Skip to main content
Glama

Caido MCP Server

A Model Context Protocol (MCP) server that acts as a bridge to Caido, allowing AI Agents (like Claude, LangChain, etc.) to perform automated security testing and analysis.

🚀 Capabilities

This server connects to your local Caido instance (default port 8080) and exposes tools to:

  • View Request History: Analyze traffic captured by Caido proxy.

  • Send Requests: Forge and send HTTP requests via Caido's engine.

  • Scan for Mitigation: Run basic automated XSS/SQLi checks.

  • Get Findings: Retrieve reported vulnerabilities.

See MCP_CAPABILITIES.md for a detailed power list.

Related MCP server: Kali Linux MCP Server

🛠️ Setup

  1. Prerequisites:

    • Node.js installed.

    • Caido running (usually on port 8080).

    • Caido API Token (Settings -> API).

  2. Installation:

    git clone https://github.com/FazcomIA/mcp-caido.git
    cd mcp-caido
    npm install
  3. Configuration: Create a .env file in the root:

    CAIDO_URL=http://127.0.0.1:8080/graphql
    CAIDO_API_TOKEN=your_token_here
    MCP_PORT=3000
    MCP_API_KEY=mcp-dev-key

🏃 Usage

Start the server:

node server.js

Connect an AI Agent

The MCP server listens on http://localhost:3000/mcp/call. Required Header: X-API-Key: mcp-dev-key

Example Curl:

curl -X POST http://localhost:3000/mcp/call \
  -H "Content-Type: application/json" \
  -H "X-API-Key: mcp-dev-key" \
  -d '{"tool": "getStatus", "params": {}}'

🔒 Security

  • API Key: Protected by MCP_API_KEY.

  • Local Only: By default, runs locally. Be careful if exposing to a network.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to perform authorized security testing and penetration testing operations including SSL/TLS analysis, port scanning, vulnerability scanning, and HTTP security header audits through natural language interactions.
    1
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to perform penetration testing and security assessments by exposing 60+ Kali Linux security tools including network scanning, web security testing, password cracking, exploitation frameworks, and OSINT capabilities through an AI-friendly interface.
    2
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to perform security testing on web applications by controlling a Firefox browser with 39 security tools, including injection testing and access control analysis.
    22
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Integrates 7 security tools (nmap, nuclei, dirsearch, sqlmap, hydra, Acunetix, Metasploit) via MCP protocol for AI-assisted penetration testing with enterprise-grade safety features.
    1
    MIT

Appeared in Searches