MCPVault

crlfuzz_scan

MCP tool from Tengu by rfunix

CRLF injection fuzzing for header injection vulnerabilities

How to use it

crlfuzz_scan is exposed by the Tengu MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the crlfuzz_scan tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.

Install Tengu

$claude mcp add --transport sse tengu http://localhost:8000/sse
FULL TENGU LISTING

Other tools in Tengu (39)

amass_enum

Attack surface mapping and DNS brute-force

analyze_headers

HTTP security headers analysis and grading

arjun_discover

Hidden HTTP parameter discovery

commix_scan

Automated command injection detection and exploitation

dns_enumerate

DNS record enumeration (A, MX, NS, TXT, SOA…)

dnsrecon_scan

DNS recon (zone transfer, brute-force, PTR)

dnstwist_scan

Domain permutation and typosquatting detection

feroxbuster_scan

Fast, recursive content discovery via brute-force

ffuf_fuzz

Directory, parameter, and vhost fuzzing

gobuster_scan

Directory, DNS, and vhost brute-force

gowitness_screenshot

Web screenshot capture for documentation

graphql_security_check

GraphQL introspection, batching, depth limit, field suggestions

httpx_probe

HTTP probe — status codes, tech stack, redirects

httrack_mirror

Full website mirror for offline analysis and forensics

katana_crawl

Fast web crawler for link discovery and endpoint mapping

masscan_scan

High-speed port scanner for large networks

msf_module_info

Get detailed Metasploit module information

msf_run_module

Execute a Metasploit module (requires explicit confirmation)

msf_search

Search Metasploit modules

msf_session_cmd

Execute a command on an active session (shell/Meterpreter)

msf_sessions_list

List active Metasploit sessions

nikto_scan

Web server misconfiguration and outdated software scanner

nmap_scan

Port scanning and service/OS detection

nuclei_scan

Template-based vulnerability scanner (CVEs, misconfigs)

rustscan_scan

Ultra-fast port scanning (finds open ports for Nmap follow-up)

shodan_lookup

Shodan host and asset search

snmpwalk_scan

SNMP enumeration and MIB walking

sqlmap_scan

Automated SQL injection detection and exploitation

ssl_tls_check

SSL/TLS certificate and cipher check (sslyze)

subfinder_enum

Passive subdomain enumeration

subjack_check

Subdomain takeover detection

test_cors

CORS misconfiguration detection

testssl_check

Comprehensive SSL/TLS configuration analysis

theharvester_scan

Email, subdomain, and host enumeration from public sources

wafw00f_scan

Web Application Firewall detection and fingerprinting

whatweb_scan

Web technology fingerprinting (CMS, WAF, frameworks)

whois_lookup

WHOIS domain and IP lookup

wpscan_scan

WordPress vulnerability scanner

xss_scan

XSS detection via Dalfox