offsec-mcp
Related Servers
Alternatives to offsec-mcp
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityDmaintenanceAI-powered Attack Surface Intelligence server that exposes industry-standard penetration testing tools via MCP, enabling AI agents to perform comprehensive security assessments.3-
- FlicenseNot gradedqualityCmaintenanceA production-style MCP server providing AI models with cybersecurity tools including port scanning, WHOIS, DNS, threat intelligence, CVE lookup, and more.-
- FlicenseNot gradedqualityBmaintenanceProduction-grade MCP server that exposes Kali Linux penetration testing tools to AI agents, enabling automated reconnaissance, web application testing, vulnerability assessment, and more.-
- AlicenseNot gradedqualityAmaintenanceAn MCP server that exposes a 60+ tool security and threat-intel stack to AI agents, enabling secret scanning, Sigma rule generation, ransomware lookup, OSINT, and deep research.1MIT
- FlicenseNot gradedqualityBmaintenanceAn MCP server that exposes over 20 standard penetration testing utilities, such as Nmap, SQLMap, and OWASP ZAP, as callable tools for AI agents. It enables natural language control over complex security workflows for automated and interactive penetration testing.97-
- AlicenseNot gradedqualityBmaintenanceMCP server providing safe, structured network and security reconnaissance tools for AI agents, with graded JSON results.1MIT
TDQS
Scored across 10 tools
Most tools target distinct actions (recon, DNS, WHOIS, CVE search/lookup, JS analysis, HTTP probing, header auditing, port scanning), but http_probe and security_headers both fetch a URL and could be confused without careful reading. cve_search and cve_lookup are also similar in name but serve different purposes.
Tool names mostly follow a snake_case pattern with a clear verb_noun structure (recon_subdomains, cve_search, analyze_js, port_scan). A few names like whois and scope_status deviate from this, but the overall convention is consistent and readable.
Ten tools is well-scoped for an offensive security server. Each tool represents a distinct phase of recon or assessment, and none feel redundant or superfluous.
The set covers passive recon (subdomains, DNS, WHOIS), vulnerability research (CVE), and active assessment (HTTP, headers, ports, JS). Minor gaps exist like no explicit tool for web technology fingerprinting beyond http_probe, but the core workflow is well covered.