Skip to main content
Glama

mcpsmuggler

FastMCP wrapper for the Smuggler HTTP Request Smuggling scanner, packaged for Render via Docker.

What this does

  • Exposes an MCP server with a single tool: do_smuggler

  • Runs the Smuggler CLI (smuggler -u <url> ...) inside the container

  • Uses SSE transport on /mcp (FastMCP default)

Related MCP server: ZAP MCP Proxy

Running locally

git clone https://github.com/ozgurozkan123/mcpsmuggler.git
cd mcpsmuggler
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
python server.py  # starts on http://0.0.0.0:8000/mcp

Render deployment (Docker)

Render will auto-detect the Dockerfile:

  • Runtime: Docker

  • Exposed port: PORT env (Render sets this)

  • Start command: handled by Dockerfile (python server.py)

If using Render UI:

  1. Create a Web Service

  2. Connect this repo and choose Docker

  3. Leave root directory empty, Dockerfile path = Dockerfile

  4. No build/start commands needed

MCP client config examples

{
  "mcpServers": {
    "mcpsmuggler": {
      "url": "https://<your-render-url>/mcp"
    }
  }
}

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Scans MCP tool descriptions for prompt injection attacks, including cross-tool instructions, privilege escalation, and data exfiltration patterns. It can be used as a CLI scanner or integrated as an MCP server itself.
    22 npm
    6
    MIT
  • F
    license
    Not graded
    quality
    C
    maintenance
    A lightweight MCP server that wraps OWASP ZAP's REST API as Model Context Protocol tools, enabling AI agents to perform automated security scanning.
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to run bounded security reconnaissance tools against a local OWASP Juice Shop target via MCP, including HTTP checks, header inspection, Nmap scanning, and web enumeration, without granting arbitrary shell access.
    -