Developer · Remote MCP server
Pentest MCP Server
Offline methodology engine for authorized penetration testing, CTF, and security research.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.cyanheads/pentest-mcp-server- Version
- 0.1.9
- Status
- Active
- Category
- developer
- Transport
- Streamable HTTP, stdio (local process)
- Package
- npm
- Published
- 2026-09-20
- Updated
- 2026-09-20
- Publisher
- cyanheads (GitHub) · 140 servers with pages here
- Repository
- github.com/cyanheads/pentest-mcp-server
- Source
- Registry API entry
Remote endpoints
| Transport | URL | Headers declared |
|---|---|---|
| Streamable HTTP | https://pentest.caseyjhand.com/mcp | None |
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npmruntime: bun | @cyanheads/pentest-mcp-server | 0.1.9 | stdio |
| npmruntime: bun | @cyanheads/pentest-mcp-server | 0.1.9 | HTTP |
How to connect Pentest MCP Server
Pentest MCP Server is a remote MCP server: there is nothing to install. Its endpoint is https://pentest.caseyjhand.com/mcp, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.
No headers are declared in the registry entry. If the server needs you to sign in, a client that supports MCP authorization opens the service's own sign-in page when it first connects.
It can also run locally from a Node.js package published to the npm registry: @cyanheads/pentest-mcp-server version 0.1.9. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @cyanheads/pentest-mcp-server@0.1.9; the entry names bun as the runtime. It reads the environment variable MCP_LOG_LEVEL; set it in the client's configuration for this server.
It can also run locally from a Node.js package published to the npm registry: @cyanheads/pentest-mcp-server version 0.1.9. The package starts a local server that speaks MCP over Streamable HTTP; the client then connects to it by URL (the entry names bun as the runtime). It reads these environment variables: MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE and MCP_LOG_LEVEL; set them in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"pentest-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/pentest-mcp-server@0.1.9"
],
"env": {
"MCP_LOG_LEVEL": "<value>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from cyanheads (GitHub)
| Server | Runs |
|---|---|
| Openstates MCP ServerSearch bills, legislators, committees, and events across all 50 US states, DC, and 5 US territories. | Remote & Local · HTTP, stdio |
| Openstreetmap MCP ServerGeocode, reverse geocode, and run Overpass spatial queries on OpenStreetMap data. | Remote & Local · HTTP, stdio |
| Orcid MCP ServerResearcher profiles, works, affiliations, funding, and peer reviews from the ORCID registry. | Remote & Local · HTTP, stdio |
| Osv Advisory MCP ServerQuery OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP. | Remote & Local · HTTP, stdio |
| Ourairports MCP ServerOffline global aviation reference — airports, runways, navaids, frequencies from OurAirports. | Remote & Local · HTTP, stdio |
| Paleobiology MCP ServerSearch fossil occurrences, taxon ranges, diversity through deep time, and the geologic time scale. | Remote & Local · HTTP, stdio |
| Pixoo MCP ServerRender and push styled pixel art, text, dashboards, and animations to Divoom Pixoo LED displays. | Local · stdio, HTTP |
| Pokeapi MCP ServerLook up Pokémon, moves, abilities, items, natures, and type matchups from PokéAPI v2. | Remote & Local · HTTP, stdio |
| Protein MCP ServerMCP Server for 3D protein structural data retrieval & analysis from RCSB PDB, PDBe, and UniProt. | Local · stdio, HTTP |
| Pubchem MCP ServerSearch PubChem compounds, properties, safety data, bioactivity, and cross-references. | Remote & Local · HTTP, stdio |
| Pubmed MCP ServerSearch PubMed/Europe PMC, fetch articles and full text (PMC/EPMC/Unpaywall), citations, MeSH terms. | Remote & Local · HTTP, stdio |
| Reference Data MCP ServerCountries, timezones, elements, constants, HTTP status codes, unit conversion, and MIME type lookup. | Remote & Local · HTTP, stdio |
More developer servers
| Server | Runs |
|---|---|
| PeerPushFind and compare software, SaaS, developer, and AI tools: alternatives, pricing, platforms, trends. | Remote · HTTP |
| PennyPilot MCPOpen-core, local, read-only MCP server for Pennylane Company API v2. Auditable READ_ONLY_GUARD. | Local · stdio |
| PensieveManually-triggered, self-organising personal memory for AI agents; SQLite, no vector DB. | Local · stdio |
| Pentagonal MCPAI contract forge — 8-agent security audits, generation, and compilation across 8 chains. | Local · stdio |
| pentest-tools.comMCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM. | Remote · HTTP |
| Peon MemLocal-first memory brain for AI coding agents: hooks capture sessions, beliefs injected per prompt. | Local · stdio |
| People ContextLocal-first MCP server giving AI agents contextual knowledge about the people in your life. | Local · stdio |
| PeppolStatusPeppol market intelligence and network monitoring: migrations, provider churn, leads, and uptime. | Remote · HTTP |