Skip to main content
Glama

phantom-mcp

MCP Server for PHANTOM — exposes all PHANTOM capabilities as MCP tools for Claude Desktop, Cursor, and any MCP client.


Tools available

Tool

Description

phantom_scan

Quick recon + vuln scan

phantom_quick_recon

Passive subdomain discovery only

phantom_red

Full red team pipeline (authorised use only)

phantom_orchestrate

Natural language → autonomous execution

phantom_grey

Bug bounty / OSCP-style (no blind exploits)

phantom_blue_analyze_log

Analyse a log file for IOCs and attacks

phantom_hardening_checklist

AI-powered hardening checklist

phantom_ir_playbook

Incident response playbook from findings

phantom_siem_queries

Splunk SPL / Elastic KQL from findings

phantom_identity_gen

Generate a fake persona + disposable email

phantom_inbox

Check disposable email inbox

phantom_wait_email_otp

Wait for OTP in email

phantom_sms_otp

Poll for SMS OTP

phantom_report

Generate HackerOne / Bugcrowd / generic report

phantom_sessions_list

List all sessions

phantom_findings

Get session findings (with severity filter)

phantom_session_summary

Full session summary

phantom_chat

General-purpose AI chat (any topic)

phantom_analyze_findings

Ask AI to analyze your findings


Related MCP server: kali-tools-mcp

Install

# 1. Install PHANTOM first
git clone https://github.com/grsanudeep42-cmd/phantom
cd phantom && pip install -e .

# 2. Install phantom-mcp (bundled in phantom/phantom-mcp)
pip install mcp  # only extra dependency

Connect to Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or
%APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "phantom": {
      "command": "python",
      "args": ["-m", "phantom_mcp.server.main"],
      "cwd": "/absolute/path/to/phantom",
      "env": {
        "PYTHONPATH": "/absolute/path/to/phantom",
        "ANTHROPIC_API_KEY": "sk-ant-..."
      }
    }
  }
}

Then restart Claude Desktop. You'll see all PHANTOM tools available.


LLM Provider

Every tool accepts optional provider and model arguments:

phantom_chat(message="explain XSS", provider="ollama", model="llama3.1")
phantom_scan(target="example.com", provider="openai", model="gpt-4o")

Supported: anthropic, openai, ollama, openrouter, custom


Example usage in Claude Desktop

Use phantom_scan to scan example.com

Use phantom_grey to test example.com for bug bounty vulnerabilities

Use phantom_sessions_list to show my recent scans

Use phantom_findings with session_id="abc123" and severity="critical"

Use phantom_report with session_id="abc123" and format="hackerone"

Use phantom_chat to explain the CVE-2024-1234 vulnerability

License

MIT © Anudeep | Part of the PHANTOM project

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    C
    maintenance
    Exposes AI-augmented network reconnaissance and evasion capabilities as callable FastMCP tools, enabling natural language orchestration of host discovery, service fingerprinting, CVE mapping, and attack chain synthesis.
    1
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    Exposes a hardened Docker container with Kali Linux security tools (nmap, sqlmap, dig, whois, etc.) as MCP tools, enabling network reconnaissance, web analysis, and vulnerability scanning through natural language commands.
    -
  • A
    license
    A
    quality
    B
    maintenance
    Exposes the Maester security test framework for Microsoft 365/Entra/Defender as MCP tools, enabling AI agents to run tests, audit AI agents and MCP servers, and investigate security posture.
    9
    MIT