Provides authentication capabilities via OAuth2 for testing secured GitHub API endpoints to identify security vulnerabilities in authentication flows, token handling, and data access controls.
Supports the installation and dependency management through package.json, allowing the MCP server to be installed and run for cybersecurity API testing purposes.
Provides TypeScript integration for implementing strongly-typed security testing tools and utilities, with configuration through tsconfig.json to support the MCP server development.
š CyberMCP
AI-powered Cybersecurity API Testing with Model Context Protocol (MCP)
CyberMCP is a Model Context Protocol (MCP) server that enables AI agents to perform comprehensive security testing on backend APIs. It provides 14 specialized security tools and 10 resources for identifying vulnerabilities like authentication bypass, injection attacks, data leakage, and security misconfigurations.
š Quick Start
Related MCP server: Mutmut MCP
⨠Features
š Authentication Testing - JWT analysis, bypass detection, OAuth2 flows
š Injection Testing - SQL injection, XSS vulnerability detection
š Data Protection - Sensitive data exposure, path traversal checks
ā±ļø Rate Limiting - DoS vulnerability assessment
š”ļø Security Headers - OWASP security header validation
š Comprehensive Resources - Security checklists and testing guides
š ļø Security Tools (14 Total)
Category | Tools |
Authentication |
|
Injection Testing |
|
Data Protection |
|
Infrastructure |
|
šÆ IDE Integration
CyberMCP works with all major AI-powered IDEs:
Claude Desktop - Direct MCP integration
Cursor IDE - Built-in MCP support
Windsurf (Codeium) - Native MCP protocol
VS Code + Cline - Extension-based integration
š Complete Setup Guide - Detailed configuration for each IDE
š Usage Example
The AI agent will:
Configure authentication credentials
Test the protected endpoint for bypass vulnerabilities
Provide detailed security analysis and recommendations
š Testing & Validation
š Project Structure
š§ Development
š Documentation
Setup Guide - Detailed installation and configuration
Project Summary - Complete feature overview
Testing Results - Validation and test coverage
š¤ Contributing
Fork the repository
Create a feature branch:
git checkout -b feature/new-security-toolMake your changes and add tests
Submit a pull request
š License
This project is licensed under the MIT License - see the LICENSE file for details.
š Resources
Model Context Protocol - Official MCP documentation
OWASP API Security - API security best practices
MCP TypeScript SDK - Development framework
š Secure your APIs with AI-powered testing!
For support and questions, please