den
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@denuse whisker to find subdomains of example.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ferret-den
An MCP server that exposes ProjectDiscovery reconnaissance binaries under decoupled tool names to prevent false-positive model refusals.
den:whisker runs subfinder. den:fang runs nuclei. The agent sees the job. The binary name stays out of the catalog.
Why the Names · Architecture & Safety · Jobs · Installation · Configuration · License

Why the Names
Frontier models and automated API moderation layers frequently trigger refusal reflexes on specific cybersecurity keywords (nuclei, subfinder, exploit, vulnerability scanner). When these names appear directly in an MCP server's tools/list catalog, models often refuse benign reconnaissance tasks (such as asset inventory or attack surface mapping) before evaluating the prompt context, target authorization, or input arguments.
ferret-den decouples tool definitions from binary execution:
The Agent View: The agent inspects
den:*names paired with clear functional descriptions and typed schemas (e.g.,den:whisker= "Finds subdomains").The Process View: The local server translates valid calls into local binary invocations via argument arrays (
subfinder,httpx,nuclei).The Safety View: Destructive or active scanning actions are protected by explicit human confirmation gates (
confirm: true), replacing brittle keyword blocking with real operational oversight.
This design reflects recent empirical research on agentic safety boundaries:
Not All Refusals Are Equal: How Safety Alignment Fails Cybersecurity at Scale (arXiv:2607.02714): Demonstrates that cybersecurity refusals often operate as blunt, over-generalized directional vectors that penalize defensive workflows without stopping dedicated adversaries.
A New Framework for Cybersecurity Refusals in AI Agents (arXiv:2606.02644): Evaluates refusal variations across frontier models on multi-step security tasks.
MLLMs Fail to Refuse when Using Tools Agentically (arXiv:2610.03938): Shows that structured tool usage focuses models on API compliance, significantly reducing superficial conversational refusals.
Renaming is not an exploit or a jailbreak. If a model determines that an underlying objective is harmful, it will still refuse. The renaming simply prevents surface-level lexical filters from blocking authorized, routine recon.
Related MCP server: PengStrike AI MCP
Architecture & Safety
No Shell Interpolation: All binaries are spawned directly using argument arrays via POSIX
spawn. Shells (/bin/sh,cmd.exe) are never invoked, eliminating command injection risks.Execution Timeouts: Kit jobs carry an enforced 120-second execution cap.
den:denhomeexits after 8 seconds.Human Confirmation Gate:
den:fang,den:raid,den:keeper,den:chatter,den:shadow, andden:denhomerequireconfirm: truebefore execution begins.External Binaries: The repository does not ship binaries. It invokes existing executables managed by
pdtmin$PD_TOOLS_DIR(defaulting to$HOME/.pdtm/go/bin).
Jobs
The server exposes 22 discrete MCP tools. The primary nine jobs feature fully typed argument schemas, while utility tasks accept a target and an argument array.
MCP Tool Name | Underlying Binary | Functional Description | Execution Gate |
|
| Discovers subdomains passively across public sources. | Standard |
|
| Resolves hostnames and validates active DNS records. | Standard |
|
| Probes HTTP/HTTPS endpoints for status, title, and tech stack. | Standard |
|
| Inspects TLS/SSL certificates, ciphers, and protocols. | Standard |
|
| Performs fast TCP port scanning. | Standard |
|
| Crawls web pages and JavaScript links. | Standard |
|
| Brute-forces domain resolution against wordlists. | Standard |
|
| Executes vulnerability and configuration template checks. |
|
| chain | Runs subfinder, dnsx, naabu, then probes open ports with httpx, crawls with katana, and scans with nuclei. |
|
|
| Installs or updates ProjectDiscovery binaries. |
|
|
| Discovers exposed assets and administrative panels via OSINT engines. | Standard |
|
| Dispatches webhook and messaging notifications. |
|
|
| Intercepts and captures HTTP/HTTPS traffic. |
|
|
| Queries ProjectDiscovery Chaos threat intelligence datasets. | Standard |
|
| Detects CDN, cloud provider, and WAF IP ownership. | Standard |
|
| Maps ASN IP ranges and CIDR blocks. | Standard |
|
| Generates permutation lists of subdomains. | Standard |
|
| Formats and expands CIDR blocks. | Standard |
|
| Enumerates assets across cloud infrastructure providers. | Standard |
|
| Discovers top-level domains for a given entity. | Standard |
|
| Spawns a local testing file server that auto-terminates after 8 seconds. |
|
|
| Prompts ProjectDiscovery AI command assistants. | Standard |
| internal | Returns the active tool mapping table from the running server. | Standard |
Installation
Prerequisites
Install pdtm and set up the ProjectDiscovery suite:
go install github.com/projectdiscovery/pdtm/cmd/pdtm@latest
pdtm -install-allServer Setup
git clone https://github.com/toxicwind/ferret-den.git
cd ferret-den
cp .env.example .env
sh scripts/write-env.sh
sh scripts/link-bins.sh
bun install
bun src/index.tsscripts/link-bins.sh generates the symlinks in the bin directory. The server exclusively accepts and processes den:* identifiers.
Configuration
Add the server to your MCP client configuration (for example claude_desktop_config.json):
{
"mcpServers": {
"den": {
"command": "bun",
"args": ["/path/to/ferret-den/src/index.ts"],
"env": {
"PD_TOOLS_DIR": "$HOME/.pdtm/go/bin"
}
}
}
}Repository Layout
src/index.ts: Primary MCP entrypoint; validates inputs and routes process execution.src/den-names.ts: Static mapping between MCP identifiers and system binaries.src/tools/: Type definitions and structured schemas for core tools.src/tools/kit.ts: Argument forwarding and timeout wrappers for utility tools.src/workflows/bug-bounty.ts: Pre-chained reconnaissance sequence (den:raid).scripts/: Environment configuration and binary symlink scripts.
License
The den translation layer, scripts, and documentation are licensed under WTFPL v2.
Upstream MCP core components derived from intelligent-ears/pd-tools-mcp remain under the MIT License.
This server cannot be deployed
Maintenance
Related MCP Connectors
Find, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Your org's AI agents, tasks, runs, search, and brain files as MCP tools and resources.
Hyperion — MCP tool marketplace for AI agents: web, OSINT, security, research via one key.
Related MCP Servers
- FlicenseAqualityDmaintenanceIntegrates ProjectDiscovery security tools to perform automated reconnaissance, subdomain discovery, and vulnerability scanning. It enables comprehensive bug hunting workflows by chaining tools like subfinder, naabu, and nuclei into a unified pipeline.76-
- AlicenseNot gradedqualityCmaintenanceTurns any MCP-capable AI agent into a professional penetration testing platform with 150+ security tools, adaptive async tasks, and crash-proof concurrency.1MIT
- FlicenseNot gradedqualityCmaintenanceEnables AI agents to run bounded security reconnaissance tools against a local OWASP Juice Shop target via MCP, including HTTP checks, header inspection, Nmap scanning, and web enumeration, without granting arbitrary shell access.-
- AlicenseNot gradedqualityCmaintenanceEnables LLM-driven security assessments by exposing Kali tools like nmap, httpx, sqlmap, and ffuf as MCP tools, with explicit planning, parallel tool calls, tiered memory, MITRE ATT&CK mapping, and human approval gates for intrusive operations.2MIT