Why this server?
This server provides code analysis and security scans, which are related to penetration testing.
-securityAlicense-qualityA Model Context Protocol tool for analyzing code repositories, performing security scans, and assessing code quality across multiple programming languages.Last updated2MITWhy this server?
This secure shell command execution server is designed for integration with Claude and other MCP-compatible LLMs, useful for executing pentesting commands.
Why this server?
Enables secure shell command execution within a controlled environment, important for running penetration testing tools safely.
AsecurityAlicenseCqualityA Node.js implementation of the Model Context Protocol that provides secure shell command execution capabilities, allowing AI models like Claude to run shell commands in a controlled environment with built-in security measures.Last updated138240MITWhy this server?
A demonstration server that allows large language models to perform penetration testing tasks autonomously by interfacing with the Mythic C2 framework.
-securityFlicense-qualityA demonstration server that allows large language models to perform penetration testing tasks autonomously by interfacing with the Mythic C2 framework.Last updated73Why this server?
Enables code scanning for security vulnerabilities, which is essential for penetration testing.

Semgrep MCP Serverofficial
AsecurityAlicenseBqualityAn MCP server that provides a comprehensive interface to Semgrep, enabling users to scan code for security vulnerabilities, create custom rules, and analyze scan results through the Model Context Protocol.Last updated6649MITWhy this server?
A Model Context Protocol server for dnstwist, a powerful DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage, which is relevant to penetration testing.
-securityAlicense-qualityA Model Context Protocol (MCP) server for dnstwist, a powerful DNS fuzzing tool that helps detect typosquatting, phishing, and corporate espionage.Last updated7348MITWhy this server?
Provides accessibility testing capabilities, which can help identify vulnerabilities related to accessibility during a pentest.
AsecurityAlicenseBqualityProvides accessibility testing capabilities through CLI, helping identify accessibility issues in web applications using axe-core and Puppeteer.Last updated12MITWhy this server?
A secure server that enables AI applications to execute shell commands in specified directories, supporting multiple shell types with built-in security features like directory isolation and timeout control, important for a pentest.
AsecurityAlicenseBqualityA secure server that enables AI applications to execute shell commands in specified directories, supporting multiple shell types (bash, sh, cmd, powershell) with built-in security features like directory isolation and timeout control.Last updated118Apache 2.0Why this server?
Integrates with Sumo Logic's API to enable log search, supporting error handling, and easy deployment via Docker which could be used during pentesting to analyze logs.
-securityFlicense-qualityIntegrates with Sumo Logic's API to enable log search with configurable queries and time ranges, supporting error handling and easy deployment via Docker.Last updated1510