Skip to main content
Glama
README.md
# ๐Ÿ›ก๏ธ PenTest MCP

**AI-Powered Security Scanning via Model Context Protocol (MCP)**

PenTest MCP is a specialized MCP server that exposes 25+ professional security tools to AI agents like Claude Desktop. It enables security researchers and developers to orchestrate penetration testing through natural language, automating complex tool chains and generating professional reports.

[![Python 3.11+](https://img.shields.io/badge/python-3.11+-blue?logo=python&logoColor=white)](https://www.python.org/)
[![MCP](https://img.shields.io/badge/MCP-1.0+-purple)](https://modelcontextprotocol.io/)
[![License: MIT](https://img.shields.io/badge/license-MIT-lightgrey)](LICENSE)

---

## ๐Ÿš€ Quick Start (Claude Desktop)

1. **Install dependencies:**
   ```bash
   pip install -e .
   ```

2. **Configure Claude Desktop:**
   Add the following to your `claude_desktop_config.json`:
   ```json
   {
     "mcpServers": {
       "pentest": {
         "command": "python3",
         "args": [
           "-m",
           "pentest_mcp.mcp_server"
         ],
         "cwd": "/absolute/path/to/pentest-mcp"
       }
     }
   }
   ```

3. **Restart Claude Desktop** and start scanning:
   - "Initialize a security assessment for http://localhost:3001"
   - "Run a quick scan on http://localhost:3001 with consent"
   - "Check if the site has a WAF"
   - "Generate the final security report"

---

- **Claude Desktop Integration** - Full orchestration via the Model Context Protocol.
- **25+ Security Tools** - Including `nmap`, `sqlmap`, `nuclei`, `ffuf`, `nikto`, `testssl`, and more.
- **Natural Language Orchestration** - Ask security questions, Claude picks the right tools.
- **Preset Scan Modes** - Quick Triage and Extensive Assessment modes.
- **AI-Generated Reports** - Professional markdown reports powered by Gemini AI.
- **CVE Enrichment** - Findings are automatically cross-referenced with CVE data.

---

## ๐Ÿ› ๏ธ Supported Tools (25)

| Category | Tools |
|----------|-------|
| **Reconnaissance** | `subfinder`, `wafw00f`, `nmap`, `whatweb`, `amass`, `dnsrecon`, `theharvester` |
| **Vulnerability Scanning** | `nuclei`, `sqlmap`, `dalfox`, `nikto`, `retire`, `commix`, `corscanner`, `graphql_cop` |
| **Web Fuzzing** | `ffuf`, `gobuster`, `wfuzz`, `arjun` |
| **TLS/SSL** | `sslyze`, `testssl` |
| **Advanced/OSINT** | `masscan`, `trufflehog`, `git_dumper`, `jwt_tool` |

---

## ๐Ÿ”ง Installation & Setup

### Prerequisites
- Python 3.11+
- [Gemini API Key](https://aistudio.google.com/apikey) (for reports and analysis)
- (Recommended) External tools installed: `nmap`, `sqlmap`, `ffuf`, `nuclei`, etc.

### Configuration
Create a `.env` file in the project root:
```bash
GEMINI_API_KEY=your_api_key_here
GEMINI_MODEL=gemini-flash-lite-latest
```

---

## ๐Ÿ“ Project Structure

```
pentest-mcp/
โ”œโ”€โ”€ pentest_mcp/
โ”‚   โ”œโ”€โ”€ mcp_server.py      # Main MCP server entry point
โ”‚   โ”œโ”€โ”€ scan_modes.py      # Quick & Extensive scan logic
โ”‚   โ”œโ”€โ”€ session.py         # Session & DB management
โ”‚   โ”œโ”€โ”€ report_engine.py   # AI report generation
โ”‚   โ”œโ”€โ”€ llm_providers.py   # Gemini API integration
โ”‚   โ”œโ”€โ”€ tools/             # Tool wrappers & logic
โ”‚   โ””โ”€โ”€ models.py          # Pydantic data models
โ”œโ”€โ”€ vulnerable-app/        # Local test target (Node.js)
โ”œโ”€โ”€ reports/               # Generated scan reports
โ””โ”€โ”€ pyproject.toml         # Project dependencies
```

---

## ๐Ÿ”’ Security Notice

**This tool is for authorized security testing only.**
- Always obtain explicit written permission before scanning any target.
- Unauthorized testing is illegal and unethical.
- The `consent` flag is a mandatory requirement for all active scanning tools.

---

**Built with** ๐Ÿ Python ยท ๐Ÿง  Gemini AI ยท ๐Ÿ›ก๏ธ MCP

TDQS

C2.5/5.0

Scored across 29 tools

Disambiguation4/5

Most tools have distinct purposes (e.g., sqlmap vs nmap), but some overlap exists between masscan and nmap for port scanning, and multiple fuzzing tools like ffuf, wfuzz, and gobuster may cause confusion for an agent. Descriptions help differentiate but are not entirely unambiguous.

Naming Consistency4/5

Tool names are consistently lowercase with underscores for multi-word names, but they do not follow a strict verb_noun pattern. Some are single words (e.g., amass, nikto) while others are compound (e.g., git_dumper, jwt_tool), which is consistent but not highly patterned.

Tool Count4/5

With 29 tools, the server covers a broad range of penetration testing tasks, which is appropriate for a comprehensive tool set. While on the higher end, the count is justified by the diversity of functionality and does not feel excessive.

Completeness4/5

The tool set covers most key areas of penetration testing: reconnaissance, scanning, web fuzzing, vulnerability detection, and reporting. However, it lacks network vulnerability scanners (e.g., OpenVAS) and exploitation tools, leaving minor gaps. The inclusion of quick_scan and extensive_scan helps cover comprehensive workflows.

Maintenance

ActivityStale
ResponsivenessNo issues