- Conduid
- Marketplace
- #penetration-testing
MCP servers tagged penetration-testing
32 live MCP servers tagged "penetration-testing", ranked by trust score. Tags come from package metadata and repository topics, so this list covers servers across every category that work with penetration-testing.
Browserbruter
BrowserBruter is a powerful web form fuzzing automation tool designed for web security professionals and penetration testers. This Python-based tool leverages Selenium and Seleniu…
Pentestagent
PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.
Anthropic Cybersecurity Skills
753+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini…
Redamon
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
Pentesting MCP Servers Checklist
A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained b…
Pentest MCP Server
AI-powered security testing for Claude Desktop. MCP server integrating 6 essential pentesting tools (nmap, nikto, sqlmap, wpscan, dirb, searchsploit) in a secure Kali Linux Docker…
LuaN1aoAgent
LuaN1aoAgent is a cognitive-driven AI hacker. It is a fully autonomous AI penetration testing agent powered by DeepSeek V3.2. Using dual-graph reasoning, LuaN1ao achieves a succes…
Reconmap
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and re…
Dark Moon
Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities.…
CyberStrike
AI-powered offensive security agent. Autonomous pentesting with 13+ specialized agents, 120+ OWASP test cases, 15+ LLM providers, and Bolt remote tool servers. Your AI red team.
Claude Active Directory
AI agent harness for Active Directory offensive security — 8 skill domains, 13 slash commands, 7 agents, ROE-safe orchestration. Part of DoOS by Evaluris Solutions Labs.
Tengu
AI-powered penetration testing MCP server
Signature Cloaking
This research introduces MCP Signature Cloaking - a novel backdoor technique that allows attackers to exploit hidden parameters in MCP servers, concealing malicious behavior behin…
Pentester MCP
Elevate your AI assistants (like Claude & Cursor) into autonomous cybersecurity experts. Pentester-MCP integrates 200+ pentesting tools via the Model Context Protocol (MCP) using…
Pentest AI
The most autonomous pentesting AI on the market. MCP server + Python agents with 150+ security tools, exploit chaining, and PoC validation.
Client And Proxy
A universal MCP client with proxying feature to interact with MCP Servers which support STDIO transport.
RedTeam Agent
RedTeam-MCP: AI-Powered Autonomous Red Team Framework via Model Context Protocol. AI红队与内网渗透自动化框架,支持 gogo, fscan, httpx, nuclei, impacket, playwright 等 15+ 渗透工具,让 LLM 直接化身安全审计黑客。
Pentest
MCP server for authorized pentest workflows: Nmap/Gobuster orchestration, context aggregation, AI-assisted triage, and reporting.
Js Recon
JS Enumeration & SAST
Osint MCP Server
OSINT intelligence MCP server for AI agents — 37 tools, 12 sources. Shodan, VirusTotal, Censys, SecurityTrails, DNS reconnaissance, WHOIS, certificate transparency, BGP routing, W…
Yorishiro Proxy
AI-native MITM proxy — MCP server for traffic interception, recording & replay
Firebreak
Security MCP server that turns your AI into a penetration tester. 20 tools, 100 best practice guides, 47 vulnerability patterns. Connect to Claude, Cursor, or any MCP client.
Thru Burp
A cross-platform desktop UI MCP client specifically for proxying MCP traffic through Burp Suite Proxy. Useful for recon and fuzzing when pentesting a remote MCP HTTP server.
Shannon On Claude Code
Shannon's 5-phase pentest pipeline running natively in Claude Code — no Docker, no Temporal, just /pentest https://github.com/KeygraphHQ/shannon
Prompt Injection MCP
MCP Server for authorized AI security research and penetration testing (Educational purposes only - requires explicit authorization)
Gemini Vuln Scanner
Vulnerability Scanning and Reconnaissance App with Gemini integrated workflow
SPECTRE
[SPECTRE] Security Platform for Encrypted Comms, Testing, Enumeration, Recon ... unified offensive security toolkit integrating WRAITH-Protocol comms, ProRT-IP reconnaissance, and…
Decoy Redteam
Autonomous red team for MCP servers. Sends adversarial payloads to your tools, proves exploitation, reports what's broken. 53 attack patterns across 6 categories. Zero dependencie…
Nsauditor AI
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration.…
Cybersec Toolkit
580+ cybersecurity tools, one command. Modular bash installer for Linux & Termux with 14 profiles, 18 modules, and an MCP server for AI-assisted ethical hacking.
Frameseven
Offensive web security scanner — OWASP Top 10 · MCP server · CLI · Go
BurpMcpEnhance
Enhanced Burp Suite MCP Server — Streamable HTTP solves AI disconnection; SQLite cache prevents Burp freezing under load.Burp Suite MCP Server 增强版 — Streamable HTTP 彻底解决AI断连,SQLit…