Skip to main content
Glama
intruder-io

intruder-mcp

Official
by intruder-io
README.md
# Intruder MCP

Let MCP clients like Claude and Cursor control [Intruder](https://www.intruder.io/). For more information and sample use cases, please see [our blog post](https://www.intruder.io/blog/claude-intruder-mcp#intruder-mcp-use-cases).

## Installation
There are two ways to use the MCP server:
- Locally on your machine with Python
- In a Docker container

All of these methods require you to provide an Intruder API key. To generate a key, see [the documentation](https://developers.intruder.io/docs/creating-an-access-token).

### Running Locally
Install [uv](https://github.com/astral-sh/uv) if it isn't already present, and then clone this repository and run the following from the root directory:

```bash
uv venv
uv pip install -e .
```

Then, add the following to your MCP client configuration, making sure to fill in your API key, and update the path to where you have cloned this repository:

```json
{
  "mcpServers": {
    "intruder": {
      "command": "uv",
      "args": [
        "--directory",
        "path/to/intruder-mcp/intruder_mcp",
        "run",
        "server.py"
      ],
      "env": {
        "INTRUDER_API_KEY": "your-api-key"
      }
    }
  }
}
```

### Running in a Container

Add the following to your MCP client configuration, making sure to fill in your API key:

```json
{
  "mcpServers": {
    "intruder": {
      "command": "docker",
      "args": [
        "container",
        "run",
        "--interactive",
        "--rm",
        "--init",
        "--env",
        "INTRUDER_API_KEY=<your-api-key>",
        "ghcr.io/intruder-io/intruder-mcp"
      ]
    }
  }
}
```

TDQS

A3.6/5.0

Scored across 22 tools

Disambiguation5/5

Each tool has a clearly distinct purpose. For example, create_scan vs create_scan_schedule target different entities, and list_scans vs get_scan differentiate listing from details. No overlapping functionality.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern (e.g., create_targets, list_issues, delete_target_tag). No mixing of conventions, making the set predictable.

Tool Count5/5

22 tools cover target management, scan lifecycle, issue tracking, and account info without being excessive. Each tool serves a necessary function for a vulnerability scanning API.

Completeness4/5

Core CRUD operations are present for targets, tags, scans, schedules, issues, and occurrences. Minor gaps exist like no direct update for a scan (only schedules) or no unsnooze tool, but the overall surface is robust.

Maintenance

ActivityInactive
ResponsivenessNo issues