शैक्षिक उद्देश्यों के लिए नहीं: एक MCP सर्वर जो पेशेवर पेनिट्रेशन टेस्टरों के लिए है, जिसमें STDIO/HTTP/SSE समर्थन, nmap, go/dirbuster, nikto, JtR, hashcat, वर्डलिस्ट निर्माण, और अधिक शामिल है।
आधुनिक ट्रांसपोर्ट/प्रमाणीकरण समर्थन और विस्तारित रिकॉन टूलिंग के साथ पेशेवर पेनिट्रेशन-टेस्टिंग MCP सर्वर।
@modelcontextprotocol/sdk@^1.26.0 में अपग्रेड किया गया@modelcontextprotocol/inspector@^0.20.0) पर बनाए रखा गया, बंडल लॉन्चर के साथMCP_TRANSPORT=http)subfinderEnum, httpxProbe, ffufScan, nucleiScan, trafficCapture, hydraBruteforce, privEscAudit, extractionSweeplistEngagementRecords, getEngagementRecordscopeMode=ask) का उपयोग करके रिपोर्टों के लिए SoW कैप्चर फ़्लो जोड़ा गयाhttpx-toolkit (पसंदीदा) या मान्य ProjectDiscovery httpx का उपयोग करे, Python httpx CLI टकरावों से बचने के लिएpentest-mcp inspector)nmapScanrunJohnTheRipperrunHashcatgobusterniktosubfinderEnumhttpxProbeffufScannucleiScantrafficCapturehydraBruteforceprivEscAuditextractionSweepgenerateWordlistlistEngagementRecordsgetEngagementRecordcreateClientReportcancelScannpm install -g pentest-mcp
pentest-mcp
pentest-mcp inspector
आप सीधे Inspector फ़्लैग्स अग्रेषित कर सकते हैं:
pentest-mcp inspector --help
MCP_TRANSPORT=http MCP_SERVER_HOST=0.0.0.0 MCP_SERVER_PORT=8000 pentest-mcp
MCP_TRANSPORT=sse MCP_SERVER_PORT=8001 pentest-mcp
stdio: स्थानीय MCP क्लाइंट के लिए डिफ़ॉल्ट।http: आधुनिक नेटवर्क ट्रांसपोर्ट। अनुशंसित।sse: केवल संगतता। अप्रचलित और भविष्य के प्रमुख रिलीज़ में हटा दिया जाएगा।pentest-mcp inspector बंडल @modelcontextprotocol/inspector CLI लॉन्च करता है।node <this-package-entrypoint> stdioMCP_TRANSPORT=http (या यदि आवश्यक हो तो sse) का उपयोग करते समय ये env वेरिएबल सेट करें:
MCP_AUTH_ENABLED=true
MCP_AUTH_MODE=bearer
MCP_AUTH_SCOPES=read,write
MCP_AUTH_AUDIENCE=
MCP_OIDC_ISSUER=https://issuer.example.com
MCP_OIDC_JWKS_URL=https://issuer.example.com/.well-known/jwks.json
# वैकल्पिक/बैकअप सत्यापन मोड:
MCP_OIDC_INTROSPECTION_URL=https://issuer.example.com/oauth/introspect
MCP_OAUTH_CLIENT_ID=...
MCP_OAUTH_CLIENT_SECRET=...
लीगेसी उपनाम अभी भी अस्थायी रूप से स्वीकार किए जाते हैं:
MCP_OAUTH_ENABLEDMCP_OAUTH_PROVIDER_URLMCP_OAUTH_SCOPEScreateClientReport अब SoW हैंडलिंग मोड का समर्थन करता है:
scopeMode=ask: MCP एलिसिटेशन के माध्यम से उपयोगकर्ता को संकेत दें (अनुशंसित)scopeMode=provided: सीधे scopeOfWork मान का उपयोग करेंscopeMode=template: अंतर्निहित सामान्य अधिकृत-परीक्षण टेम्पलेट का उपयोग करेंयदि एलिसिटेशन स्वीकार/उपलब्ध नहीं है, तो रिपोर्ट स्वचालित रूप से टेम्पलेट पर वापस आ जाती है।
अभी तक कोई अलग फ़ाइल-अपलोड API नहीं है। वर्तमान विकल्प हैं:
{
"tool": "createClientReport",
"arguments": {
"title": "Q1 External Pentest",
"assessmentType": "external-network",
"scopeMode": "ask"
}
}
scopeOfWork में पेस्ट करें{
"tool": "createClientReport",
"arguments": {
"title": "Q1 External Pentest",
"assessmentType": "external-network",
"scopeMode": "provided",
"scopeOfWork": "Authorized targets: ...\nOut-of-scope: ...\nTesting window: ...\nRules of engagement: ..."
}
}
{
"tool": "createClientReport",
"arguments": {
"title": "Q1 External Pentest",
"assessmentType": "external-network",
"scopeMode": "template"
}
}
recordId=...) संग्रहीत करता है।listEngagementRecords का उपयोग करें।recordIds (या डिफ़ॉल्ट रूप से नवीनतम रिकॉर्ड) से रिपोर्ट तैयार करें।ask)provided)template)ये विशेष रूप से पेंटेस्ट प्रशासनिक ओवरहेड को कम करने के लिए नियोजित हैं।
scopeFilePath इन्जेशन (MCP होस्ट पर स्थानीय फ़ाइल पथ से SoW लोड करें)scopeDocument चंक्ड अपलोड फ़्लो (रिमोट क्लाइंट के लिए MCP के माध्यम से सीधे SoW सामग्री भेजें)recordId) से निष्कर्षों और रिपोर्ट अनुभागों में साक्ष्य ऑटो-लिंकिंगnuclei, nikto, आदि) में निष्कर्ष डीडुप/मर्जअपनाने पर ध्यान दें:
scopeFilePath और scopeDocument के लिए मजबूत उपयोग की उम्मीद है क्योंकि अधिकांश टीमें पहले से ही SoW को दस्तावेज़ों/PDF में बनाए रखती हैं और बार-बार पेस्ट-एंड-रिफ़ॉर्मेट चरणों से बचना चाहती हैं।{
"tool": "subfinderEnum",
"arguments": {
"domain": "example.com",
"recursive": true,
"allSources": true
}
}
{
"tool": "httpxProbe",
"arguments": {
"targets": ["example.com", "api.example.com"],
"includeTitle": true,
"includeStatusCode": true
}
}
{
"tool": "ffufScan",
"arguments": {
"targetUrl": "https://example.com/FUZZ",
"wordlist": "/usr/share/seclists/Discovery/Web-Content/common.txt",
"threads": 40
}
}
{
"tool": "nucleiScan",
"arguments": {
"targets": ["https://example.com"],
"severities": ["medium", "high", "critical"]
}
}
{
"tool": "trafficCapture",
"arguments": {
"networkInterface": "eth0",
"packetCount": 200,
"bpfFilter": "tcp port 80"
}
}
{
"tool": "hydraBruteforce",
"arguments": {
"target": "10.10.10.20",
"service": "ssh",
"usernameList": "/usr/share/seclists/Usernames/top-usernames-shortlist.txt",
"passwordList": "/usr/share/seclists/Passwords/Common-Credentials/10k-most-common.txt"
}
}
{
"tool": "extractionSweep",
"arguments": {
"targetUrl": "https://target.local/item.php?id=1",
"risk": 2,
"level": 3
}
}