Kitsune vulnerability research MCP
OfficialRelated Servers
Alternatives to Kitsune vulnerability research MCP
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityCmaintenanceA local Python MCP server for safe, human-led bug bounty recon, providing lightweight helpers for scope checks, headers, robots.txt, sitemap.xml, JavaScript URL collection, endpoint extraction, URL deduplication, evidence notes, and manual test planning.MIT
- AlicenseBqualityDmaintenanceAn MCP server for authorized bug bounty work that enforces an evidence-driven workflow with session management, preflight checks, surface discovery, and verified scanning.12MIT
- AlicenseAqualityBmaintenanceAn MCP server that provides passive and low-impact active reconnaissance tools for authorized bug bounty and security assessments, enabling LLMs to perform structured recon and generate reports.11Apache 2.0
- AlicenseAqualityBmaintenanceA scope-aware bug-bounty & reconnaissance MCP server that works out of the box on the Python standard library and augments itself with your favourite CLI tools when they're present.22MIT
- AlicenseNot gradedqualityBmaintenanceStandalone MCP server that provides security scanning, project mapping, and vulnerability fix generation to AI coding assistants.27 npm2MIT
- AlicenseCqualityAmaintenanceA local-first, authorization-gated MCP server for web security assessment that transforms URLs into traceable, reviewable reports and integrates with Claude Code and local LLMs.15MIT
TDQS
Scored across 19 tools
Most tools have distinct purposes (e.g., sync vs. search vs. prioritize for vulnerabilities; register vs. check vs. create vs. assess for research). However, there is a small overlap between vuln_get_cve and vuln_search_cves (both retrieve CVE data) and between vuln_refresh_vrt and vuln_search_vrt (both operate on the VRT). The descriptions help differentiate them, but the boundaries are not perfectly sharp.
Tool names follow a consistent verb_noun pattern with prefixes: 'vuln_' for vulnerability operations and 'research_' for research scope/case operations. Within each group, verbs like refresh, sync, get, search, query are clear. Minor deviation: 'research_export_report' is a noun-heavy name, but overall the pattern is strong.
19 tools is on the higher end but still appropriate for a server covering two domains (vulnerability data and research management). Each tool addresses a specific operation in the vulnerability lifecycle (sync, search, prioritize) and research workflow (scope, case, evidence, patch). A slight reduction could be achieved by merging some closely related tools, but the count is not excessive.
The vulnerability domain covers syncing from multiple sources (NVD, KEV, EPSS, OSV), searching, prioritization, and status monitoring. The research side covers scope registration, case creation, SARIF import, evidence recording, finding assessment, report export, and patch verification. Minor gaps: there is no tool for updating/deleting a case or for submitting a report to Bugcrowd. These are reasonable omissions given the stated local audit focus.