blackarch-AI MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_scopeA | Check whether |
| nmap_scanC | Run an nmap scan against |
| gobuster_dirC | Directory-brute-force |
| nikto_scanB | Run a nikto web vulnerability scan against |
| hydra_bruteforceA | Credential brute-force |
| audit_listening_portsA | List listening ports (ss -tulnp) cross-referenced with firewall rules on this local host. |
| audit_suid_world_writableA | Find SUID and world-writable files under |
| review_auth_logC | Summarize sshd auth log entries on this local host since |
| lint_ssh_configA | Check sshd_config at |
| list_installed_toolsA | Inventory installed BlackArch security-tool packages, grouped by category (recon, exploitation, cracking, etc.). |
| audit_pacman_packagesA | Report orphan packages, available updates, and package integrity via pacman (read-only) on this local host. |
| crack_hash_offlineB | Run an offline password-strength audit with hashcat/john against a hash file placed in data/hashes/. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 12 tools
Most tools have clearly distinct purposes: scanning (nmap, nikto, gobuster), credential attacks (hydra), local auditing (audit_*, lint_*, review_*), and offline cracking (crack_hash_offline). However, check_scope is a utility tool that could be considered overlapping with the scope checks built into other tools, but it serves as a proactive check rather than a reactive refusal.
The naming pattern mixes styles: verbs like 'check_', 'nmap_scan', 'gobuster_dir', and 'hydra_bruteforce' use a tool_name format, while others like 'audit_listening_ports' and 'review_auth_log' use verb_noun. The category for local auditing tools is consistent, but the overall set lacks a single unified pattern.
12 tools is a reasonable count for a security auditing server covering reconnaissance, brute-forcing, local system auditing, and offline cracking. It's slightly high but each tool has a specific role, and no tool feels redundant. The scope is well-defined for a BlackArch-oriented toolset.
The toolset covers external scanning, web vulnerability scanning, brute-forcing, local host auditing, and password cracking. However, there are gaps: no network sniffing, exploitation, or privilege escalation tools, and no reporting or logging of results. For a comprehensive security assessment suite, these missing capabilities could hinder an agent's workflow.