operant-mcp
OfficialRelated Servers
Alternatives to operant-mcp
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityDmaintenanceA security pentesting MCP server with 89 tools across 10 categories, enabling comprehensive reconnaissance, web security, OSINT, and exploitation tasks. It features a native Windows/WSL bridge for Kali Linux tools and scope-aware permission tiers for safe and efficient scanning.3MIT
- FlicenseNot gradedqualityDmaintenanceA comprehensive MCP server for automated bug bounty hunting and security reconnaissance, featuring over 28 specialized tools for subdomain discovery, vulnerability scanning, and traffic analysis. It integrates automated scope validation and professional reporting across multiple platforms like HackerOne and Bugcrowd to streamline security testing.5-
- FlicenseNot gradedqualityCmaintenanceMCP server for security analysis, reverse engineering, and penetration testing, providing 70+ tools (nmap, sqlmap, hydra, frida, etc.) with configurable backends (Docker Kali, WSL, SSH).-
- FlicenseNot gradedqualityBmaintenanceAn MCP server that exposes over 20 standard penetration testing utilities, such as Nmap, SQLMap, and OWASP ZAP, as callable tools for AI agents. It enables natural language control over complex security workflows for automated and interactive penetration testing.105-
- AlicenseNot gradedqualityNot gradedmaintenanceProvides access to 13+ penetration testing and security audit tools through a unified MCP interface. Enables security professionals to perform vulnerability scanning, web fuzzing, network reconnaissance, and other security assessments through containerized tools like Nuclei, Nmap, SQLMap, and FFUF.MIT
- AlicenseNot gradedqualityCmaintenanceThis MCP server offers 72 typed tools for Kali Linux pentesting, including recon, web, AD, cracking, C2, remote desktop, and tunneling. It provides structured JSON output, persistent session state, and auto-populated findings for streamlined workflows.MIT
TDQS
Scored across 51 tools
Tools are grouped by domain prefixes (pcap_, recon_, sqli_, etc.) and each description specifies a unique technique. Minor overlap exists between clickjacking/frame-buster tools and cookie/role manipulation tools, but the descriptions are explicit enough to avoid serious misselection.
All tool names follow snake_case with clear domain prefixes, making them readable and predictable. However, verb placement is inconsistent—some use noun_verb (cloudtrail_analyze), others verb_placement varies (pcap_detect_scan, sqli_blind_time)—so the pattern is not uniform.
51 tools is far beyond the typical well-scoped range and makes the server unwieldy for agents. The set spans unrelated domains—web testing, PCAP analysis, memory forensics, and cloud log review—which would be better served by splitting into smaller specialized servers.
The tool surface is broad and deep, covering reconnaissance, SQLi/NoSQLi/XSS/SSRF, authentication flaws, PCAP analysis, and memory forensics. Minor gaps exist, such as no dedicated port scanner or LFI/RFI tester, but core offensive security workflows are well supported.