MCPVault
GEMMA By GOOGLE logo

GEMMA By GOOGLE

Unclaimed

by XenoCoreGiger31

A fully local, autonomous AI penetration-testing agent powered by Gemma 4-12B and a Flask MCP tool server. Runs recon, attack loops, and report generation on its own — no cloud, no API keys. For authorized security testing only.

autonomous-ai-agentscybersecurityethical-hackingexploitationgemmakali-linuxllmspenetration-testingpythonrecon

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Tools (40)

run_amass

Subdomain enumeration (passive by default)

run_cloudfox

Cloud-infrastructure enumeration

run_command

Arbitrary command execution

run_curl

HTTP request testing

run_dalfox

XSS scanning (reflected / stored / DOM)

run_dnsx

DNS resolution and probing

run_enum4linux

SMB / Samba enumeration

run_exploit

Sandboxed execution of custom PoC scripts

run_feroxbuster

Recursive content discovery

run_ffuf

Web fuzzing

run_gau

Known URLs from OTX / Wayback / Common Crawl

run_ghosttrack

OSINT for username / IP / phone

run_gobuster

Web directory brute forcing

run_gowitness

Web screenshotting for visual recon

run_httpx

HTTP probing and fingerprinting

run_hydra

Credential brute forcing

run_john

Hash cracking

run_katana

Web crawling

run_masscan

Fast port discovery

run_medusa

Fast parallel brute forcing

run_metasploit

Fire a chosen Metasploit module at a target (human-approved)

run_ncrack

Network authentication cracking

run_netstat

Network connection analysis

run_nikto

Web vulnerability scanning

run_nmap

Deep service/version scanning

run_nuclei

Template-based vulnerability scanning

run_phoneinfoga

Phone-number OSINT

run_phonextract

Phone-number OSINT / extraction

run_recon_ng

recon-ng OSINT framework (non-interactive)

run_searchsploit

Exploit lookup

run_setoolkit

Social-engineering toolkit

run_sherlock

Username OSINT across 90+ platforms

run_shodan

Internet-exposure intelligence lookups

run_spiderfoot

Headless multi-module OSINT scanning

run_sqlmap

SQL injection testing

run_subfinder

Subdomain enumeration

run_theharvester

Passive OSINT — emails, subdomains, hosts

run_wafw00f

WAF / security-solution fingerprinting

run_waybackurls

Historical URLs from the Wayback Machine

run_wget

File retrieval