Skip to main content
Glama
Balckers

mcp-security-server

by Balckers

MCP セキュリティスキャナーサーバー v2.0

Python MCP Kali License Security

セキュリティ評価のためのプロフェッショナルな本番グレードのMCPサーバー。Model Context Protocol を搭載し、Kali Linux 向けに構築されています。

概要

AIエージェントに標準化されたセキュリティスキャン機能を提供する、プロフェッショナルな Model Context Protocol (MCP) サーバーです。厳格なコンプライアンス管理を備えた、認可されたセキュリティ評価向けに設計されています。

主な機能

  • 7ステップ必須フロー — すべてのツールが以下に従います: パラメータ検証 → セキュリティフィルタリング → 境界チェック → ビジネスロジック → 結果パッケージング → 例外キャプチャ → ロギング

  • ゼロコマンドインジェクション — すべてのシェル呼び出しはパラメータ配列を使用し、文字列連結は一切行いません

  • 必須認可 — すべてのスキャン操作には legal_authorized=true が必要です

  • 8件のCVE検証 — Log4Shell、Spring4Shell、Apache パストラバーサル、HTTP/2 Rapid Reset など

  • 標準化された出力 — 統一JSONレスポンス: code/msg/target/vuln_list/risk_level/cvss_score/suggest

  • プロフェッショナルなロギング — タスクID、スキャントレイル、監査記録付きのタイムスタンプ付きログ

Related MCP server: Security MCP Server

アーキテクチャ

mcp-security-server/
├── server.py              # MCP Server Entry Point
├── core/                  # Business Logic Layer
│   ├── scanner.py         # Scanning Engine (6 tools, 37KB)
│   ├── result.py          # Unified Response Builder
│   ├── analyzer.py        # CVSS 3.1 Scoring & Vulnerability DB
│   └── reporter.py        # Multi-format Report Generator
├── utils/                 # Infrastructure Layer
│   ├── executor.py        # Safe Command Executor (Parameter Arrays)
│   ├── validator.py       # Parameter Validation & Whitelist
│   ├── logger.py          # Professional Logging System
│   └── env.py             # Kali Environment Detection
└── requirements.txt       # Dependencies

クイックスタート

1. 依存関係のインストール

# Python packages
pip3 install mcp pydantic

# System tools (Kali Linux)
sudo apt update && sudo apt install -y nmap curl

2. サーバーの起動

cd mcp-security-server
python3 server.py

3. MCPクライアントの設定

MCPクライアント設定(例: Claude Desktop、opencode)に追加します:

{
  "mcpServers": {
    "mcp-security-scanner": {
      "command": "python3",
      "args": ["/path/to/mcp-security-server/server.py"]
    }
  }
}

ツール

ツール

説明

必須パラメータ

host_alive_detect

ホスト死活検出(ICMP + TCP SYN)

target、legal_authorized

port_scan

ポートスキャン(SYN/Connect)

target、legal_authorized

service_fingerprint

サービスバージョン検出

target、legal_authorized

web_vuln_scan

Web脆弱性スキャン

target、legal_authorized

cve_poc_check

CVE POC検証

target、legal_authorized、cve_id

report_generate

セキュリティレポート生成

target、legal_authorized、scan_data

env_check

環境・依存関係チェック

(なし)

使用例

ホスト死活検出

{
  "target": "192.168.1.1",
  "legal_authorized": true,
  "timeout": 15
}

ポートスキャン

{
  "target": "192.168.1.1",
  "legal_authorized": true,
  "ports": "80,443,8080,8443",
  "scan_type": "syn"
}

CVE検証

{
  "target": "192.168.1.1",
  "legal_authorized": true,
  "cve_id": "CVE-2021-44228",
  "port": 8080
}

レポート生成

{
  "target": "192.168.1.1",
  "legal_authorized": true,
  "scan_data": "{\"vuln_list\":[...],\"suggest\":[...]}",
  "format_type": "html"
}

対応CVE

CVE

名前

CVSS

検証方法

CVE-2021-44228

Log4Shell

10.0

Javaサービス検出

CVE-2022-22965

Spring4Shell

9.8

Spring/Tomcat検出

CVE-2023-22515

Confluence 権限昇格

10.0

セットアップエンドポイントチェック

CVE-2022-26134

Confluence OGNL

9.8

Confluence検出

CVE-2021-41773

Apache パストラバーサル

7.5

パストラバーサルテスト

CVE-2021-42013

Apache パストラバーサル 2

7.5

パストラバーサルテスト

CVE-2023-44487

HTTP/2 Rapid Reset

7.5

HTTP/2サポートチェック

CVE-2021-3449

OpenSSL NULL 参照外し

5.9

バージョン検出

標準化された出力

{
  "code": 0,
  "msg": "success",
  "target": "192.168.1.1",
  "status": "completed",
  "scan_data": { ... },
  "vuln_list": [
    {
      "vuln_id": "CVE-2021-44228",
      "vuln_name": "Log4Shell",
      "cve_id": "CVE-2021-44228",
      "cvss_score": 10.0,
      "risk_level": "Critical",
      "confidence": "Suspected",
      "description": "Apache Log4j2 RCE",
      "evidence": "Java service detected",
      "remediation": "Upgrade Log4j to 2.17.0+"
    }
  ],
  "risk_level": "critical",
  "cvss_score": 10.0,
  "suggest": ["URGENT: Fix critical vulnerability immediately"],
  "task_id": "TASK-20260822100000-a1b2c3d4",
  "timestamp": "2026-08-22T10:00:00",
  "duration": 12.34
}

ロギング

ログは自動的に log/ ディレクトリに保存されます:

ログファイル

目的

main_YYYY-MM-DD.log

一般操作

scan_YYYY-MM-DD.log

スキャン活動

error_YYYY-MM-DD.log

エラーと例外

audit_YYYY-MM-DD.log

セキュリティ監査トレイル

コンプライアンス

このツールは以下を目的として設計されています:

  • 書面による認可を得たセキュリティ評価

  • 内部セキュリティチームによる脆弱性検証

  • セキュリティ研究と教育

禁止事項: 無許可のスキャン、データ窃取、システムへの損害

ライセンス

MITライセンス - 認可されたセキュリティテストのみ

F
license - not found
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    C
    quality
    D
    maintenance
    An automated penetration testing framework that enables intelligent security assessments through reconnaissance, vulnerability scanning, and controlled exploitation. Features AI-driven workflow management with comprehensive reporting for authorized security testing.
    25
    27
    9
    7
    BSD 3-Clause
  • F
    license
    Not graded
    quality
    D
    maintenance
    Provides AI agents like Claude with secure, controlled access to network security tools like nmap for scanning private networks and lab environments. Features comprehensive safety controls, circuit breakers, and production-ready monitoring.
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to perform authorized security testing and penetration testing operations including SSL/TLS analysis, port scanning, vulnerability scanning, and HTTP security header audits through natural language interactions.
    1
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables AI agents to perform automated security testing through Caido, providing 10 security tools for vulnerability scanning (XSS, SQLi, command injection), HTTP request manipulation, and penetration testing workflows with whitelist protection.
    1

View all related MCP servers

Related MCP Connectors

  • Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Balckers/mcp-security-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server