pentest-mcp — security grade SAFE, quality 74/100

Security audit verdict: SAFE · quality 74/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by DMontgomery40 · MCP Server · ★ 139

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is pentest-mcp safe to install? View the security audit →

About pentest-mcp

Pentest MCP Professional penetration-testing MCP server with modern transport/auth support and expanded recon tooling. What Changed in 0.9.0 Upgraded MCP SDK to Kept MCP Inspector at the latest release () with bundled launcher Streamable HTTP is now the primary network transport () SSE is still available only as a deprecated compatibility mode Added bearer-token auth with OIDC JWKS and introspection support Added first-class tools: , , , , , , , Added report-admin tools: , Added SoW capture flow for reports using MCP elicitation () with safe template fallback Hardened command resolution so web probing uses (preferred) or validated ProjectDiscovery , avoiding Python CLI collisions Integrated bundled MCP Inspector launcher () Runtime baseline is now Node.js 22.7.5+ Added invocation metadata in new tool outputs when auth/session context is available Included Tools runJohnT

cybersecuritydirbustergobusterhashcathttp-streamingjohn-the-ripperjtrmcpmcp-servermodel-context-protocol

Quick Facts

Stars139
Forks28
LanguageJavaScript
CategoryMCP Server
LicenseMIT
Quality Score74.0792867332492/100
Open Issues2
Last Updated2026-03-23
Created2025-04-04
Platformsmcp, node
Est. Tokens~564k

Compatible Skills

These tools work well together with pentest-mcp for enhanced workflows:

pentest-mcp alternative? Top 6 similar tools

Looking for a pentest-mcp alternative? If you're comparing pentest-mcp with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • RedTeam-Agent by ktol1 · ⭐ 66

    RedTeam-MCP: AI-Powered Autonomous Red Team Framework via Model Context Protocol. AI红队与内网渗透自动化框架,支持 gogo, fsca

  • tengu by rfunix · ⭐ 58

    AI-powered penetration testing MCP server

  • mcp-for-security by cyproxio · ⭐ 631

    MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF,

  • vurb.ts by vinkius-labs · ⭐ 251

    TypeScript framework for building production MCP servers. Fluent tool API, FSM gating, presenters, semantic ro

  • Wazuh-MCP-Server by gensecaihq · ⭐ 232

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • mcp-virustotal by BurtTheCoder · ⭐ 127

    MCP server for VirusTotal API — analyze URLs, files, IPs, and domains with comprehensive security reports, rel

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is pentest-mcp?

pentest-mcp is NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR, hashcat, wordlist building, and more.. It is categorized as a MCP Server with 139 GitHub stars.

What programming language is pentest-mcp written in?

pentest-mcp is primarily written in JavaScript. It covers topics such as cybersecurity, dirbuster, gobuster.

How do I install or use pentest-mcp?

You can find installation instructions and usage details in the pentest-mcp GitHub repository at github.com/DMontgomery40/pentest-mcp. The project has 139 stars and 28 forks, indicating an active community.

What license does pentest-mcp use?

pentest-mcp is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to pentest-mcp?

The top alternatives to pentest-mcp on Agent Skills Hub include RedTeam-Agent, tengu, mcp-for-security. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools