Maps & transport · Local MCP server
Attack Surface MCP Server
Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.cyanheads/attack-surface-mcp-server- Version
- 0.2.3
- Status
- Active
- Category
- maps & transport
- Transport
- stdio (local process), Streamable HTTP
- Package
- npm
- Published
- 2026-09-30
- Updated
- 2026-09-30
- Publisher
- cyanheads (GitHub) · 140 servers with pages here
- Repository
- github.com/cyanheads/attack-surface-mcp-server
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npmruntime: bun | @cyanheads/attack-surface-mcp-server | 0.2.3 | stdio |
| npmruntime: bun | @cyanheads/attack-surface-mcp-server | 0.2.3 | HTTP |
How to connect Attack Surface MCP Server
Attack Surface MCP Server runs locally from a Node.js package published to the npm registry: @cyanheads/attack-surface-mcp-server version 0.2.3. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @cyanheads/attack-surface-mcp-server@0.2.3; the entry names bun as the runtime. It reads these environment variables: SHODAN_API_KEY (secret), CERTSPOTTER_API_KEY (secret), ATTACKSURFACE_DEFAULT_RESOLVERS, ATTACKSURFACE_HTTP_USER_AGENT, ATTACKSURFACE_MAX_SUBDOMAINS, ATTACKSURFACE_RDAP_BOOTSTRAP_URL, ATTACKSURFACE_ALLOW_PRIVATE_TARGETS and MCP_LOG_LEVEL; set them in the client's configuration for this server.
Attack Surface MCP Server runs locally from a Node.js package published to the npm registry: @cyanheads/attack-surface-mcp-server version 0.2.3. The package starts a local server that speaks MCP over Streamable HTTP; the client then connects to it by URL (the entry names bun as the runtime). It reads these environment variables: MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE and MCP_LOG_LEVEL; set them in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"attack-surface-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/attack-surface-mcp-server@0.2.3"
],
"env": {
"SHODAN_API_KEY": "<secret>",
"CERTSPOTTER_API_KEY": "<secret>",
"ATTACKSURFACE_DEFAULT_RESOLVERS": "<value>",
"ATTACKSURFACE_HTTP_USER_AGENT": "<value>",
"ATTACKSURFACE_MAX_SUBDOMAINS": "<value>",
"ATTACKSURFACE_RDAP_BOOTSTRAP_URL": "<value>",
"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS": "<value>",
"MCP_LOG_LEVEL": "<value>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from cyanheads (GitHub)
| Server | Runs |
|---|---|
| Anime MCP ServerSearch anime/manga, franchise watch order, schedule, characters, rankings, studio filmography. | Local · stdio, HTTP |
| Art Institute Chicago MCP ServerSearch the Art Institute of Chicago collection: artworks, artists, exhibitions, and audio guides. | Remote & Local · HTTP, stdio |
| Arxiv MCP ServerSearch arXiv, fetch paper metadata, and read full-text content. | Remote & Local · HTTP, stdio |
| Astronomy MCP ServerOffline observational astronomy: positions, rise/set, moon phases, eclipses, and seasons. | Remote & Local · HTTP, stdio |
| Aviation Weather MCP ServerFetch METARs, TAFs, PIREPs, and domestic SIGMETs from the NWS Aviation Weather Center. | Remote & Local · HTTP, stdio |
| Biorxiv MCP ServerSearch and retrieve bioRxiv and medRxiv preprints — by DOI, date interval, or keyword — via MCP. | Remote & Local · HTTP, stdio |
| Bls Labor MCP ServerFetch US Bureau of Labor Statistics data — CPI, unemployment, wages, JOLTS, and more via MCP. | Remote & Local · HTTP, stdio |
| Bluesky MCP ServerSearch posts, profiles, feeds, threads, and trending topics on Bluesky. | Remote & Local · HTTP, stdio |
| Brapi MCP ServerCollaborative BrAPI v2.1 MCP workspace — studies, germplasm, genotypes across Breedbase, T3, more. | Remote & Local · HTTP, stdio |
| Browser Compat MCP ServerBrowser compatibility and Baseline status for any web feature — offline, from bundled MDN data. | Remote & Local · HTTP, stdio |
| Calculator MCP ServerEvaluate, simplify, and differentiate mathematical expressions. | Remote & Local · HTTP, stdio |
| Cdc Health MCP ServerSearch and query CDC public health data — mortality, vaccinations, surveillance, behavioral risk. | Remote & Local · HTTP, stdio |
More maps & transport servers
| Server | Runs |
|---|---|
| askacharge.com — EV charging networkOperate a network of EV charge points over OCPP: status, sessions, tariffs, prices, remote commands. | Remote · HTTP |
| Astrology Forecast MCP Server by RoxyAPIAstrology transit forecasts, timelines and significant-date feeds for AI agents. | Remote · HTTP |
| AtlasThe world railway atlas as MCP tools: notable train routes, night trains, journey times. | Remote · HTTP |
| AtlasFetchReverse geocode a coordinate to country, region, municipality and street, plus your own geofences. | Local · stdio |
| Australian Towing Legality CheckLegal towing check for ~46 AU vehicles — compliant/marginal/illegal + the binding constraint. | Remote · HTTP |
| AutomationNation data tools (via Apify)AI visibility, Google Maps leads, Trends, Jobs, AI Overviews, UK leads, app reviews: one server. | Remote · HTTP |
| Axion GatewayVerified answers with named sources: UK parking appeals, NYC dismissal rates, UK MTD tax facts. | Remote · HTTP |
| BagIQ MCPAnalyse disc golf bag gaps and overlap, recommend discs, and open an interactive Bag Map. | Remote · HTTP |