Skip to main content
Glama
README.md
# mcp-noctua

*🇬🇧 English · [🇫🇷 Français](README.fr.md)*

An MCP server (stdio) that exposes a **pentest toolbox** to a strong LLM
orchestrator (Claude Code, interactive), to run **authorized** security audits.

A clean rewrite inspired by the [Darkmoon](https://github.com/ASCIT31/Dark-Moon)
MCP (GPL v3) **with no code copied** → CeCILL-B license, zero GPL debt. What's
reused is the *toolbox* (sqlmap, nuclei, ffuf, httpx, naabu, katana, whatweb…);
the fragile orchestration (opencode + local model) is dropped and replaced by a
strong brain that **verifies**.

## Architecture

```
[Claude Code] --stdio--> [mcp-noctua (host)] --docker.sock--> [darkmoon container = toolbox]
   (the brain)             (controlled gateway)               (sqlmap, nuclei, ffuf…)
```

mcp-noctua **reuses** the `darkmoon` container (`ascit/darkmoon:latest`) as its
toolbox, invoking it via `docker.sock`. Invoking tools inside a container is not a
derivative work → no license concern. The container is kept alive; noctua starts
it if it's stopped before a run.

## Exposed MCP tools

| Tool | Role |
|------|------|
| `run_tool(command, timeout?)` | Run a **whitelisted** tool in the toolbox. |
| `web_crawl(url, depth?, timeout?)` | Bounded crawl (katana). |
| `port_scan(target, ...)` | naabu + httpx, bounded. |
| `vuln_scan(url, tags?)` | nuclei, bounded. |
| `list_tools()` | Tools available in the toolbox. |
| `health()` | Toolbox container state (running / started / not found). |

## Guard-rails

- Strict **allow-list** of tools; dangerous patterns blocked (`rm -rf`, fork bomb, exfil…).
- A timeout that **actually kills** the process inside the toolbox (fixes the Darkmoon flaw).
- **Authorized testing only**; the operator validates every target.

## Configuration (`.env`)

See `.env.example`. Keys: `DOCKER_CONTAINER_NAME`, `NOCTUA_TIMEOUT`,
`NOCTUA_REPORTS_DIR`, `NOCTUA_COMPOSE_DIR`, `DEBUG`.

## Install

```bash
git clone https://github.com/NeveuGregor/mcp-noctua.git
cd mcp-noctua
python3 -m venv venv && source venv/bin/activate
pip install -e ".[dev]"
cp .env.example .env   # adjust as needed
pytest
```

Register in `~/.claude.json` as a stdio MCP server:
`venv/bin/python -m src.main` (cwd = `mcp-noctua`).

## License

CeCILL-B — see [LICENSE](LICENSE).

TDQS

A3.8/5.0

Scored across 6 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: health checks container state, list_tools enumerates whitelisted tools, port_scan performs port scanning, run_tool executes a generic recon tool, vuln_scan does vulnerability scanning, and web_crawl does web crawling. No overlap or ambiguity.

Naming Consistency4/5

All names use snake_case and are descriptive, but there's a mix of verb-first (list_tools, run_tool) and noun-first (port_scan, vuln_scan, web_crawl) patterns, plus health stands alone. Still consistent in style and readable.

Tool Count5/5

6 tools is well-scoped for a reconnaissance/scanning toolbox, covering essential functions without being overly numerous or sparse.

Completeness4/5

The set covers core recon tasks: tool listing, port scanning, vulnerability scanning, web crawling, and a generic run_tool for extensibility. Minor gaps like explicit service detection or DNS enumeration are likely addressable via run_tool.

Maintenance

ActivityStale
ResponsivenessNo issues