mcp-security-server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-security-serverScan host 192.168.1.1 for open ports"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP Security Scanner Server v2.0
Professional production-grade MCP Server for security assessment. Powered by Model Context Protocol, built for Kali Linux.
Overview
A professional Model Context Protocol (MCP) Server that provides AI agents with standardized security scanning capabilities. Designed for authorized security assessments with strict compliance controls.
Key Features
7-Step Mandatory Flow — Every tool follows: param validation → security filtering → boundary checks → business logic → result packaging → exception capture → logging
Zero Command Injection — All shell calls use parameter arrays, never string concatenation
Mandatory Authorization —
legal_authorized=truerequired for all scan operations8 CVE Verification — Log4Shell, Spring4Shell, Apache Path Traversal, HTTP/2 Rapid Reset, and more
Standardized Output — Unified JSON response:
code/msg/target/vuln_list/risk_level/cvss_score/suggestProfessional Logging — Timestamped logs with task IDs, scan trails, and audit records
Related MCP server: Security MCP Server
Architecture
mcp-security-server/
├── server.py # MCP Server Entry Point
├── core/ # Business Logic Layer
│ ├── scanner.py # Scanning Engine (6 tools, 37KB)
│ ├── result.py # Unified Response Builder
│ ├── analyzer.py # CVSS 3.1 Scoring & Vulnerability DB
│ └── reporter.py # Multi-format Report Generator
├── utils/ # Infrastructure Layer
│ ├── executor.py # Safe Command Executor (Parameter Arrays)
│ ├── validator.py # Parameter Validation & Whitelist
│ ├── logger.py # Professional Logging System
│ └── env.py # Kali Environment Detection
└── requirements.txt # DependenciesQuick Start
1. Install Dependencies
# Python packages
pip3 install mcp pydantic
# System tools (Kali Linux)
sudo apt update && sudo apt install -y nmap curl2. Start Server
cd mcp-security-server
python3 server.py3. Configure MCP Client
Add to your MCP client configuration (e.g., Claude Desktop, opencode):
{
"mcpServers": {
"mcp-security-scanner": {
"command": "python3",
"args": ["/path/to/mcp-security-server/server.py"]
}
}
}Tools
Tool | Description | Required Params |
| Host alive detection (ICMP + TCP SYN) | target, legal_authorized |
| Port scanning (SYN/Connect) | target, legal_authorized |
| Service version detection | target, legal_authorized |
| Web vulnerability scanning | target, legal_authorized |
| CVE POC verification | target, legal_authorized, cve_id |
| Security report generation | target, legal_authorized, scan_data |
| Environment & dependency check | (none) |
Usage Examples
Host Alive Detection
{
"target": "192.168.1.1",
"legal_authorized": true,
"timeout": 15
}Port Scan
{
"target": "192.168.1.1",
"legal_authorized": true,
"ports": "80,443,8080,8443",
"scan_type": "syn"
}CVE Verification
{
"target": "192.168.1.1",
"legal_authorized": true,
"cve_id": "CVE-2021-44228",
"port": 8080
}Generate Report
{
"target": "192.168.1.1",
"legal_authorized": true,
"scan_data": "{\"vuln_list\":[...],\"suggest\":[...]}",
"format_type": "html"
}Supported CVEs
CVE | Name | CVSS | Verification Method |
CVE-2021-44228 | Log4Shell | 10.0 | Java service detection |
CVE-2022-22965 | Spring4Shell | 9.8 | Spring/Tomcat detection |
CVE-2023-22515 | Confluence Privilege | 10.0 | Setup endpoint check |
CVE-2022-26134 | Confluence OGNL | 9.8 | Confluence detection |
CVE-2021-41773 | Apache Path Traversal | 7.5 | Path traversal test |
CVE-2021-42013 | Apache Path Traversal 2 | 7.5 | Path traversal test |
CVE-2023-44487 | HTTP/2 Rapid Reset | 7.5 | HTTP/2 support check |
CVE-2021-3449 | OpenSSL NULL deref | 5.9 | Version detection |
Standardized Output
{
"code": 0,
"msg": "success",
"target": "192.168.1.1",
"status": "completed",
"scan_data": { ... },
"vuln_list": [
{
"vuln_id": "CVE-2021-44228",
"vuln_name": "Log4Shell",
"cve_id": "CVE-2021-44228",
"cvss_score": 10.0,
"risk_level": "Critical",
"confidence": "Suspected",
"description": "Apache Log4j2 RCE",
"evidence": "Java service detected",
"remediation": "Upgrade Log4j to 2.17.0+"
}
],
"risk_level": "critical",
"cvss_score": 10.0,
"suggest": ["URGENT: Fix critical vulnerability immediately"],
"task_id": "TASK-20260822100000-a1b2c3d4",
"timestamp": "2026-08-22T10:00:00",
"duration": 12.34
}Logging
Logs are automatically saved to log/ directory:
Log File | Purpose |
| General operations |
| Scan activities |
| Errors & exceptions |
| Security audit trail |
Compliance
This tool is designed for:
Security assessments with written authorization
Internal security team vulnerability verification
Security research and education
PROHIBITED: Unauthorized scanning, data theft, system damage
License
MIT License - Authorized security testing only
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseCqualityDmaintenanceAn automated penetration testing framework that enables intelligent security assessments through reconnaissance, vulnerability scanning, and controlled exploitation. Features AI-driven workflow management with comprehensive reporting for authorized security testing.252797BSD 3-Clause
- FlicenseNot gradedqualityDmaintenanceProvides AI agents like Claude with secure, controlled access to network security tools like nmap for scanning private networks and lab environments. Features comprehensive safety controls, circuit breakers, and production-ready monitoring.
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to perform authorized security testing and penetration testing operations including SSL/TLS analysis, port scanning, vulnerability scanning, and HTTP security header audits through natural language interactions.1MIT
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to perform automated security testing through Caido, providing 10 security tools for vulnerability scanning (XSS, SQLi, command injection), HTTP request manipulation, and penetration testing workflows with whitelist protection.1
Related MCP Connectors
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Balckers/mcp-security-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server