blackarch-AI MCP Server
Related Servers
Alternatives to blackarch-AI MCP Server
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityCmaintenanceEnables automated bug bounty hunting and security research with tools for reconnaissance, web vulnerability scanning, API testing, binary analysis, and mobile app analysis through an MCP interface.MIT
- AlicenseNot gradedqualityCmaintenanceEnables LLM-driven security assessments by exposing Kali tools like nmap, httpx, sqlmap, and ffuf as MCP tools, with explicit planning, parallel tool calls, tiered memory, MITRE ATT&CK mapping, and human approval gates for intrusive operations.2MIT
- AlicenseAqualityBmaintenanceA scope-aware bug-bounty & reconnaissance MCP server that works out of the box on the Python standard library and augments itself with your favourite CLI tools when they're present.22MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to orchestrate 100+ security tools over MCP for authorized penetration testing, including recon, scanning, exploitation, attack-chain planning, and knowledge-base retrieval.5Apache 2.0
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to run bounded security reconnaissance tools against a local OWASP Juice Shop target via MCP, including HTTP checks, header inspection, Nmap scanning, and web enumeration, without granting arbitrary shell access.-
- AlicenseNot gradedqualityBmaintenanceA safety-constrained MCP server that exposes selected Kali Linux and Nmap capabilities within an authorized lab network, enforcing strict scope limitations and audit logging.MIT
TDQS
Scored across 12 tools
Most tools have clearly distinct purposes: scanning (nmap, nikto, gobuster), credential attacks (hydra), local auditing (audit_*, lint_*, review_*), and offline cracking (crack_hash_offline). However, check_scope is a utility tool that could be considered overlapping with the scope checks built into other tools, but it serves as a proactive check rather than a reactive refusal.
The naming pattern mixes styles: verbs like 'check_', 'nmap_scan', 'gobuster_dir', and 'hydra_bruteforce' use a tool_name format, while others like 'audit_listening_ports' and 'review_auth_log' use verb_noun. The category for local auditing tools is consistent, but the overall set lacks a single unified pattern.
12 tools is a reasonable count for a security auditing server covering reconnaissance, brute-forcing, local system auditing, and offline cracking. It's slightly high but each tool has a specific role, and no tool feels redundant. The scope is well-defined for a BlackArch-oriented toolset.
The toolset covers external scanning, web vulnerability scanning, brute-forcing, local host auditing, and password cracking. However, there are gaps: no network sniffing, exploitation, or privilege escalation tools, and no reporting or logging of results. For a comprehensive security assessment suite, these missing capabilities could hinder an agent's workflow.