AynOps
未认领An Open Sourced Model Context Protocol (MCP) Local server that gives AI Clients real-time cybersecurity reconnaissance capabilities
安装
docker run --rm -i aynops更多AI & ML服务器
浏览完整目录安全概况
已认领和已认证的服务器每周接受一次静态扫描,显示代码能触及的范围(外部服务、环境变量、shell 命令、代理配置目录)以及带有已知公告的依赖。认领此列表即可获得。 安全概况的工作原理
16 个工具中显示 16 个
文档中列出的工具 (16)
内容来自项目文档。服务器握手不会验证每个工具的说明或行为。
asn_lookup
Autonomous System Number (ASN) and network ownership lookup via Team Cymru WHOIS — identifies ASN, BGP prefix, organization, registry, country, and allocation date for domains or IP addresses (no API key required)
cert_transparency
Query crt.sh Certificate Transparency logs for a domain and extract certificate, subdomain, and wildcard information
cloud_exposure_check
Checks for publicly accessible AWS S3, Azure Blob Storage, and Google Cloud Storage buckets using common bucket naming patterns derived from the target domain
cve_lookup
Search NVD for known CVEs by software name and version (no API key required)
dns_enumeration
A, AAAA, MX, NS, TXT, CNAME, SOA, CAA, and common SRV records (SIP, LDAP, XMPP, Kerberos, Autodiscover) + common subdomain brute-forcing
email_security_check
Checks SPF, DKIM, and DMARC DNS records — returns a securityscore, rating, and actionable recommendations for missing or weak configurations
full_recon
Runs all core tools in parallel and returns combined result
headers_analyzer
Analyzes HTTP security headers — checks HSTS, CSP, X-Frame-Options, and more with severity ratings and misconfiguration details
hibp_check
Check if an email or domain appears in Have I Been Pwned breaches (HIBPAPIKEY required)
ip_reputation
Check if an IP is flagged as malicious via AbuseIPDB (api key requied)
port_scan
Nmap-powered scanner with service/version detection and security warnings
robots_txt_inspect
Fetch and parse robots.txt to reveal hidden directories and sitemaps
ssl_inspect
SSL/TLS certificate — issuer, expiry, cipher strength, SANs, TLS version
tech_stack_detect
Web server, CMS, JS frameworks, CDN, and analytics
trace_redirects
Traces the full HTTP redirect chain hop by hop — flags TLS downgrades, private-IP leaks, redirect loops, cross-domain hops, and overly long chains
whois_lookup
Domain registration data — owner, registrar, creation date, expiry, name servers