PenTest MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| GEMINI_MODEL | No | The Gemini model to use (default: gemini-flash-lite-latest). | gemini-flash-lite-latest |
| GEMINI_API_KEY | Yes | Your Gemini API key for AI-powered reports and analysis. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| pingC | Health check for the PenTest MCP server |
| init_sessionC | Initialize new security assessment session |
| get_reportC | Generate final security assessment report |
| environment_checkA | Inspect installed tools, missing dependencies, and assessment readiness |
| quick_scanA | Fast triage scan (10-15 min): WAF detection, subdomain enum, top-port scan, header analysis, TLS audit, tech fingerprinting, sensitive file discovery, SSRF probe, CSRF check |
| extensive_scanC | Comprehensive scan (20-45 min): WAF detection, full recon, top-1000 port scan, tech fingerprinting, TLS audit, directory discovery, XSS, SQLi, CSRF, sensitive file discovery |
| subfinderC | Passive subdomain enumeration |
| wafw00fC | Web Application Firewall detection |
| nmapC | Port scanning and service detection |
| nucleiC | Fast vulnerability scanner with templates |
| sqlmapC | SQL injection detection and exploitation |
| dalfoxC | XSS vulnerability scanner |
| ffufC | Fast web fuzzer for directory/file discovery |
| sslyzeC | TLS/SSL configuration analyzer |
| whatwebC | Web technology fingerprinting |
| testsslC | TLS/SSL security testing |
| niktoD | Web server vulnerability scanner |
| gobusterC | Directory/file brute forcing |
| wfuzzC | Web application fuzzer |
| arjunC | HTTP parameter discovery |
| masscanC | Fast port scanner |
| amassC | Advanced subdomain enumeration |
| dnsreconC | DNS enumeration and reconnaissance |
| theharvesterC | OSINT gathering from public sources |
| retireC | JavaScript library vulnerability scanner |
| trufflehogC | Secret and credential scanner |
| git_dumperC | Exposed .git directory dumper |
| commixC | Command injection vulnerability scanner |
| corscannerC | CORS misconfiguration scanner |
| jwt_toolD | JWT security testing |
| graphql_copC | GraphQL security scanner |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 31 tools
Many tools have overlapping purposes (e.g., multiple port scanners, fuzzers, and vulnerability scanners). While descriptions provide some distinction, the high degree of redundancy makes it difficult for an agent to select the correct tool for a task.
Most tools are named after actual tool names (e.g., nmap, sqlmap) which are not descriptive of actions. There are a few descriptive names like ping and init_session, but overall the naming is a mix of proper nouns and verbs, lacking a consistent pattern.
31 tools is excessive for the scope, with many overlapping functionalities (e.g., 3 fuzzers, 2 TLS scanners). The count feels inflated by bundling every available tool rather than curating a minimal, non-redundant set.
The tool set covers major penetration testing areas (recon, scanning, web vulns, etc.), but notable gaps exist such as exploitation frameworks and post-exploitation tools. Additionally, the redundancy indicates incomplete coverage in certain areas.