MCP Security Hub

Production-ready MCP servers for offensive security tools

36
MCP Servers
298+
Security Tools
13
Categories

Reconnaissance

8

nmap-mcp

FuzzingLabs 8 tools

Port scanning, service detection, OS fingerprinting, NSE scripts

port_scan service_scan os_detection script_scan quick_scan get_scan_results +1 more

shodan-mcp

Community 7 tools

Wrapper for official Shodan MCP

shodan_ip_lookup shodan_search shodan_cve_lookup shodan_dns_lookup shodan_reverse_dns shodan_cpe_lookup +1 more

pd-tools-mcp

Community 6 tools

Wrapper for ProjectDiscovery tools (subfinder, httpx, katana)

**subfinder** **httpx** **katana** **nuclei** **dnsx** **naabu**

whatweb-mcp

FuzzingLabs 5 tools

Web technology fingerprinting and CMS detection

whatweb_scan get_scan_results list_active_scans

masscan-mcp

FuzzingLabs 6 tools

High-speed port scanning for large networks

masscan_scan masscan_top_ports get_scan_results list_active_scans

zoomeye-mcp

Community 4 tools

Wrapper for ZoomEye MCP - Cyberspace search engine

Host search Web search Domain search IP search

networksdb-mcp

FuzzingLabs 4 tools

IP/ASN/DNS lookups via NetworksDB

ip_lookup asn_lookup dns_lookup org_lookup

externalattacker-mcp

FuzzingLabs 6 tools

Attack surface mapping with ExternalAttacker

discover_subdomains scan_ports analyze_http enumerate_dns check_cdn analyze_tls

Web Security

6

nuclei-mcp

FuzzingLabs 7 tools

Template-based vulnerability scanning with 8000+ templates

nuclei_scan quick_scan template_scan list_templates get_scan_results list_active_scans

sqlmap-mcp

FuzzingLabs 8 tools

SQL injection detection and exploitation

sql_scan sql_enumerate sql_dump sql_test get_scan_results list_active_scans

nikto-mcp

Community

Wrapper for Nikto MCP web server scanner

ffuf-mcp

FuzzingLabs 9 tools

Web fuzzing for directories, files, parameters, and virtual hosts

ffuf_dir ffuf_vhost ffuf_param ffuf_custom list_wordlists get_fuzz_results +7 more

waybackurls-mcp

FuzzingLabs 3 tools

Fetch historical URLs from Wayback Machine for reconnaissance

fetch_wayback_urls get_fetch_results list_active_fetches

burp-mcp

Community 7 tools

Wrapper for official Burp Suite MCP

get_sitemap send_to_repeater send_to_intruder get_proxy_history active_scan passive_scan +1 more

Binary Analysis

6

radare2-mcp

Community 32 tools

Wrapper for official radare2-mcp - disassembly, decompilation

binwalk-mcp

FuzzingLabs 6 tools

Firmware analysis, signature scanning, extraction

binwalk_scan binwalk_extract binwalk_entropy binwalk_hexdump get_scan_results list_extractions +1 more

yara-mcp

FuzzingLabs 7 tools

Pattern matching for malware classification

yara_scan yara_scan_with_rules list_rulesets get_scan_results list_active_scans

capa-mcp

FuzzingLabs 5 tools

Capability detection in executables

capa_analyze get_analysis_results list_active_scans

ghidra-mcp

Community 13 tools

Wrapper for pyghidra-mcp - Headless AI-powered reverse engineering

decompile_function search_symbols_by_name search_code list_project_binaries list_project_binary_metadata list_exports +7 more

ida-mcp

Community 9 tools

Wrapper for ida-pro-mcp - IDA Pro integration

decompile_function get_function_info list_functions get_disassembly get_xrefs_to get_xrefs_from +3 more

Blockchain Security

3

daml-viewer-mcp

FuzzingLabs 1 tools

DAML access-control table generation and run tracking

damlviewer_generate_table get_run_results list_runs list_active_runs

medusa-mcp

FuzzingLabs 4 tools

High-performance smart contract fuzzer for Solidity

solazy-mcp

FuzzingLabs 8 tools

Solana sBPF static analysis and reverse engineering

solazy_reverse solazy_sast solazy_recap solazy_fetcher solazy_dotting get_run_results +2 more

Cloud Security

3

trivy-mcp

FuzzingLabs 7 tools

Container, filesystem, and IaC vulnerability scanning

trivy_scan_image trivy_scan_filesystem trivy_scan_config trivy_generate_sbom get_scan_results list_active_scans

prowler-mcp

FuzzingLabs 6 tools

AWS/Azure/GCP security auditing and compliance

prowler_scan prowler_compliance list_checks list_compliance_frameworks get_scan_results list_active_scans

roadrecon-mcp

FuzzingLabs 6 tools

Azure AD enumeration via RoadRecon

list_users list_groups list_applications list_service_principals analyze_permissions find_privileged

Secrets Detection

1

gitleaks-mcp

FuzzingLabs 5 tools

Find secrets and credentials in git repos and files

gitleaks_scan_repo gitleaks_scan_dir gitleaks_detect get_scan_results list_active_scans

Exploitation

1

searchsploit-mcp

FuzzingLabs 5 tools

Exploit-DB search and retrieval

searchsploit_search searchsploit_examine list_recent_searches

OSINT

2

maigret-mcp

Community 2 tools

Wrapper for mcp-maigret - Username OSINT across 2500+ sites

maigret_search maigret_url_search

dnstwist-mcp

Community 1 tools

Wrapper for mcp-dnstwist - Typosquatting/phishing detection

check_domain

Threat Intelligence

2

virustotal-mcp

Community 8 tools

Wrapper for mcp-virustotal - Malware analysis and threat intel

scan_url scan_file get_file_report get_url_report get_domain_report get_ip_report +2 more

otx-mcp

Community 5 tools

Wrapper for OTX MCP - AlienVault Open Threat Exchange

Search indicators Get indicator details Get pulses Submit URLs Monitor events

Active Directory

1

bloodhound-mcp

Community 75+ tools

Wrapper for BloodHound-MCP-AI - AD attack path analysis

find_all_domain_admins find_kerberoastable_users find_asreproastable_users find_paths_to_da find_unconstrained_delegation find_gpo_permissions

Password Cracking

1

hashcat-mcp

Community 4 tools

Wrapper for hashcat-mcp - Natural language hash cracking

crack_hash identify_hash list_hash_modes benchmark

Code Security

1

semgrep-mcp

Community 7 tools

Wrapper for Semgrep MCP - Static code analysis with 5000+ rules

security_check semgrep_scan semgrep_scan_with_custom_rule get_abstract_syntax_tree semgrep_findings supported_languages

Meta

1

mcp-scan

Community 2 tools

Wrapper for mcp-scan - Scan MCP servers for vulnerabilities

Toxic Flows Information Disclosure
Copied to clipboard!