Sviluppo · Server MCP remoto
Pentest MCP Server
Offline methodology engine for authorized penetration testing, CTF, and security research.
Cosa indica il MCP Registry
La voce come pubblicata nel MCP Registry ufficiale (consultazione: 4 ottobre 2026), ultima versione.
- Nome nel registro
io.github.cyanheads/pentest-mcp-server- Versione
- 0.1.9
- Stato
- Attivo
- Categoria
- sviluppo
- Trasporto
- Streamable HTTP e stdio (processo locale)
- Pacchetto
- npm
- Pubblicato
- 20 settembre 2026
- Aggiornato
- 20 settembre 2026
- Editore
- cyanheads (GitHub) · 140 server con una pagina qui
- Namespace
- Namespace verificato dal MCP Registry tramite GitHub (github.com/cyanheads) · come funziona
- Repository
- github.com/cyanheads/pentest-mcp-server
- Fonte
- Voce nell’API del registro
Endpoint remoti
| Trasporto | URL | Header dichiarati |
|---|---|---|
| Streamable HTTP | https://pentest.caseyjhand.com/mcp | Nessuno |
Verifica live
Questa directory si è collegata a ogni endpoint remoto e ne ha richiesto l’elenco degli strumenti. La verifica si limita a collegarsi e a elencare gli strumenti; non li esegue, non effettua l’accesso e non testa la sicurezza.
- Raggiungibile
- Sì (HTTP 200)
- Handshake
- pentest-mcp-server 0.1.9 · protocollo 2025-06-18
- Strumenti trovati
- 7:
pentest_guide,pentest_analyze_response,pentest_lookup_technique,pentest_lookup_group,pentest_map_techniques,pentest_generate_payloads,pentest_encode - Data della verifica
- 5 ottobre 2026
Pacchetti
| Registro | Pacchetto | Versione | Trasporto |
|---|---|---|---|
| npmruntime: bun | @cyanheads/pentest-mcp-server | 0.1.9 | stdio |
| npmruntime: bun | @cyanheads/pentest-mcp-server | 0.1.9 | HTTP |
Come collegare Pentest MCP Server
Pentest MCP Server è un server MCP remoto: non c’è niente da installare. Il suo endpoint, servito tramite Streamable HTTP, è https://pentest.caseyjhand.com/mcp. In un assistente che accetta server MCP remoti (spesso in un’impostazione chiamata connettori, integrazioni o strumenti) si aggiunge un nuovo server indicando questo URL; in un client configurato tramite file lo si aggiunge come server remoto (HTTP) con lo stesso URL.
La voce del registro non dichiara alcun header. Se il server richiede l’accesso, un client che supporta l’autorizzazione MCP apre la pagina di accesso del servizio alla prima connessione.
Può essere eseguito anche in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @cyanheads/pentest-mcp-server, versione 0.1.9. Comunica via MCP su stdio, quindi il client lo avvia come programma e dialoga con esso tramite standard input e standard output. Richiede Node.js; i client in genere lo avviano con npx - il comando abituale è npx -y @cyanheads/pentest-mcp-server@0.1.9; la voce indica bun come ambiente di esecuzione. Legge la variabile d’ambiente MCP_LOG_LEVEL; va impostata nella configurazione del client per questo server.
Può essere eseguito anche in locale a partire da un pacchetto Node.js pubblicato nel registro npm: @cyanheads/pentest-mcp-server, versione 0.1.9. Il pacchetto avvia un server locale che comunica via MCP su Streamable HTTP; il client vi si collega poi tramite URL (la voce indica bun come ambiente di esecuzione). Legge queste variabili d’ambiente: MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE e MCP_LOG_LEVEL; vanno impostate nella configurazione del client per questo server.
Nel formato JSON mcpServers, letto da molti client MCP desktop e per editor di codice, la voce si presenta così (segnaposto tra parentesi angolari):
{
"mcpServers": {
"pentest-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/pentest-mcp-server@0.1.9"
],
"env": {
"MCP_LOG_LEVEL": "<valore>"
}
}
}
}Ricavato dalla voce del registro; la verifica live riportata sopra mostra solo se l’endpoint ha risposto. Cosa fa il server, e a quali condizioni, lo stabilisce il suo editore; prima di concedergli l’accesso ai propri account o file conviene consultarne il repository o il sito web. Come aggiungere un server MCP a un assistente · Prima di collegare un server
Altri server di cyanheads (GitHub)
| Server | Esecuzione |
|---|---|
| Openstates MCP ServerSearch bills, legislators, committees, and events across all 50 US states, DC, and 5 US territories. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Openstreetmap MCP ServerGeocode, reverse geocode, and run Overpass spatial queries on OpenStreetMap data. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Orcid MCP ServerResearcher profiles, works, affiliations, funding, and peer reviews from the ORCID registry. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Osv Advisory MCP ServerQuery OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Ourairports MCP ServerOffline global aviation reference - airports, runways, navaids, frequencies from OurAirports. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Paleobiology MCP ServerSearch fossil occurrences, taxon ranges, diversity through deep time, and the geologic time scale. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Pixoo MCP ServerRender and push styled pixel art, text, dashboards, and animations to Divoom Pixoo LED displays. | Locale · stdio e HTTP |
| Pokeapi MCP ServerLook up Pokémon, moves, abilities, items, natures, and type matchups from PokéAPI v2. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Protein MCP ServerMCP Server for 3D protein structural data retrieval & analysis from RCSB PDB, PDBe, and UniProt. | Locale · stdio e HTTP |
| Pubchem MCP ServerSearch PubChem compounds, properties, safety data, bioactivity, and cross-references. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Pubmed MCP ServerSearch PubMed/Europe PMC, fetch articles and full text (PMC/EPMC/Unpaywall), citations, MeSH terms. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
| Reference Data MCP ServerCountries, timezones, elements, constants, HTTP status codes, unit conversion, and MIME type lookup. | Remoto e locale · HTTP e stdioVerifica live: ✓ handshake |
Altri server della categoria sviluppo
| Server | Esecuzione |
|---|---|
| pendntHuman approvals, notifications, inbound webhooks, wake-ups for headless agents. Free trial: /try. | Remoto · HTTPVerifica live: accesso richiesto |
| Penniless Data UtilitiesTen x402-paid tools for JSON, YAML, cron, diff, text, DNS, WHOIS, GitHub, crypto, and email. | Remoto · HTTPVerifica live: ✓ handshake |
| PensieveManually-triggered, self-organising personal memory for AI agents; SQLite, no vector DB. | Locale · stdio |
| Pentagonal MCPAI contract forge - 8-agent security audits, generation, and compilation across 8 chains. | Locale · stdio |
| pentest-tools.comMCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM. | Remoto · HTTPVerifica live: accesso richiesto |
| Peon MemLocal-first memory brain for AI coding agents: hooks capture sessions, beliefs injected per prompt. | Locale · stdio |
| PeppolStatusPeppol market intelligence and network monitoring: migrations, provider churn, leads, and uptime. | Remoto · HTTPVerifica live: ✓ handshake |
| PerennaA lightweight, Git-backed permanent memory for AI agents. | Locale · stdio |