MCPFP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCPFP_AUTHORIZED | Yes | Set to true to confirm you have permission (mandatory). | |
| MCPFP_PORT_RANGE | No | Optional port range to scan. | |
| MCPFP_REPORT_DIR | No | Optional directory where Markdown reports are written. | |
| MCPFP_TARGET_HOST | Yes | IP/host of the lab VM. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| load_target_infoA | Carga y valida el objetivo unico desde .env, confirmando autorizacion. |
| check_environmentA | Verifica que herramientas externas de reconocimiento estan instaladas. |
| scan_networkA | Descubre puertos y servicios del objetivo (nmap no intrusivo). |
| analyze_http_headersC | Evalua las cabeceras de seguridad HTTP del objetivo. |
| analyze_tlsB | Inspecciona el certificado y protocolo TLS del objetivo. |
| assess_owaspB | Fingerprinting web y mapeo pasivo a OWASP Top 10. |
| get_guidanceB | Guia pedagogica paso a paso (obvios / no obvios / siguiente paso). Temas: reconocimiento, a01, a02, a05, a06, bandera. |
| write_reportB | Guarda hallazgos en un reporte Markdown en el directorio de invocacion. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| metodologia | Metodologia de abordaje siguiendo OWASP e ISO 27001 (sin explotacion). |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 8 tools
Each tool targets a distinct stage or concern: target setup, environment checks, network scanning, HTTP header analysis, TLS inspection, OWASP mapping, guidance, and reporting. Even the two analyze tools are clearly separated by layer, so no agent should confuse one tool for another.
All tool names follow a consistent snake_case verb_noun pattern: load_, check_, scan_, analyze_, assess_, get_, and write_. The verb clearly signals the action and the noun signals the target, making the naming predictable and easy to extend.
Eight tools is a well-scoped set for a reconnaissance and OWASP assessment workflow. Each tool has a clear responsibility and no tool feels redundant or extraneous.
The workflow is complete for the stated passive-assessment and pedagogical purpose: it covers target validation, environment readiness, network discovery, HTTP/TLS inspection, OWASP mapping, guidance, and report generation. There are no obvious dead ends or missing core operations.