PenTest MCP
Related Servers
Alternatives to PenTest MCP
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to perform safe, authorized penetration testing by managing engagements, enforcing scope and risk policies, and orchestrating tools like Nmap, Nuclei, and Subfinder.-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to plan and run authorized offensive security assessments across 150+ integrated tools, with full activity logging of every scan.MIT
- FlicenseNot gradedqualityDmaintenanceAI-powered cybersecurity automation platform with 150+ security tools and 12+ autonomous AI agents for penetration testing, vulnerability assessment, and bug bounty hunting. Enables comprehensive security testing through intelligent tool selection and automated workflows.2-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to orchestrate 100+ security tools over MCP for authorized penetration testing, including recon, scanning, exploitation, attack-chain planning, and knowledge-base retrieval.5Apache 2.0
- AlicenseNot gradedqualityDmaintenanceEnables comprehensive security testing and penetration testing through natural language conversations with 92+ tools for reconnaissance, vulnerability assessment, web application testing, OSINT, and reporting. Designed for authorized bug bounty hunting and security assessments.44MIT
- AlicenseNot gradedqualityCmaintenanceEnables MCP-compatible AI agents to run autonomous penetration testing and cybersecurity assessments with 150+ security tools, intelligent decision-making, and real-time reporting.MIT
TDQS
Scored across 31 tools
Many tools have overlapping purposes: nmap/masscan both scan ports, sslyze/testssl both audit TLS, ffuf/gobuster/wfuzz all fuzz for directories, and subfinder/amass/dnsrecon all do subdomain/DNS enumeration. The descriptions are lean and don't clarify when to choose one over the other.
The tool names are a mix of raw external tool names (nmap, sqlmap, gobuster) and server-specific snake_case verbs (init_session, get_report, quick_scan). This makes the naming pattern unpredictable and inconsistent across the API surface.
31 tools is too many for a focused MCP server, especially when several are near-duplicates (subfinder/amass/dnsrecon, ffuf/gobuster/wfuzz, sslyze/testssl). A consolidated surface with fewer, higher-level scan operations would be easier for an agent to use.
The server covers reconnaissance, scanning, web fuzzing, TLS testing, secret detection, and report generation, which is solid for web-focused pentesting. However, session lifecycle support is thin (init_session/get_report only) and there are no explicit post-exploitation or broader infrastructure testing tools, leaving noticeable gaps for a general 'PenTest' role.