nmap-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| NMAP_BINARY | No | Path to the Nmap binary | nmap |
| NMAP_MAX_TARGETS | No | Maximum number of target hosts per scan (max /24 subnet) | 256 |
| FASTMCP_LOG_LEVEL | No | Logging level (DEBUG, INFO, WARNING, ERROR) | WARNING |
| NMAP_SCAN_TIMEOUT | No | Maximum scan duration in seconds | 600 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| scan-portsA | Scan ports on a target host or network. Performs a port scan using nmap with the specified parameters. Validates all inputs to prevent command injection. IMPORTANT: Only scan targets you are authorized to scan. Returns: ScanResult with discovered hosts, ports, and their states. |
| discover-hostsA | Discover live hosts on a network without performing a port scan. Uses nmap ping scan (-sn) to identify which hosts are up on the target network. This is typically the first step in a network assessment. IMPORTANT: Only scan networks you are authorized to scan. Returns: HostDiscoveryResult with lists of hosts that are up and down. |
| detect-servicesA | Detect services and versions running on open ports. Uses nmap's service detection probes (-sV) to identify software names, versions, and CPE identifiers for services running on open ports. IMPORTANT: Only scan targets you are authorized to scan. Returns: ScanResult with service information for each open port. |
| detect-osA | Detect the operating system of a target host. Uses nmap TCP/IP stack fingerprinting (-O) to identify the target's operating system. NOTE: This typically requires elevated privileges (root/sudo). IMPORTANT: Only scan targets you are authorized to scan. Returns: ScanResult with OS detection matches for the target host. |
| scan-vulnerabilitiesA | Scan for known vulnerabilities using Nmap Scripting Engine (NSE). Runs NSE vulnerability detection scripts against the target. Uses safe script categories by default. Results include CVE identifiers when available. IMPORTANT: Only scan targets you are authorized to scan. Vulnerability scanning may trigger security alerts on the target network. Returns: VulnScanResult with discovered vulnerabilities and their details. |
| quick-scanA | Perform a fast scan of the most common ports. Scans the top N most frequently used ports with aggressive timing for quick results. Good for getting a fast security overview of a target. IMPORTANT: Only scan targets you are authorized to scan. Returns: ScanResult with discovered hosts and open ports. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 6 tools
Each tool has a clearly distinct purpose: host discovery, OS detection, service detection, quick port scan, comprehensive port scan, and vulnerability scanning. No overlap or ambiguity.
All tool names follow a consistent verb_noun pattern using lowercase and hyphens (e.g., detect-os, scan-ports). The only slight deviation is 'quick-scan' (adjective-verb), but it remains clear and predictable.
With 6 tools, the set is well-scoped for network scanning. It covers the essential nmap operations without being excessive or too sparse.
The tool surface covers the full lifecycle of network reconnaissance: host discovery, OS fingerprinting, service version detection, port scanning (both quick and thorough), and vulnerability scanning. No obvious gaps for typical use cases.