FofaMap — security grade SAFE, quality 61/100

Security audit verdict: SAFE · quality 61/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by asaotomo · MCP Server · ★ 699

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is FofaMap safe to install? View the security audit →

About FofaMap

🗺️ FofaMap v2.0 — Platinum Agent Edition 🧠 全网首个支持 MCP 协议 + AI 自我反思机制的红队资产测绘智能体 Self-Reflecting AI Queries → MCP Protocol Integration → Intelligent Vulnerability Scanning ✨ 一句话介绍 ❌ 它不是 FOFA 工具 ❌ 也不是 Nuclei 封装 ✅ 它是:一个可以被 AI 接管、会自己反思、会自己决策扫描策略的「全网资产测绘智能体」 目前fofamapv2.0版本已作为 Skill 上线 ClawHub 技能商城,您可通过以下命令安装,让您的 AI 助手(“龙虾”)也能使用资产测绘: 🚀 v2.0 是什么级别的升级? FofaMap 从「资产查询工具」→ 进化为 AI Agent(智能体) 🧠 1️⃣ 你只要说人话 AI 自动完成: 理解你的意图 生成 FOFA 语法 查询资产 若 0 结果 → 启动 自我反思机制 自动放宽条件重试 分析资产指纹 判断是否值得扫描 自动生成 Nuclei 扫描参数 询问你是否执行 🤖 2️⃣ 会“自我反思”的 AI(核心黑科技) 不再出现: AI 会自动: 判断: 是否地区条件过严? 是否关键词不合理? 是否语法太死? 自动: 放宽条件 重写语法 多策略重试 直到:尽量给你产出结果 🔌 3️⃣ 原生 MCP 支持(给 AI

ai-agentasset-discoveryasset-mappingattack-surface-managementcybersecurityfastapifofafofa-apimcpmodel-context-protocol

Quick Facts

Stars699
Forks93
LanguagePython
CategoryMCP Server
LicenseApache-2.0
Quality Score61.0294057715335/100
Open Issues31
Last Updated2026-08-16
Created2021-12-29
Platformscli, mcp, python
Est. Tokens~17k

FofaMap alternative? Top 6 similar tools

Looking for a FofaMap alternative? If you're comparing FofaMap with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • redamon by samugit83 · ⭐ 2.9k

    Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously

  • CyberStrike by CyberStrikeus · ⭐ 1.9k

    Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,

  • ARL-Next by owl234 · ⭐ 447

    现代化资产测绘与漏洞监控平台 (ARL-Next)。经典 ARL 架构重构,聚焦企业资产关联、异步解耦并发调度与原生 MCP 协议集成,容器化开箱部署。

  • AutoRedTeam-Orchestrator by Coff0xc · ⭐ 263

    MCP-native security automation workbench (SDK + CLI + MCP) — authorized testing + static AI/MCP attack-surface

  • mcp-security-hub by FuzzingLabs · ⭐ 792

    A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei,

  • python-utcp by universal-tool-calling-protocol · ⭐ 650

    Official python implementation of UTCP. UTCP is an open standard that lets AI agents call any API directly, wi

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is FofaMap?

FofaMap is 一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。. It is categorized as a MCP Server with 699 GitHub stars.

What programming language is FofaMap written in?

FofaMap is primarily written in Python. It covers topics such as ai-agent, asset-discovery, asset-mapping.

How do I install or use FofaMap?

You can find installation instructions and usage details in the FofaMap GitHub repository at github.com/asaotomo/FofaMap. The project has 699 stars and 93 forks, indicating an active community.

What license does FofaMap use?

FofaMap is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to FofaMap?

The top alternatives to FofaMap on Agent Skills Hub include redamon, CyberStrike, ARL-Next. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools