Skip to main content
Glama
KitsuneTech1

Kitsune vulnerability research MCP

Official
by KitsuneTech1

Related Servers

Alternatives to Kitsune vulnerability research MCP

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      C
      maintenance
      A local Python MCP server for safe, human-led bug bounty recon, providing lightweight helpers for scope checks, headers, robots.txt, sitemap.xml, JavaScript URL collection, endpoint extraction, URL deduplication, evidence notes, and manual test planning.
      MIT
    • A
      license
      B
      quality
      D
      maintenance
      An MCP server for authorized bug bounty work that enforces an evidence-driven workflow with session management, preflight checks, surface discovery, and verified scanning.
      12
      MIT
    • A
      license
      A
      quality
      B
      maintenance
      An MCP server that provides passive and low-impact active reconnaissance tools for authorized bug bounty and security assessments, enabling LLMs to perform structured recon and generate reports.
      11
      Apache 2.0
    • A
      license
      A
      quality
      B
      maintenance
      A scope-aware bug-bounty & reconnaissance MCP server that works out of the box on the Python standard library and augments itself with your favourite CLI tools when they're present.
      22
      MIT
    • A
      license
      C
      quality
      A
      maintenance
      A local-first, authorization-gated MCP server for web security assessment that transforms URLs into traceable, reviewable reports and integrates with Claude Code and local LLMs.
      15
      MIT

    TDQS

    A3.6/5.0

    Scored across 19 tools

    Disambiguation4/5

    Most tools have distinct purposes (e.g., sync vs. search vs. prioritize for vulnerabilities; register vs. check vs. create vs. assess for research). However, there is a small overlap between vuln_get_cve and vuln_search_cves (both retrieve CVE data) and between vuln_refresh_vrt and vuln_search_vrt (both operate on the VRT). The descriptions help differentiate them, but the boundaries are not perfectly sharp.

    Naming Consistency4/5

    Tool names follow a consistent verb_noun pattern with prefixes: 'vuln_' for vulnerability operations and 'research_' for research scope/case operations. Within each group, verbs like refresh, sync, get, search, query are clear. Minor deviation: 'research_export_report' is a noun-heavy name, but overall the pattern is strong.

    Tool Count4/5

    19 tools is on the higher end but still appropriate for a server covering two domains (vulnerability data and research management). Each tool addresses a specific operation in the vulnerability lifecycle (sync, search, prioritize) and research workflow (scope, case, evidence, patch). A slight reduction could be achieved by merging some closely related tools, but the count is not excessive.

    Completeness4/5

    The vulnerability domain covers syncing from multiple sources (NVD, KEV, EPSS, OSV), searching, prioritization, and status monitoring. The research side covers scope registration, case creation, SARIF import, evidence recording, finding assessment, report export, and patch verification. Minor gaps: there is no tool for updating/deleting a case or for submitting a report to Bugcrowd. These are reasonable omissions given the stated local audit focus.

    Maintenance

    ActivityMaintained
    ResponsivenessSyncing