mcp server
pentest-mcp-server
Offline methodology engine for authorized penetration testing, CTF, and security research.
Description as published by the maintainer. Source
- version 0.1.6
- active
- retrieval
- security
active — Most recent push to the repository was 2026-07-30. Dashed tags are derived by ZBS Index from the published description, not stated by the maintainer.
What this server can do
7 functions, named and described by the server itself. Parameter names are shown because they say more about what a function does than its name usually does.
pentest_analyze_response(context, status_code, response_body, response_headers)- Analyze a server response from authorized probing for information leakage, fingerprinting signals, and exploitation opportunities scoped to the authorized engagement. Accepts raw HTTP response headers and body (paste from Burp, curl, or any HTTP client) and returns structured findings grouped by category. Each finding includes: what was detected, why it matters for an authorized tester, how a defender detects misuse, and recommended remediation. Identifies version disclosures, stack traces, debug headers, internal paths, JWT/cookie patterns, CORS misconfigurations, and other common leakage patterns. Use as the bridge between recon/probing output and the methodology and payload tools.
pentest_encode(chain, explain, payload)- Transform a payload string through one or more encoding layers for bypass research during authorized testing. Accepts a chain of encodings applied in order (e.g., ["unicode", "url", "base64"] applies Unicode → URL-encode → base64). Returns the transformed payload with a step-by-step decoding explanation: how a WAF or server would decode each layer, and why the combined encoding might bypass a specific filter. Use to understand filter bypass mechanics in an authorized engagement and to confirm that a target's decoding pipeline matches an expected bypass path. Payloads are transformed mathematically — no live probing occurs. Required: payload, chain.
pentest_generate_payloads(count, category, encoding, waf_profile, injection_context)- Generate payload templates for authorized testing against systems the tester owns or is permitted to test. Payloads are annotated templates — each includes why it works in the specified context, what vulnerability class it tests, detection signatures that WAF/IDS products might fire, and recommended mitigations. Context-awareness is core: an XSS payload for an HTML attribute differs entirely from one for a JS template literal, and both differ from a DOM-based sink. When a WAF profile is specified, bypass variants reference known public research for that WAF product. All payloads are illustrative templates for authorized testing only. Required: category, injection_context.
pentest_guide(phase, vector, target_context)- Return a structured attack methodology playbook for the given attack vector and optional target context, for use in authorized penetration testing, CTF, or security research. Covers reconnaissance, enumeration, exploitation, and post-exploitation phases for the vector, filtered to what is relevant given the provided stack and WAF profile. Each phase includes: what to look for, tools to use, common mistakes, detection indicators that would alert defenders, and recommended mitigations. Next-tool suggestions are pre-filled with payload generator and technique lookup calls. Covers 15 vectors via the vector enum. Authorized testing only. Required: vector.
pentest_lookup_group(query)- Look up a MITRE ATT&CK threat group (intrusion set) or software entry by name or ID for authorized penetration testing and threat intelligence. Returns the group or software record: ATT&CK ID, display name, known aliases, type (group vs. software), description, and the techniques it uses with procedure-level context from public ATT&CK reporting. Accepts exact ATT&CK IDs (G0007 for threat groups, S0002 for software) or keyword/name search (e.g., "APT28", "Mimikatz", "Lazarus Group"). Equally useful for defenders building detection coverage around specific adversary tradecraft. Required: query.
pentest_lookup_technique(query, include_subtechniques)- Look up a MITRE ATT&CK technique by ID or keyword for authorized penetration testing and security research. Returns the full technique record: name, associated tactics, description, detection opportunities (log sources, behavioral indicators), real-world procedure examples from public reporting, recommended mitigations, and related sub-techniques. The detection and mitigation sections make this equally useful for defenders building detection coverage. Accepts exact IDs (T1190, T1059.001) or keyword search (e.g., "sql injection", "pass the hash", "web shell upload"). Required: query.
pentest_map_techniques(os, limit, stack, services, auth_type)- Given a profile of the authorized test target (technology stack, exposed services, authentication type, OS), return a ranked list of ATT&CK techniques and OWASP test cases most relevant to that profile — not a generic dump of all techniques. Ranking factors: platform match, service match, auth type exposure, technique prevalence. Each result includes why it is relevant to this specific profile, the detection opportunity, and the recommended mitigation. Use when starting an authorized engagement to prioritize the testing scope; pair with pentest_guide to get the full methodology for each top-ranked vector.
Last successful function declaration observed on . Source: https://pentest.caseyjhand.com/mcp. We list what the server declared; we do not call any of these functions.
Endpoint status observed on . Source: https://pentest.caseyjhand.com/mcp.
Signals
These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.
| Signal | Value | What it measures | Window | Observed | Source |
|---|---|---|---|---|---|
| GitHub stars | 1 | Number of GitHub accounts that bookmarked this repository since it was created. It is a bookmark count, not installs, not active users and not quality. | cumulative, all time | GitHub | |
| Last commit | 2026-07-30 | Date of the most recent push to any branch. This is the strongest cheap indicator of whether the project is still maintained. | point in time | GitHub | |
| Open issues | 7 | Open issues plus open pull requests, as GitHub counts them together. A high number can mean an active project or an abandoned one. | as of fetch | GitHub | |
| Latest published version | 0.1.6 | Latest version string the maintainer published to the registry. | as of fetch | Model Context Protocol | |
| Registry record last updated | 2026-06-20 | When the registry record was last updated by its maintainer. | point in time | Model Context Protocol | |
| License | Apache-2.0 | Licence GitHub detected in the repository. Detection can be wrong; the LICENSE file is authoritative. | as of fetch | GitHub | |
| First listed in the MCP Registry | 2026-06-20 | Date this server was first published to the official MCP Registry. Not a usage or quality measure. | point in time | Model Context Protocol | |
| repository status | active | The repository exists on GitHub and is not archived. This says nothing about how recently it was worked on. | as of fetch | GitHub | |
| mcp tools declared | 7 tools | Number of functions the server itself declared when asked to list them. This is what the server offers an agent, not a measure of how well any of them work. | as of probe | pentest.caseyjhand.com | |
| mcp endpoint status | ok | The server listed 7 functions when asked. | as of probe | pentest.caseyjhand.com |
Where to get it
Related, by what their authors tagged them
-
io.github.Gorgon-Cyber/gorgon-scout
— last commit 2026-08-07, shares owasp, pentest, security
Run AI-driven web-app and API security scans (DAST) from Claude or any MCP agent. Windows.
-
com.threadlinqs/intelthreadlinqs-mcp
— last commit 2026-08-03, shares cybersecurity, mitre-attack, security
Threadlinqs threat-intelligence MCP — 73 tools: threats, detections, IOCs, actors, C2, MITRE, CVEs
-
io.github.AynOps/AynOps
— last commit 2026-08-06, shares penetration-testing
AynOps is a reconnaissance focused MCP Server which gives reconnaissance capabilities to AI Clients
-
com.vandorla/workspace-tools
— last commit 2026-08-06, shares security-research
Sandbox workspace tools: search, file read, DB queries, integrations. Returns synthetic data.
-
io.github.brian-mitchell-sec/workspace-tools
— last commit 2026-08-06, shares security-research
Research honeypot. Logs connections and tool arguments; injects instructions. Read README first.
-
io.github.frangelbarrera/osint-agent-skills
— last commit 2026-07-27, shares security-research
OSINT MCP server — 23 tools: DNS, WHOIS, Shodan, breaches, GEOINT, crypto. Works with Claude Code.
-
Compuute MCP Security Scanner
— last commit 2026-07-03, shares owasp, security
Scan any public GitHub MCP-server repo for security issues. 37 MCP-specific L1 rules, 8 languages.
-
io.github.goklab/guardvibe
— last commit 2026-07-23, shares owasp, security
Deterministic security layer your AI can't be. 462 rules, 39 tools, CLI + doctor + host audit.
-
io.github.H129hj/checkmcp
— last commit 2026-07-22, shares owasp, security
Audit any MCP server's security & quality — OWASP MCP Top 10 + explainable 0-100 MCP Score
-
Bawbel Scanner
— last commit 2026-05-23, shares owasp
Scan MCP servers and skill files for AVE vulnerabilities. Conformance scoring and threat intel.
These share tags the maintainers applied themselves, such as owasp, pentest, security, cybersecurity. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.
This is not a recommendation and not a test result. It is a map of what the authors said their work is about.
Also from cyanheads
-
io.github.cyanheads/anime-mcp-server
— last commit 2026-07-30
Search anime/manga, franchise watch order, schedule, characters, rankings, studio filmography.
-
io.github.cyanheads/arxiv-mcp-server
— last commit 2026-07-27
Search arXiv, fetch paper metadata, and read full-text content.
-
io.github.cyanheads/astronomy-mcp-server
— last commit 2026-07-31
Offline observational astronomy: positions, rise/set, moon phases, eclipses, and seasons.
-
io.github.cyanheads/attack-surface-mcp-server
— last commit 2026-07-30
Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
-
io.github.cyanheads/aviation-weather-mcp-server
— last commit 2026-07-30
Fetch METARs, TAFs, PIREPs, and SIGMETs/AIRMETs from the NWS Aviation Weather Center.
-
io.github.cyanheads/biorxiv-mcp-server
— last commit 2026-07-11
Search and retrieve bioRxiv and medRxiv preprints — by DOI, date interval, or keyword — via MCP.
-
io.github.cyanheads/bls-labor-mcp-server
— last commit 2026-07-17
Fetch US Bureau of Labor Statistics data — CPI, unemployment, wages, JOLTS, and more via MCP.
-
io.github.cyanheads/bls-mcp-server
— last commit 2026-07-17
Fetch US Bureau of Labor Statistics data — CPI, unemployment, wages, JOLTS, and more via MCP.
-
io.github.cyanheads/bluesky-mcp-server
— last commit 2026-07-31
Search posts, profiles, feeds, threads, and trending topics on Bluesky.
-
io.github.cyanheads/brapi-mcp-server
— last commit 2026-07-16
Collaborative BrAPI v2.1 MCP workspace — studies, germplasm, genotypes across Breedbase, T3, more.
How the author describes it
Topics the maintainer set on GitHub: ai-agents, ai-tools, bun, ctf, cyanheads, cybersecurity, mcp, mcp-server, mitre-attack, model-context-protocol, owasp, penetration-testing, pentest, security, security-research, typescript.
This record as data
Every field on this page, with its source and observation date, is in the catalog JSON. Fetch the whole kind at once instead of parsing this HTML.
GET /api/v1/entries/mcp_server.json