rqwstr
rqwstr
AI-native HTTP security testing toolkit, shipped as an MCP server. It gives an AI agent low-level control over HTTP/1.1 and HTTP/2 — raw framing, connection pinning, intruder-style fuzzing, request racing, OOB detection, and multi-step chains — on its own Go engine, rather than wrapping a high-level HTTP client.
This repository hosts the release binaries and Claude Desktop .mcpb bundles. The source is proprietary. Docs and sign-up: rqwstr.com.
Install
Claude Desktop (one-click)
Download the .mcpb for your platform from the latest release and double-click it to add rqwstr as a Claude Desktop extension.
macOS — Apple silicon (
darwin_arm64) or Intel (darwin_amd64)Linux —
linux_amd64orlinux_arm64Windows —
windows_amd64
Standalone MCP server
Download the binary for your platform from the latest release, then point your MCP client at it:
{
"mcpServers": {
"rqwstr": {
"command": "rqwstr",
"args": ["serve"]
}
}
}rqwstr serve runs the MCP server on stdio.
Related MCP server: pentestMCP
What's in the box
17 HTTP tools driven by an AI agent over MCP:
Traffic —
send(HTTP/1.1),send_h2(HTTP/2),fetch,import(Burp / HAR),export(curl / python / requests)Hunt lifecycle —
hunt,scope,save,search,session,profileAttacks —
intruder(sniper, battering ram, pitchfork, cluster bomb),race(single-packet),chain,parallelOOB —
oobwith Interactsh integrationEncoding —
encode(URL, base64, JWT, and more)
Agents discover workflows through the rqwstr_docs tool. Per-hunt state lives in SQLite. The free tier is the core toolset; a Pro tier unlocks the heavier offensive tools.
Verify a download
Each release includes checksums.txt. Verify before running:
sha256sum -c checksums.txtLicense
Proprietary. © Kjøpstad IT. See rqwstr.com for terms.
Maintenance
Related MCP Servers
- Flicense-qualityFmaintenanceA configurable MCP server that adapts any HTTP API into an MCP toolset with generic HTTP tools (GET, POST, PUT, DELETE) and pluggable authentication. Includes API discovery scripts and supports dynamic tool generation from OpenAPI specs or wordlist scans.Last updated
- Flicense-qualityBmaintenanceAn MCP server that exposes over 20 standard penetration testing utilities, such as Nmap, SQLMap, and OWASP ZAP, as callable tools for AI agents. It enables natural language control over complex security workflows for automated and interactive penetration testing.Last updated89
- Alicense-qualityDmaintenanceAI-Powered Red Team MCP Server enabling autonomous penetration testing via Model Context Protocol with 44+ security tools for AI agents.Last updated12MIT
- Flicense-qualityDmaintenanceMCP server that provides AI clients with 26 security and developer tools, enabling tasks like JWT decoding, HTTP header analysis, and phishing URL inspection.Last updated
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Kjopstad-IT/rqwstr-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server