Track MCP LogoTrack MCP
Track MCP LogoTrack MCP

The world's largest repository of Model Context Protocol servers. Discover, explore, and submit MCP tools.

Product

  • Categories
  • Top MCP
  • New & Updated
  • Submit MCP

Company

  • About

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 TrackMCP. All rights reserved.

Built with ❤️ by Krishna Goyal

    Mcp For Security

    A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF, NMAP, Masscan and more. TypeScript-based implementation.

    465 stars
    TypeScript
    Updated Nov 1, 2025
    ai-assistants
    ai-security
    cybersecurity
    hacking-tools
    mcp
    mcp-ai
    mcp-pentest
    mcp-security
    model-context-protocol
    pentesting
    security-automation
    security-integrations
    security-testing
    security-tools
    web-security

    Table of Contents

    • Cyprox
    • 🚀 Project Overview
    • 🌐 Installation
    • Docker
    • Manuel
    • Available Tools
    • Quick Reference
    • Alterx MCP
    • Amass MCP
    • arjun MCP
    • Assetfinder MCP
    • Cero MCP Server
    • Certificate Search (crt.sh) MCP
    • FFUF MCP Server
    • Gowitness MCP Server
    • HTTP Headers Security MCP
    • httpx MCP
    • Katana MCP
    • Masscan MCP Server
    • MobSF MCP Server
    • Nmap MCP Server
    • Nuclei MCP Server
    • Scout Suite MCP Server
    • shuffledns MCP
    • smuggler MCP
    • SQLmap MCP Server
    • SSLScan MCP Server
    • Waybackurls MCP
    • WPScan MCP
    • TO-DO Tools
    • Development
    • Installation
    • Usage

    Table of Contents

    • Cyprox
    • 🚀 Project Overview
    • 🌐 Installation
    • Docker
    • Manuel
    • Available Tools
    • Quick Reference
    • Alterx MCP
    • Amass MCP
    • arjun MCP
    • Assetfinder MCP
    • Cero MCP Server
    • Certificate Search (crt.sh) MCP
    • FFUF MCP Server
    • Gowitness MCP Server
    • HTTP Headers Security MCP
    • httpx MCP
    • Katana MCP
    • Masscan MCP Server
    • MobSF MCP Server
    • Nmap MCP Server
    • Nuclei MCP Server
    • Scout Suite MCP Server
    • shuffledns MCP
    • smuggler MCP
    • SQLmap MCP Server
    • SSLScan MCP Server
    • Waybackurls MCP
    • WPScan MCP
    • TO-DO Tools
    • Development
    • Installation
    • Usage

    Documentation

    MCP for Security

    License

    Stars

    Docker

    ---

    About Cyprox — The Future of AI-Driven Cybersecurity

    Cyprox is pioneering the future of cybersecurity by combining artificial intelligence and security tools to empower organizations with next-level threat detection and automated response.

    *"The Future of Cybersecurity Humans and AI, Working Together..."*

    Cyprox

    • 🚀 AI Driven Solutions: Cybersecurity solutions using Agentic-AI systems with an AI-driven approach
    • 🌐 Community-Driven: Open-source projects fostering collaboration and rapid evolution.
    • ⚡ Speed & Precision: Automated threat detection that reduces human latency.
    • 🔒 Secure & Transparent: Trustworthy platform built with open standards.

    Explore more at https://cyprox.io

    ---

    🚀 Project Overview

    MCP for Security repository contains Model Context Protocol (MCP) server implementations for various security testing tools, making them accessible through a standardized interface.

    ---

    🌐 Installation

    Docker

    You can use all MCP servers through Docker using the cyprox/mcp-for-security Docker image. It can also be used from any MCP client with Docker support, such as the Cyprox platform.

    Visit Cyprox for more information.

    Manuel

    Since each MCP server may require different dependencies, the start.sh bash script provides a general setup mechanism. Nonetheless, users should always refer to the installation instructions specific to the corresponding MCP server to ensure proper setup.

    ---

    Available Tools

    ToolDescriptionDetailed Documentation
    AmassAdvanced subdomain enumeration and reconnaissance toolAmass MCP Documentation
    AlterxPattern-based wordlist generator for subdomain discoveryAlterx MCP Documentation
    ArjunRun Arjun to discover hidden HTTP parametersArjun MCP Documentation
    AssetfinderPassive subdomain discovery tool based on Tomnomnom’s AssetfinderAssetfinder MCP Documentation
    CeroCertificate-based subdomain enumeration tool leveraging TLS handshakes to extract domain names from certificate fields like SANCero MCP Documentation
    Certificate Search (crt.sh)Subdomain discovery tool using SSL certificate logsCertificate Search MCP Documentation
    FFUFWeb content fuzzing tool for discovering hidden files and directoriesFFUF MCP Documentation
    GowitnessWeb screenshot and reconnaissance tool for capturing and analyzing web pagesGowitness MCP Documentation
    HTTP Headers SecurityAnalyzer for HTTP security headers against OWASP standardsHTTP Headers MCP Documentation
    httpxFast and multi-purpose HTTP toolkit for port scanning.httpx MCP Documentation
    KatanaFast and flexible web crawler with JS parsing and hybrid crawling supportKatana MCP Documentation
    MasscanFast port scanner for large-scale network discoveryMasscan MCP Documentation
    MobSFMobile security framework for analyzing mobile applicationsMobSF MCP Documentation
    NmapComprehensive network scanning tool for service and vulnerability discoveryNmap MCP Documentation
    NucleiVulnerability scanner using custom templatesNuclei MCP Documentation
    Scout SuiteCloud security auditing tool for assessing configurations across multiple servicesScout Suite MCP Documentation
    SSLScanSSL/TLS configuration analyzer for security assessmentSSLScan MCP Documentation
    shufflednsHigh-speed and customizable DNS brute-forcing and resolution toolshuffledns MCP Documentation
    SmugglerAdvanced tool for detecting HTTP Request Smuggling vulnerabilitiesSmuggler MCP Documentation
    SQLmapAdvanced SQL injection detection and exploitation toolSQLmap MCP Documentation
    WaybackurlsTool for retrieving historical URLs from the Wayback MachineWaybackurls MCP Documentation
    WPScanWordPress vulnerability scanner for detecting plugins, themes, and configuration issuesWPScan MCP Documentation

    Quick Reference

    Alterx MCP

    Generates custom wordlists for subdomain discovery using pattern-based permutations.

    Amass MCP

    Advanced reconnaissance tool for subdomain enumeration and intelligence gathering with both passive and active modes.

    arjun MCP

    Discovers hidden HTTP parameters on web applications by scanning URLs, supporting custom wordlists, multiple methods, and adjustable scanning speeds.

    Assetfinder MCP

    Discovers subdomains related to a given domain using passive enumeration techniques. Integrates Tomnomnom’s Assetfinder into the MCP ecosystem for fast and reliable reconnaissance.

    Cero MCP Server

    Certificate-based subdomain discovery tool that extracts domain names from TLS certificates for reconnaissance and infrastructure mapping.

    Certificate Search (crt.sh) MCP

    Discovers subdomains by querying SSL certificate transparency logs without active scanning.

    FFUF MCP Server

    URL-based fuzzing tool with support for all FFUF command line arguments.

    Gowitness MCP Server

    Web screenshot and reconnaissance tool that captures screenshots of web pages, analyzes HTTP responses, and provides visual reconnaissance capabilities for security assessments and web application testing.

    HTTP Headers Security MCP

    Analyzes HTTP response headers against OWASP security standards with recommendations.

    httpx MCP

    Performs high-speed probing of discovered subdomains to validate alive hosts, fetch response details, and enrich reconnaissance data without heavy scanning.

    Katana MCP

    Performs fast and customizable web crawling to discover endpoints, scripts, and hidden paths. Supports JavaScript parsing, depth control, and hybrid crawling with headless browsers to enrich reconnaissance and automation workflows.

    Masscan MCP Server

    Fast port scanning tool for target-based port discovery across networks.

    MobSF MCP Server

    Mobile application security testing framework for Android, iOS, and Windows applications.

    Nmap MCP Server

    Full-featured network scanner with detailed service fingerprinting and vulnerability detection.

    Nuclei MCP Server

    Template-based vulnerability scanner with an extensive library of security checks.

    Scout Suite MCP Server

    Performs a multi-service cloud security audit by analyzing cloud configurations and highlighting potential misconfigurations and risks based on best practices.

    shuffledns MCP

    High-speed DNS brute-forcing and mass subdomain resolution tool to quickly discover valid subdomains using custom resolvers and wordlists.

    smuggler MCP

    HTTP Request Smuggling detection tool that identifies desynchronization vulnerabilities between front-end and back-end servers.

    SQLmap MCP Server

    SQL injection testing tool with comprehensive capabilities for vulnerability discovery.

    SSLScan MCP Server

    SSL/TLS configuration analyzer for identifying weak ciphers and security misconfigurations.

    Waybackurls MCP

    Retrieves historical URLs from the Wayback Machine to discover forgotten endpoints.

    WPScan MCP

    WordPress vulnerability scanner for detecting outdated plugins, themes, and common misconfigurations.

    TO-DO Tools

    • commix
    • Corsy
    • CrackMapExec
    • crlfuzz
    • dalfox
    • dnsrecon
    • feroxbuster
    • gau
    • getJS
    • github-endpoints
    • github-subdomains
    • gobuster
    • gospider
    • hakrawler
    • kiterunner
    • medusa
    • naabu
    • ParamSpider
    • puredns
    • s3scanner
    • tlsx
    • wafw00f
    • webscreenshot
    • wpscan
    • ...

    Development

    The project uses TypeScript and the Model Context Protocol SDK. To contribute:

    1. Fork the repository

    2. Create a feature branch

    3. Make your changes

    4. Submit a pull request

    Installation

    For installation instructions for each tool, please refer to the individual documentation linked in the table above.

    Usage

    Each tool has specific parameters and usage instructions. For detailed information, see the documentation for the specific tool you want to use.

    Similar MCP

    Based on tags & features

    • AN

      Anilist Mcp

      TypeScript·
      57
    • MC

      Mcp Ipfs

      TypeScript·
      11
    • MC

      Mcpjungle

      Go·
      617
    • MC

      Mcp Open Library

      TypeScript·
      42

    Trending MCP

    Most active this week

    • PL

      Playwright Mcp

      TypeScript·
      22.1k
    • SE

      Serena

      Python·
      14.5k
    • MC

      Mcp Playwright

      TypeScript·
      4.9k
    • MC

      Mcp Server Cloudflare

      TypeScript·
      3.0k
    View All MCP Servers

    Similar MCP

    Based on tags & features

    • AN

      Anilist Mcp

      TypeScript·
      57
    • MC

      Mcp Ipfs

      TypeScript·
      11
    • MC

      Mcpjungle

      Go·
      617
    • MC

      Mcp Open Library

      TypeScript·
      42

    Trending MCP

    Most active this week

    • PL

      Playwright Mcp

      TypeScript·
      22.1k
    • SE

      Serena

      Python·
      14.5k
    • MC

      Mcp Playwright

      TypeScript·
      4.9k
    • MC

      Mcp Server Cloudflare

      TypeScript·
      3.0k