Tengu
UnclaimedAI-powered penetration testing MCP server
Install
claude mcp add --transport sse tengu http://localhost:8000/sseSet up this server
More in Security
Browse the full directoryUnclaimed listing
Is this your MCP server?
This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.
Claim this serverSecurity profile
Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works
40 of 40 tools
Documented tools (40)
From project documentation. A server handshake does not verify each tool’s description or behavior.
amass_enum
Attack surface mapping and DNS brute-force
analyze_headers
HTTP security headers analysis and grading
arjun_discover
Hidden HTTP parameter discovery
commix_scan
Automated command injection detection and exploitation
crlfuzz_scan
CRLF injection fuzzing for header injection vulnerabilities
dns_enumerate
DNS record enumeration (A, MX, NS, TXT, SOA…)
dnsrecon_scan
DNS recon (zone transfer, brute-force, PTR)
dnstwist_scan
Domain permutation and typosquatting detection
feroxbuster_scan
Fast, recursive content discovery via brute-force
ffuf_fuzz
Directory, parameter, and vhost fuzzing
gobuster_scan
Directory, DNS, and vhost brute-force
gowitness_screenshot
Web screenshot capture for documentation
graphql_security_check
GraphQL introspection, batching, depth limit, field suggestions
httpx_probe
HTTP probe — status codes, tech stack, redirects
httrack_mirror
Full website mirror for offline analysis and forensics
katana_crawl
Fast web crawler for link discovery and endpoint mapping
masscan_scan
High-speed port scanner for large networks
msf_module_info
Get detailed Metasploit module information
msf_run_module
Execute a Metasploit module (requires explicit confirmation)
msf_search
Search Metasploit modules
msf_session_cmd
Execute a command on an active session (shell/Meterpreter)
msf_sessions_list
List active Metasploit sessions
nikto_scan
Web server misconfiguration and outdated software scanner
nmap_scan
Port scanning and service/OS detection
nuclei_scan
Template-based vulnerability scanner (CVEs, misconfigs)
rustscan_scan
Ultra-fast port scanning (finds open ports for Nmap follow-up)
shodan_lookup
Shodan host and asset search
snmpwalk_scan
SNMP enumeration and MIB walking
sqlmap_scan
Automated SQL injection detection and exploitation
ssl_tls_check
SSL/TLS certificate and cipher check (sslyze)
subfinder_enum
Passive subdomain enumeration
subjack_check
Subdomain takeover detection
test_cors
CORS misconfiguration detection
testssl_check
Comprehensive SSL/TLS configuration analysis
theharvester_scan
Email, subdomain, and host enumeration from public sources
wafw00f_scan
Web Application Firewall detection and fingerprinting
whatweb_scan
Web technology fingerprinting (CMS, WAF, frameworks)
whois_lookup
WHOIS domain and IP lookup
wpscan_scan
WordPress vulnerability scanner
xss_scan
XSS detection via Dalfox
Tool change history
FAQ
Questions about Tengu MCP Server
- How do I connect Tengu MCP Server to Claude?
- The listing records `claude mcp add --transport sse tengu http://localhost:8000/sse` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Desktop, Claude Code as compatible clients.
- Is Tengu MCP Server free?
- The listed licence is MIT. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
- What can Tengu MCP Server do?
- Tengu MCP Server documents 40 tools to the agent, including amass_enum, analyze_headers, arjun_discover. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.