ProjectDiscovery MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| subfinderC | Discover subdomains for a given domain using passive sources |
| dnsxC | Resolve DNS records for domains and subdomains |
| naabuC | Fast port scanner to discover open ports on hosts |
| httpxC | Probe HTTP/HTTPS servers and gather information |
| katanaC | Fast web crawler for discovering endpoints and paths |
| nucleiC | Fast vulnerability scanner using YAML-based templates |
| bug_bounty_workflowB | Execute complete bug bounty reconnaissance workflow: subdomain discovery, DNS resolution, port scanning, HTTP probing, crawling, and vulnerability scanning |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 7 tools
Each tool has a clearly distinct purpose with no ambiguity: subfinder for subdomain discovery, dnsx for DNS resolution, naabu for port scanning, httpx for HTTP probing, katana for crawling, nuclei for vulnerability scanning, and bug_bounty_workflow as an orchestration tool. The tools complement rather than overlap, making misselection unlikely.
Tool names follow a consistent pattern: all are lowercase, single-word names (or hyphenated for bug_bounty_workflow) that clearly identify their function (e.g., subfinder, dnsx, httpx). This uniformity makes the set predictable and easy to understand.
With 7 tools, the count is well-scoped for a security reconnaissance server, covering key stages like discovery, scanning, and analysis. Each tool earns its place by addressing a specific aspect of the workflow without redundancy.
The tool set provides complete coverage for bug bounty and reconnaissance workflows, from initial subdomain discovery (subfinder) through DNS resolution (dnsx), port scanning (naabu), HTTP probing (httpx), crawling (katana), vulnerability scanning (nuclei), and an orchestration tool (bug_bounty_workflow). There are no obvious gaps, enabling agents to handle full lifecycles.