mcp-security-server
MCP Security Scanner Server v2.0
Servidor MCP profesional de grado de producción para evaluaciones de seguridad. Impulsado por Model Context Protocol, diseñado para Kali Linux.
Descripción general
Un servidor Model Context Protocol (MCP) profesional que proporciona a los agentes de IA capacidades estandarizadas de escaneo de seguridad. Diseñado para evaluaciones de seguridad autorizadas con estrictos controles de cumplimiento.
Características principales
Flujo obligatorio de 7 pasos — Cada herramienta sigue: validación de parámetros → filtrado de seguridad → comprobaciones de límites → lógica de negocio → empaquetado de resultados → captura de excepciones → registro
Cero inyección de comandos — Todas las llamadas de shell usan matrices de parámetros, nunca concatenación de cadenas
Autorización obligatoria — Se requiere
legal_authorized=truepara todas las operaciones de escaneoVerificación de 8 CVEs — Log4Shell, Spring4Shell, Apache Path Traversal, HTTP/2 Rapid Reset y más
Salida estandarizada — Respuesta JSON unificada:
code/msg/target/vuln_list/risk_level/cvss_score/suggestRegistro profesional — Registros con marca de tiempo, IDs de tarea, rastros de escaneo y registros de auditoría
Related MCP server: Security MCP Server
Arquitectura
mcp-security-server/
├── server.py # MCP Server Entry Point
├── core/ # Business Logic Layer
│ ├── scanner.py # Scanning Engine (6 tools, 37KB)
│ ├── result.py # Unified Response Builder
│ ├── analyzer.py # CVSS 3.1 Scoring & Vulnerability DB
│ └── reporter.py # Multi-format Report Generator
├── utils/ # Infrastructure Layer
│ ├── executor.py # Safe Command Executor (Parameter Arrays)
│ ├── validator.py # Parameter Validation & Whitelist
│ ├── logger.py # Professional Logging System
│ └── env.py # Kali Environment Detection
└── requirements.txt # DependenciesInicio rápido
1. Instalar dependencias
# Python packages
pip3 install mcp pydantic
# System tools (Kali Linux)
sudo apt update && sudo apt install -y nmap curl2. Iniciar el servidor
cd mcp-security-server
python3 server.py3. Configurar el cliente MCP
Añade a la configuración de tu cliente MCP (p. ej., Claude Desktop, opencode):
{
"mcpServers": {
"mcp-security-scanner": {
"command": "python3",
"args": ["/path/to/mcp-security-server/server.py"]
}
}
}Herramientas
Herramienta | Descripción | Parámetros requeridos |
| Detección de host activo (ICMP + TCP SYN) | target, legal_authorized |
| Escaneo de puertos (SYN/Connect) | target, legal_authorized |
| Detección de versión de servicio | target, legal_authorized |
| Escaneo de vulnerabilidades web | target, legal_authorized |
| Verificación de POC de CVE | target, legal_authorized, cve_id |
| Generación de informes de seguridad | target, legal_authorized, scan_data |
| Comprobación de entorno y dependencias | (ninguno) |
Ejemplos de uso
Detección de host activo
{
"target": "192.168.1.1",
"legal_authorized": true,
"timeout": 15
}Escaneo de puertos
{
"target": "192.168.1.1",
"legal_authorized": true,
"ports": "80,443,8080,8443",
"scan_type": "syn"
}Verificación de CVE
{
"target": "192.168.1.1",
"legal_authorized": true,
"cve_id": "CVE-2021-44228",
"port": 8080
}Generar informe
{
"target": "192.168.1.1",
"legal_authorized": true,
"scan_data": "{\"vuln_list\":[...],\"suggest\":[...]}",
"format_type": "html"
}CVEs compatibles
CVE | Nombre | CVSS | Método de verificación |
CVE-2021-44228 | Log4Shell | 10.0 | Detección de servicio Java |
CVE-2022-22965 | Spring4Shell | 9.8 | Detección de Spring/Tomcat |
CVE-2023-22515 | Privilegio de Confluence | 10.0 | Comprobación de endpoint de configuración |
CVE-2022-26134 | Confluence OGNL | 9.8 | Detección de Confluence |
CVE-2021-41773 | Apache Path Traversal | 7.5 | Prueba de path traversal |
CVE-2021-42013 | Apache Path Traversal 2 | 7.5 | Prueba de path traversal |
CVE-2023-44487 | HTTP/2 Rapid Reset | 7.5 | Comprobación de soporte HTTP/2 |
CVE-2021-3449 | OpenSSL NULL deref | 5.9 | Detección de versión |
Salida estandarizada
{
"code": 0,
"msg": "success",
"target": "192.168.1.1",
"status": "completed",
"scan_data": { ... },
"vuln_list": [
{
"vuln_id": "CVE-2021-44228",
"vuln_name": "Log4Shell",
"cve_id": "CVE-2021-44228",
"cvss_score": 10.0,
"risk_level": "Critical",
"confidence": "Suspected",
"description": "Apache Log4j2 RCE",
"evidence": "Java service detected",
"remediation": "Upgrade Log4j to 2.17.0+"
}
],
"risk_level": "critical",
"cvss_score": 10.0,
"suggest": ["URGENT: Fix critical vulnerability immediately"],
"task_id": "TASK-20260822100000-a1b2c3d4",
"timestamp": "2026-08-22T10:00:00",
"duration": 12.34
}Registro
Los registros se guardan automáticamente en el directorio log/:
Archivo de registro | Propósito |
| Operaciones generales |
| Actividades de escaneo |
| Errores y excepciones |
| Rastro de auditoría de seguridad |
Cumplimiento
Esta herramienta está diseñada para:
Evaluaciones de seguridad con autorización escrita
Verificación de vulnerabilidades por parte del equipo de seguridad interno
Investigación y educación en seguridad
PROHIBIDO: Escaneo no autorizado, robo de datos, daños al sistema
Licencia
Licencia MIT: solo pruebas de seguridad autorizadas
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseCqualityDmaintenanceAn automated penetration testing framework that enables intelligent security assessments through reconnaissance, vulnerability scanning, and controlled exploitation. Features AI-driven workflow management with comprehensive reporting for authorized security testing.252797BSD 3-Clause
- FlicenseNot gradedqualityDmaintenanceProvides AI agents like Claude with secure, controlled access to network security tools like nmap for scanning private networks and lab environments. Features comprehensive safety controls, circuit breakers, and production-ready monitoring.
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to perform authorized security testing and penetration testing operations including SSL/TLS analysis, port scanning, vulnerability scanning, and HTTP security header audits through natural language interactions.1MIT
- FlicenseNot gradedqualityDmaintenanceEnables AI agents to perform automated security testing through Caido, providing 10 security tools for vulnerability scanning (XSS, SQLi, command injection), HTTP request manipulation, and penetration testing workflows with whitelist protection.1
Related MCP Connectors
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Balckers/mcp-security-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server