Skip to main content
Glama
avi686

Security Testing MCP Server

by avi686

Security Testing MCP Server

A Model Context Protocol (MCP) server that provides penetration testing tools for educational purposes using Kali Linux security tools.

Purpose

This MCP server provides a comprehensive interface for AI assistants to perform security testing using popular Kali Linux tools for educational and authorized testing purposes.

Related MCP server: ikaliMCP Server

Features

Current Implementation

  • nmap_scan - Network port scanning and service detection with multiple scan types

  • nikto_scan - Web vulnerability scanning with plugin support

  • sqlmap_test - SQL injection testing with advanced options

  • wpscan_test - WordPress vulnerability scanning with API token support

  • dirb_scan - Directory and file brute forcing with custom wordlists

  • searchsploit_lookup - Exploit database searching with filters

  • ping_sweep - Network discovery and connectivity testing

  • custom_scan - Execute custom commands with whitelisted tools

Quick Start

  1. Clone and Build:

    git clone https://github.com/avi686/security-mcp-server.git
    cd security-mcp-server
    docker build -t security-mcp-server .
  2. Set up MCP Configuration:

    mkdir -p ~/.docker/mcp/catalogs
  3. Create custom catalog (~/.docker/mcp/catalogs/custom.yaml):

    version: 2
    name: custom
    displayName: Custom MCP Servers
    registry:
      security:
        description: "Comprehensive penetration testing tools for educational and authorized use"
        title: "Security Testing Tools"
        type: server
        dateAdded: "2025-09-24T00:00:00Z"
        image: security-mcp-server:latest
        ref: ""
        tools:
          - name: nmap_scan
          - name: nikto_scan
          - name: sqlmap_test
          - name: wpscan_test
          - name: dirb_scan
          - name: searchsploit_lookup
          - name: ping_sweep
          - name: custom_scan
        metadata:
          category: security
          tags:
            - penetration-testing
            - security
            - kali-linux
            - educational
          license: MIT
          owner: local
  4. Update registry (~/.docker/mcp/registry.yaml):

    registry:
      security:
        ref: ""
  5. Configure Claude Desktop (add to your config):

    {
      "mcpServers": {
        "mcp-toolkit-gateway": {
          "command": "docker",
          "args": [
            "run", "-i", "--rm", "--network=host",
            "-v", "/var/run/docker.sock:/var/run/docker.sock",
            "-v", "/path/to/your/home/.docker/mcp:/mcp",
            "docker/mcp-gateway",
            "--catalog=/mcp/catalogs/docker-mcp.yaml",
            "--catalog=/mcp/catalogs/custom.yaml",
            "--config=/mcp/config.yaml",
            "--registry=/mcp/registry.yaml",
            "--tools-config=/mcp/tools.yaml",
            "--transport=stdio"
          ]
        }
      }
    }
  6. Restart Claude Desktop

Usage Examples

In Claude Desktop, you can ask:

Environment Variables

  • SCAN_TIMEOUT: Maximum scan time in seconds (default: 300)

  • DEFAULT_INTENSITY: Nmap timing template T1-T5 (default: T3)

  • DIRB_WORDLIST: Path to directory wordlist (default: common.txt)

  • MAX_THREADS: Maximum thread count for tools (default: 10)

IMPORTANT: This tool is for educational purposes and authorized testing only. Users are responsible for:

  • Obtaining proper authorization before scanning any systems

  • Complying with local laws and regulations

  • Using tools ethically and responsibly

  • Not using for malicious purposes

The developers assume no responsibility for misuse of these tools.

License

MIT License

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides secure access to Kali Linux security tools through a dockerized environment for authorized penetration testing and defensive security. Enables network scanning, web application testing, system enumeration, and credential testing with built-in input sanitization and network restrictions.
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    Provides a secure interface for AI assistants to interact with penetration testing tools like nmap, hydra, sqlmap, and nikto for educational cybersecurity purposes. Includes input sanitization and runs in a Docker container with Kali Linux tools for authorized testing scenarios.
    -
  • -
    license
    Not graded
    quality
    D
    maintenance
    Provides secure access to Kali Linux penetration testing tools including nmap, nikto, dirb, wpscan, and sqlmap for educational vulnerability assessment on whitelisted targets. Runs in a controlled Docker environment and includes reconnaissance capabilities for authorized security testing.
    1
    -
  • -
    license
    Not graded
    quality
    D
    maintenance
    Provides secure access to penetration testing tools from Kali Linux including nmap, nikto, dirb, wpscan, and sqlmap for educational vulnerability assessment. Operates in a controlled Docker environment with target whitelisting to ensure ethical testing practices.
    1
    -