nuclei-server MCP Server
핵 서버 MCP 서버
모델 컨텍스트 프로토콜 서버
간단한 메모 시스템을 구현하는 TypeScript 기반 MCP 서버입니다. 다음을 제공하여 핵심 MCP 개념을 보여줍니다.
URI 및 메타데이터를 사용하여 텍스트 노트를 나타내는 리소스
새로운 노트를 만드는 도구
노트 요약 생성을 위한 프롬프트
특징
자원
note://URI를 통해 메모를 나열하고 액세스합니다.각 노트에는 제목, 내용 및 메타데이터가 있습니다.
간단한 콘텐츠 액세스를 위한 일반 텍스트 MIME 유형
도구
create_note- 새로운 텍스트 노트 만들기제목과 내용을 필수 매개변수로 사용합니다.
서버 상태에 메모 저장
프롬프트
summarize_notes- 저장된 모든 노트의 요약을 생성합니다.모든 노트 내용을 내장 리소스로 포함합니다.
LLM 요약을 위한 구조화된 프롬프트를 반환합니다.
Related MCP server: azure-devops MCP Server
개발
종속성 설치:
지엑스피1
서버를 빌드하세요:
npm run build자동 재빌드를 사용한 개발의 경우:
npm run watch설치
Claude Desktop과 함께 사용하려면 서버 구성을 추가하세요.
MacOS의 경우: ~/Library/Application Support/Claude/claude_desktop_config.json Windows의 경우: %APPDATA%/Claude/claude_desktop_config.json
{
"mcpServers": {
"nuclei-server": {
"command": "/path/to/nuclei-server/build/index.js"
}
}
}디버깅
MCP 서버는 stdio를 통해 통신하므로 디버깅이 어려울 수 있습니다. 패키지 스크립트로 제공되는 MCP Inspector를 사용하는 것이 좋습니다.
npm run inspector검사기는 브라우저에서 디버깅 도구에 액세스할 수 있는 URL을 제공합니다.
Available Tools
2 toolscancel_scanC
Cancel a running scan
| Name | Required | Description | Default |
|---|---|---|---|
| scanId | Yes | Scan ID to cancel |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden for behavioral disclosure. 'Cancel' implies a mutation operation that stops an ongoing process, but the description doesn't address important behavioral aspects: whether cancellation is reversible, what permissions are required, what happens to partial scan results, or how to verify the scan was running. For a mutation tool with zero annotation coverage, this is inadequate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is maximally concise - a single four-word sentence that directly states the tool's purpose with zero wasted words. It's appropriately sized for a simple tool with one parameter and clear basic functionality.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a mutation tool with no annotations and no output schema, the description is insufficiently complete. It doesn't address the tool's behavioral implications, error conditions, or relationship to the sibling 'start_scan' tool. The agent would need to guess about important aspects like what constitutes a 'running' scan, cancellation effects, and verification of success.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has 100% description coverage, with the single parameter 'scanId' clearly documented in the schema. The description doesn't add any parameter semantics beyond what's already in the schema, but since the schema does the heavy lifting, the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('cancel') and target ('a running scan'), providing specific verb+resource. However, it doesn't differentiate from the sibling tool 'start_scan' beyond the obvious verb difference, missing an opportunity to clarify the relationship between these complementary operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, prerequisites, or constraints. While the presence of 'start_scan' as a sibling suggests a workflow relationship, the description doesn't explicitly state this or provide any usage context beyond the basic action.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
start_scanC
Start a new nuclei scan
| Name | Required | Description | Default |
|---|---|---|---|
| target | Yes | Target URL or IP address | |
| template | No | Template to use for scanning | |
| rateLimit | No | Rate limit per second | |
| templatesDir | No | Directory with templates | |
| severity | No | ||
| timeout | No | Timeout in seconds | |
| concurrency | No | Concurrent requests | |
| proxyUrl | No | Proxy URL (e.g., socks5://127.0.0.1:1080) | |
| proxyType | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states the tool starts a scan but fails to describe what happens during execution (e.g., whether it runs asynchronously, potential impacts on targets, or expected outputs). This leaves critical behavioral traits undocumented for a tool with security implications.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is extremely concise with a single, front-loaded sentence ('Start a new nuclei scan') that directly conveys the core purpose without any wasted words. This efficiency makes it easy to parse, though it may lack depth.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (9 parameters, no annotations, no output schema, and security-related functionality), the description is insufficient. It doesn't cover behavioral aspects, output expectations, or usage context, leaving significant gaps for an AI agent to understand how to invoke it correctly and interpret results.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description coverage is 78%, which is relatively high, setting a baseline of 3. The description adds no additional parameter information beyond what the schema provides, such as explaining the relationship between parameters or typical values. It doesn't compensate for the 22% gap in coverage, but the schema handles most documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Start a new nuclei scan') with a specific verb ('Start') and resource ('nuclei scan'), making the purpose immediately understandable. However, it doesn't distinguish this from its sibling tool 'cancel_scan' or explain what a 'nuclei scan' entails, which prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives, nor does it mention prerequisites or context for initiating a scan. While it implies usage for starting scans, there's no explicit advice on timing, constraints, or how it relates to 'cancel_scan'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
- First observed
cancel_scan - First observed
start_scan
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: one starts a scan and the other cancels it. There is no overlap or ambiguity between these operations, making it easy for an agent to select the correct tool for the intended action.
Both tools follow a consistent verb_noun pattern (start_scan, cancel_scan), using snake_case throughout. This predictable naming scheme enhances readability and reduces confusion for agents.
With only 2 tools, the server feels too thin for a scanning domain, as it lacks essential operations like retrieving scan results, listing scans, or configuring scans. This minimal set may force agents into dead ends or require workarounds.
The tool surface is severely incomplete for a nuclei scanning server. While start and cancel are basic actions, there are significant gaps: no way to get scan status, view results, list scans, or manage templates. This will likely cause agent failures in typical scanning workflows.
Maintenance
Related MCP Connectors
Google Keep-style notes app with an MCP server for AI agents to read/write notes.
An MCP server that used to create notes
A simple Typescript MCP server built using the official MCP Typescript SDK and smithery/cli. This…
A TypeScript MCP server for Home Assistant, enabling programmatic management of entities, automati…
Related MCP Servers
- FlicenseBqualityDmaintenanceA simple TypeScript-based MCP server that implements a notes system, allowing users to create, list, and generate summaries of text notes via Claude.13-
- AlicenseBqualityDmaintenanceA TypeScript-based MCP server that implements a simple notes system, allowing users to create, access, and generate summaries of text notes.12497 npm3MIT
- AlicenseAqualityDmaintenanceA TypeScript-based MCP server that implements a simple notes system, allowing creation and management of text notes with URIs and metadata.47 npmMIT
- AlicenseAqualityFmaintenanceA TypeScript-based MCP server that implements a simple notes system, allowing users to create, access, and generate summaries of text notes via URIs and tools.125 npm8MIT