Developer · Local MCP server

Cybersec Toolkit

Authorization-gated MCP server to discover and run 670+ security tools for CTF, pentest, and DFIR.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.26zl/cybersec-toolkit
Version
1.3.0
Status
Active
Category
developer
Transport
stdio (local process)
Package
OCI image (Docker)
Published
2026-09-24
Updated
2026-09-24
Publisher
26zl (GitHub)
Repository
github.com/26zl/cybersec-toolkit
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
OCI image (Docker)ghcr.io/26zl/cybersec-toolkit:1.3.0—stdioCYBERSEC_MCP_ALLOW_EXTERNAL, CYBERSEC_MCP_ALLOW_SCRIPTS

How to connect Cybersec Toolkit

Cybersec Toolkit runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/26zl/cybersec-toolkit:1.3.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e CYBERSEC_MCP_ALLOW_EXTERNAL -e CYBERSEC_MCP_ALLOW_SCRIPTS ghcr.io/26zl/cybersec-toolkit:1.3.0. It reads these environment variables: CYBERSEC_MCP_ALLOW_EXTERNAL and CYBERSEC_MCP_ALLOW_SCRIPTS; set them in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "cybersec-toolkit": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "CYBERSEC_MCP_ALLOW_EXTERNAL",
        "-e",
        "CYBERSEC_MCP_ALLOW_SCRIPTS",
        "ghcr.io/26zl/cybersec-toolkit:1.3.0"
      ],
      "env": {
        "CYBERSEC_MCP_ALLOW_EXTERNAL": "<value>",
        "CYBERSEC_MCP_ALLOW_SCRIPTS": "<value>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More developer servers

All 6,250 →
ServerRunsEndpoint or package
Cyanheads MCP ServerFleet discovery for the cyanheads MCP ecosystem — semantic search + install snippets.Remote & Local · HTTP, stdiocyanheads.caseyjhand.com
Cyberbro MCP ServerMCP server for Cyberbro IOC extraction, enrichment and reputation analysis.Local · stdioPyPI: mcp-cyberbro
CybergenicCancer gene co-occurrence and exclusivity in tumour cohorts, with confound controls and exact tests.Remote · HTTPcybergenic.im
CyberLensSecurity scanning for websites, public repositories, and Open CLAW skills.Local · stdionpm: @shadoprizm/cyberlens-mcp-server
Cybersecurity Threat Intelligence MCPCVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.Remote · HTTPcyber-intel-mcp-production.up.railway.app
Cybersim ProCybersecurity training, simulation, and incident response MCP server.Local · stdioOCI image (Docker): docker.io/hamcodes/cybersim-pro-mcp:v1.0.1
CyberSPFAssess a domain, IP or ASN: mail and DNS security, certificates, routing and a report card.Local · stdioPyPI: cyberspf-mcp
Cyclesite MCP ServerSearch, value, sell, and trust-check used bikes on Cyclesite — UK's used-bicycle marketplace.Remote & Local · HTTP, stdiocyclesite.co.uk