Sviluppo · Server MCP locale
Attack Surface MCP Server
Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
Cosa indica il MCP Registry
La voce come pubblicata nel MCP Registry ufficiale (consultazione: 4 ottobre 2026), ultima versione.
- Nome nel registro
io.github.cyanheads/attack-surface-mcp-server- Versione
- 0.2.3
- Stato
- Attivo
- Categoria
- sviluppo
- Trasporto
- stdio (processo locale) e Streamable HTTP
- Pacchetto
- npm
- Pubblicato
- 30 settembre 2026
- Aggiornato
- 30 settembre 2026
- Editore
- cyanheads (GitHub) · 140 server con una pagina qui
- Namespace
- Namespace verificato dal MCP Registry tramite GitHub (github.com/cyanheads) · come funziona
- Repository
- github.com/cyanheads/attack-surface-mcp-server
- Fonte
- Voce nell’API del registro
Pacchetti
| Registro | Pacchetto | Versione | Trasporto |
|---|---|---|---|
| npmruntime: bun | @cyanheads/attack-surface-mcp-server | 0.2.3 | stdio |
| npmruntime: bun | @cyanheads/attack-surface-mcp-server | 0.2.3 | HTTP |
Come collegare Attack Surface MCP Server
Attack Surface MCP Server viene eseguito in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @cyanheads/attack-surface-mcp-server, versione 0.2.3. Comunica via MCP su stdio, quindi il client lo avvia come programma e dialoga con esso tramite standard input e standard output. Richiede Node.js; i client in genere lo avviano con npx - il comando abituale è npx -y @cyanheads/attack-surface-mcp-server@0.2.3; la voce indica bun come ambiente di esecuzione. Legge queste variabili d’ambiente: SHODAN_API_KEY (segreto), CERTSPOTTER_API_KEY (segreto), ATTACKSURFACE_DEFAULT_RESOLVERS, ATTACKSURFACE_HTTP_USER_AGENT, ATTACKSURFACE_MAX_SUBDOMAINS, ATTACKSURFACE_RDAP_BOOTSTRAP_URL, ATTACKSURFACE_ALLOW_PRIVATE_TARGETS e MCP_LOG_LEVEL; vanno impostate nella configurazione del client per questo server.
Attack Surface MCP Server viene eseguito in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @cyanheads/attack-surface-mcp-server, versione 0.2.3. Il pacchetto avvia un server locale che comunica via MCP su Streamable HTTP; il client vi si collega poi tramite URL (la voce indica bun come ambiente di esecuzione). Legge queste variabili d’ambiente: MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE e MCP_LOG_LEVEL; vanno impostate nella configurazione del client per questo server.
Nel formato JSON mcpServers, letto da molti client MCP desktop e per editor di codice, la voce si presenta così (segnaposto tra parentesi angolari):
{
"mcpServers": {
"attack-surface-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/attack-surface-mcp-server@0.2.3"
],
"env": {
"SHODAN_API_KEY": "<segreto>",
"CERTSPOTTER_API_KEY": "<segreto>",
"ATTACKSURFACE_DEFAULT_RESOLVERS": "<valore>",
"ATTACKSURFACE_HTTP_USER_AGENT": "<valore>",
"ATTACKSURFACE_MAX_SUBDOMAINS": "<valore>",
"ATTACKSURFACE_RDAP_BOOTSTRAP_URL": "<valore>",
"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS": "<valore>",
"MCP_LOG_LEVEL": "<valore>"
}
}
}
}Ricavato dalla voce del registro, non testato qui. Cosa fa il server, e a quali condizioni, lo stabilisce il suo editore; prima di concedergli l’accesso ai propri account o file conviene consultarne il repository o il sito web. Come aggiungere un server MCP a un assistente · Prima di collegare un server
Altri server di cyanheads (GitHub)
| Server | Esecuzione |
|---|---|
| Anime MCP ServerSearch anime/manga, franchise watch order, schedule, characters, rankings, studio filmography. | Locale · stdio e HTTP |
| Art Institute Chicago MCP ServerSearch the Art Institute of Chicago collection: artworks, artists, exhibitions, and audio guides. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Arxiv MCP ServerSearch arXiv, fetch paper metadata, and read full-text content. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Astronomy MCP ServerOffline observational astronomy: positions, rise/set, moon phases, eclipses, and seasons. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Aviation Weather MCP ServerFetch METARs, TAFs, PIREPs, and domestic SIGMETs from the NWS Aviation Weather Center. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Biorxiv MCP ServerSearch and retrieve bioRxiv and medRxiv preprints - by DOI, date interval, or keyword - via MCP. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Bls Labor MCP ServerFetch US Bureau of Labor Statistics data - CPI, unemployment, wages, JOLTS, and more via MCP. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Bluesky MCP ServerSearch posts, profiles, feeds, threads, and trending topics on Bluesky. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Brapi MCP ServerCollaborative BrAPI v2.1 MCP workspace - studies, germplasm, genotypes across Breedbase, T3, more. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Browser Compat MCP ServerBrowser compatibility and Baseline status for any web feature - offline, from bundled MDN data. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Calculator MCP ServerEvaluate, simplify, and differentiate mathematical expressions. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Cdc Health MCP ServerSearch and query CDC public health data - mortality, vaccinations, surveillance, behavioral risk. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
Altri server della categoria sviluppo
| Server | Esecuzione |
|---|---|
| Atlassian Dc MCP BitbucketMCP server for Atlassian Bitbucket Data Center - interact with repositories and code. | Locale · stdio |
| Atomadic ForgeArchitecture compiler for AI code. 11 tools, 92 actions, 872 Lean4 proofs, 100/100 self-cert. | Remoto e locale · HTTP e stdioVerifica live: ✗ nessun handshake |
| AtomicrepsRetrieval practice in your coding agent: one short question about what you just built. | Remoto e locale · HTTP e stdioVerifica live: accesso richiesto |
| AtonoGive your AI coding tools your team's product context: stories, bugs, epics, and glossary. | Locale · stdio |
| Attest proxyZero-code proxy: policy, human gate, read-back and a hash-chained ledger for any MCP server. | Locale · stdio |
| Attestd MCPCVE checks, supply chain signals, live catalog, and CVE detail for MCP clients (infra, PyPI, npm). | Locale · stdio |
| Attester OracleVerify PyPI and npm packages, symbols, and version diffs against real artifacts. Free, no account. | Remoto · HTTPVerifica live: ✓ handshake |
| AttestorSelf-hosted memory for agent teams. Bi-temporal replay, deterministic retrieval, audit log. | Locale · stdio |