commix_scan
Automated command injection detection and exploitation
How to use it
Project documentation lists commix_scan for the Tengu MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), then check which tools your installed version makes available. Tool availability can depend on configuration and credentials. A server handshake does not verify this tool’s behavior. See the full listing for setup details.
Install Tengu
claude mcp add --transport sse tengu http://localhost:8000/sseOther tools in Tengu (39)
Attack surface mapping and DNS brute-force
HTTP security headers analysis and grading
Hidden HTTP parameter discovery
CRLF injection fuzzing for header injection vulnerabilities
DNS record enumeration (A, MX, NS, TXT, SOA…)
DNS recon (zone transfer, brute-force, PTR)
Domain permutation and typosquatting detection
Fast, recursive content discovery via brute-force
Directory, parameter, and vhost fuzzing
Directory, DNS, and vhost brute-force
Web screenshot capture for documentation
GraphQL introspection, batching, depth limit, field suggestions
HTTP probe — status codes, tech stack, redirects
Full website mirror for offline analysis and forensics
Fast web crawler for link discovery and endpoint mapping
High-speed port scanner for large networks
Get detailed Metasploit module information
Execute a Metasploit module (requires explicit confirmation)
Search Metasploit modules
Execute a command on an active session (shell/Meterpreter)
List active Metasploit sessions
Web server misconfiguration and outdated software scanner
Port scanning and service/OS detection
Template-based vulnerability scanner (CVEs, misconfigs)
Ultra-fast port scanning (finds open ports for Nmap follow-up)
Shodan host and asset search
SNMP enumeration and MIB walking
Automated SQL injection detection and exploitation
SSL/TLS certificate and cipher check (sslyze)
Passive subdomain enumeration
Subdomain takeover detection
CORS misconfiguration detection
Comprehensive SSL/TLS configuration analysis
Email, subdomain, and host enumeration from public sources
Web Application Firewall detection and fingerprinting
Web technology fingerprinting (CMS, WAF, frameworks)
WHOIS domain and IP lookup
WordPress vulnerability scanner
XSS detection via Dalfox