No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by shinthink · MCP Server · ★ 637
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is blitzstrike safe to install? View the security audit →
Blitz Strike Reconnaissance at speed. Analysis in depth. Validation before report. Blitz Strike is a structured penetration-testing methodology — reconnaissance, source analysis, and validation — delivered as a universal MCP server. It enumerates the attack surface (BLITZ), traces source-to-sink reachability (EAGLE-EYE), and verifies each finding live before it is reported (STRIKE). One server, every agent: scope enforcement
| Stars | 637 |
| Forks | 1 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 65.2100215658149/100 |
| Last Updated | 2026-09-19 |
| Created | 2026-09-12 |
| Platforms | mcp, node |
| Est. Tokens | ~18k |
Looking for a blitzstrike alternative? If you're comparing blitzstrike with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
Open source autonomous AI penetration testing platform. 50+ specialist agents for AI security testing across w
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei,
现代化资产测绘与漏洞监控平台 (ARL-Next)。经典 ARL 架构重构,聚焦企业资产关联、异步解耦并发调度与原生 MCP 协议集成,容器化开箱部署。
Explore other popular mcp server tools:
blitzstrike is ⚡ Blitz Strike — a universal MCP penetration-testing toolbelt. Structured methodology: reconnaissance & attack-surface mapping, source-to-sink analysis, and live validation. 57 escalation chains, 130-. It is categorized as a MCP Server with 637 GitHub stars.
blitzstrike is primarily written in TypeScript. It covers topics such as active-directory, blue-team, bug-bounty.
You can find installation instructions and usage details in the blitzstrike GitHub repository at github.com/shinthink/blitzstrike. The project has 637 stars and 1 forks, indicating an active community.
blitzstrike is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to blitzstrike on Agent Skills Hub include CyberStrike, pentest-ai-agents, pentest-ai. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: