive by accident?
It can. Password guessing, traffic capture and vulnerability scanning all launch as soon as your assistant asks, with no confirmation step and no dry-run mode. Some tools also need administrator rights to work at all.