Skip to main content
Glama
Balckers

mcp-security-server

by Balckers

MCP Security Scanner Server v2.0

Python MCP Kali License Security

Servidor MCP profesional de grado de producción para evaluaciones de seguridad. Impulsado por Model Context Protocol, diseñado para Kali Linux.

Descripción general

Un servidor Model Context Protocol (MCP) profesional que proporciona a los agentes de IA capacidades estandarizadas de escaneo de seguridad. Diseñado para evaluaciones de seguridad autorizadas con estrictos controles de cumplimiento.

Características principales

  • Flujo obligatorio de 7 pasos — Cada herramienta sigue: validación de parámetros → filtrado de seguridad → comprobaciones de límites → lógica de negocio → empaquetado de resultados → captura de excepciones → registro

  • Cero inyección de comandos — Todas las llamadas de shell usan matrices de parámetros, nunca concatenación de cadenas

  • Autorización obligatoria — Se requiere legal_authorized=true para todas las operaciones de escaneo

  • Verificación de 8 CVEs — Log4Shell, Spring4Shell, Apache Path Traversal, HTTP/2 Rapid Reset y más

  • Salida estandarizada — Respuesta JSON unificada: code/msg/target/vuln_list/risk_level/cvss_score/suggest

  • Registro profesional — Registros con marca de tiempo, IDs de tarea, rastros de escaneo y registros de auditoría

Related MCP server: Security MCP Server

Arquitectura

mcp-security-server/
├── server.py              # MCP Server Entry Point
├── core/                  # Business Logic Layer
│   ├── scanner.py         # Scanning Engine (6 tools, 37KB)
│   ├── result.py          # Unified Response Builder
│   ├── analyzer.py        # CVSS 3.1 Scoring & Vulnerability DB
│   └── reporter.py        # Multi-format Report Generator
├── utils/                 # Infrastructure Layer
│   ├── executor.py        # Safe Command Executor (Parameter Arrays)
│   ├── validator.py       # Parameter Validation & Whitelist
│   ├── logger.py          # Professional Logging System
│   └── env.py             # Kali Environment Detection
└── requirements.txt       # Dependencies

Inicio rápido

1. Instalar dependencias

# Python packages
pip3 install mcp pydantic

# System tools (Kali Linux)
sudo apt update && sudo apt install -y nmap curl

2. Iniciar el servidor

cd mcp-security-server
python3 server.py

3. Configurar el cliente MCP

Añade a la configuración de tu cliente MCP (p. ej., Claude Desktop, opencode):

{
  "mcpServers": {
    "mcp-security-scanner": {
      "command": "python3",
      "args": ["/path/to/mcp-security-server/server.py"]
    }
  }
}

Herramientas

Herramienta

Descripción

Parámetros requeridos

host_alive_detect

Detección de host activo (ICMP + TCP SYN)

target, legal_authorized

port_scan

Escaneo de puertos (SYN/Connect)

target, legal_authorized

service_fingerprint

Detección de versión de servicio

target, legal_authorized

web_vuln_scan

Escaneo de vulnerabilidades web

target, legal_authorized

cve_poc_check

Verificación de POC de CVE

target, legal_authorized, cve_id

report_generate

Generación de informes de seguridad

target, legal_authorized, scan_data

env_check

Comprobación de entorno y dependencias

(ninguno)

Ejemplos de uso

Detección de host activo

{
  "target": "192.168.1.1",
  "legal_authorized": true,
  "timeout": 15
}

Escaneo de puertos

{
  "target": "192.168.1.1",
  "legal_authorized": true,
  "ports": "80,443,8080,8443",
  "scan_type": "syn"
}

Verificación de CVE

{
  "target": "192.168.1.1",
  "legal_authorized": true,
  "cve_id": "CVE-2021-44228",
  "port": 8080
}

Generar informe

{
  "target": "192.168.1.1",
  "legal_authorized": true,
  "scan_data": "{\"vuln_list\":[...],\"suggest\":[...]}",
  "format_type": "html"
}

CVEs compatibles

CVE

Nombre

CVSS

Método de verificación

CVE-2021-44228

Log4Shell

10.0

Detección de servicio Java

CVE-2022-22965

Spring4Shell

9.8

Detección de Spring/Tomcat

CVE-2023-22515

Privilegio de Confluence

10.0

Comprobación de endpoint de configuración

CVE-2022-26134

Confluence OGNL

9.8

Detección de Confluence

CVE-2021-41773

Apache Path Traversal

7.5

Prueba de path traversal

CVE-2021-42013

Apache Path Traversal 2

7.5

Prueba de path traversal

CVE-2023-44487

HTTP/2 Rapid Reset

7.5

Comprobación de soporte HTTP/2

CVE-2021-3449

OpenSSL NULL deref

5.9

Detección de versión

Salida estandarizada

{
  "code": 0,
  "msg": "success",
  "target": "192.168.1.1",
  "status": "completed",
  "scan_data": { ... },
  "vuln_list": [
    {
      "vuln_id": "CVE-2021-44228",
      "vuln_name": "Log4Shell",
      "cve_id": "CVE-2021-44228",
      "cvss_score": 10.0,
      "risk_level": "Critical",
      "confidence": "Suspected",
      "description": "Apache Log4j2 RCE",
      "evidence": "Java service detected",
      "remediation": "Upgrade Log4j to 2.17.0+"
    }
  ],
  "risk_level": "critical",
  "cvss_score": 10.0,
  "suggest": ["URGENT: Fix critical vulnerability immediately"],
  "task_id": "TASK-20260822100000-a1b2c3d4",
  "timestamp": "2026-08-22T10:00:00",
  "duration": 12.34
}

Registro

Los registros se guardan automáticamente en el directorio log/:

Archivo de registro

Propósito

main_YYYY-MM-DD.log

Operaciones generales

scan_YYYY-MM-DD.log

Actividades de escaneo

error_YYYY-MM-DD.log

Errores y excepciones

audit_YYYY-MM-DD.log

Rastro de auditoría de seguridad

Cumplimiento

Esta herramienta está diseñada para:

  • Evaluaciones de seguridad con autorización escrita

  • Verificación de vulnerabilidades por parte del equipo de seguridad interno

  • Investigación y educación en seguridad

PROHIBIDO: Escaneo no autorizado, robo de datos, daños al sistema

Licencia

Licencia MIT: solo pruebas de seguridad autorizadas

F
license - not found
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    C
    quality
    D
    maintenance
    An automated penetration testing framework that enables intelligent security assessments through reconnaissance, vulnerability scanning, and controlled exploitation. Features AI-driven workflow management with comprehensive reporting for authorized security testing.
    25
    27
    9
    7
    BSD 3-Clause
  • F
    license
    Not graded
    quality
    D
    maintenance
    Provides AI agents like Claude with secure, controlled access to network security tools like nmap for scanning private networks and lab environments. Features comprehensive safety controls, circuit breakers, and production-ready monitoring.
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to perform authorized security testing and penetration testing operations including SSL/TLS analysis, port scanning, vulnerability scanning, and HTTP security header audits through natural language interactions.
    1
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables AI agents to perform automated security testing through Caido, providing 10 security tools for vulnerability scanning (XSS, SQLi, command injection), HTTP request manipulation, and penetration testing workflows with whitelist protection.
    1

View all related MCP servers

Related MCP Connectors

  • Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Balckers/mcp-security-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server