Skip to main content
Glama
X3r0K

Shodan-MCP-Server

by X3r0K

Shodan MCP Server

A Model Context Protocol (MCP) server that provides access to Shodan's internet scanning capabilities through a standardized interface.

Overview

This server implements the Model Context Protocol to expose Shodan's powerful internet scanning and reconnaissance capabilities. It provides a standardized interface for querying Shodan's database of internet-connected devices, services, and vulnerabilities.

Related MCP server: ADEO CTI MCP Server

Features

  • Search Capabilities: Query Shodan's database using advanced search filters

  • DNS Lookup: Resolve domain names and get detailed DNS information

  • CVE Information: Get detailed information about Common Vulnerabilities and Exposures

  • Get Vulnerabilities: Get detailed infor Vulnerabilities related to an IP address

  • Standardized Interface: Uses MCP protocol for consistent communication

  • Environment Variable Support: Secure API key management through environment variables

Prerequisites

  • Node.js (v14 or higher)

  • npm (v6 or higher)

  • Shodan API key

Installation

  1. Clone the repository:

    git clone https://github.com/X3r0K/Shodan-MCP-Server-Inspector.git
    cd shodan-mcp-server-Inspector
  2. Install dependencies:

    npm install
  3. Create a .env.local file in the root directory and add your Shodan API key:

    SHODAN_API_KEY=your_api_key_here

Usage

Starting the Server

  1. Build the server:

    npm run build
  2. Start the server:

    node build/index.js

Available Tools

  1. Search Tool

    • Query: Search for devices and services using Shodan's search syntax

    • Example: log4j country:US city:Atlanta

    • Returns: List of matching devices with detailed information

  2. DNS Lookup Tool

    • Query: Domain name to resolve

    • Example: example.com

    • Returns: DNS records and related information

  3. CVE Info Tool

    • Query: CVE identifier

    • Example: CVE-2021-44228

    • Returns: Detailed vulnerability information

Example Queries

// Search for Log4j vulnerable systems in the US
{
  "query": "log4j country:US"
}

// DNS lookup for a domain
{
  "query": "example.com"
}

// Get CVE information
{
  "query": "CVE-2021-44228"
}

Using the MCP Inspector

image

You can use the MCP inspector to interact with the server directly:

  1. Install the MCP inspector:

npm install -g @modelcontextprotocol/inspector
  1. Run the inspector with your server:

npx @modelcontextprotocol/inspector build/index.js

The inspector provides an interactive interface to:

  • Test all available tools

  • View tool documentation

  • Debug server responses

  • Monitor server status

Environment Variables

  • SHODAN_API_KEY: Your Shodan API key (required)

  • PORT: Server port (optional, defaults to 3000)

  • LOG_LEVEL: Logging level (optional, defaults to 'info')

Error Handling

The server implements comprehensive error handling for:

  • Invalid API keys

  • Rate limiting

  • Network issues

  • Invalid queries

  • Server errors

Security Considerations

  1. API Key Protection:

    • Never commit API keys to version control

    • Use environment variables for sensitive data

    • Rotate API keys regularly

  2. Rate Limiting:

    • Respect Shodan's API rate limits

    • Implement client-side rate limiting

  3. Data Privacy:

    • Filter sensitive information from responses

    • Implement access controls as needed

License

This project is licensed under the MIT License - see the LICENSE file for details.

Acknowledgments

  • Shodan for providing the API

  • Model Context Protocol team for the MCP specification

F
license - not found
-
quality - not tested
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    F
    maintenance
    MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.
    7
    304
    149
    MIT
  • F
    license
    -
    quality
    D
    maintenance
    A Model Context Protocol server that provides access to Shodan and VirusTotal APIs for cybersecurity analysis, enabling analysts to perform network intelligence operations including host lookups, vulnerability analysis, and threat intelligence gathering.
    22
  • F
    license
    -
    quality
    D
    maintenance
    A WebSocket server that provides MCP interface for searching and retrieving information about internet-connected devices, IP addresses, DNS data, and CVE vulnerabilities through the Shodan API.
    3
  • F
    license
    -
    quality
    D
    maintenance
    Integrates Shodan search capabilities into MCP-compatible applications for discovering internet-connected devices. Enables domain searches, IP lookups, and advanced queries to identify exposed services, infrastructure mapping, and security analysis.
    3

View all related MCP servers

Related MCP Connectors

  • Shodan InternetDB MCP — wraps Shodan InternetDB (internetdb.shodan.io)

  • Shodan MCP — wraps the full Shodan REST API (api.shodan.io)

  • MCP (Model Context Protocol) server for Appwrite

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/X3r0K/Shodan-MCP-Server-Inspector'

If you have feedback or need assistance with the MCP directory API, please join our Discord server