Tengu logo

Tengu

未认领

作者:rfunix

AI-powered penetration testing MCP server

mcpmcp-serverpentestingsecurityai-securityclaudecybersecurityethical-hackinginfoseckali-linux

安装

$claude mcp add --transport sse tengu http://localhost:8000/sse

此服务器需要专门配置。目前没有可复用的公开启动命令,请遵循项目说明。

项目说明

更多Security服务器

浏览完整目录

未认领列表

这个 MCP 服务器是你的吗?

此列表根据公开信息自动生成。认领后,你可以编辑页面、设置兼容性并解锁增长工具。全程不超两分钟。

认领此服务器

安全概况

已认领和已认证的服务器每周接受一次静态扫描,显示代码能触及的范围(外部服务、环境变量、shell 命令、代理配置目录)以及带有已知公告的依赖。认领此列表即可获得。 安全概况的工作原理

40 个工具中显示 40 个

文档中列出的工具 (40)

内容来自项目文档。服务器握手不会验证每个工具的说明或行为。

amass_enum

Attack surface mapping and DNS brute-force

analyze_headers

HTTP security headers analysis and grading

arjun_discover

Hidden HTTP parameter discovery

commix_scan

Automated command injection detection and exploitation

crlfuzz_scan

CRLF injection fuzzing for header injection vulnerabilities

dns_enumerate

DNS record enumeration (A, MX, NS, TXT, SOA…)

dnsrecon_scan

DNS recon (zone transfer, brute-force, PTR)

dnstwist_scan

Domain permutation and typosquatting detection

feroxbuster_scan

Fast, recursive content discovery via brute-force

ffuf_fuzz

Directory, parameter, and vhost fuzzing

gobuster_scan

Directory, DNS, and vhost brute-force

gowitness_screenshot

Web screenshot capture for documentation

graphql_security_check

GraphQL introspection, batching, depth limit, field suggestions

httpx_probe

HTTP probe — status codes, tech stack, redirects

httrack_mirror

Full website mirror for offline analysis and forensics

katana_crawl

Fast web crawler for link discovery and endpoint mapping

masscan_scan

High-speed port scanner for large networks

msf_module_info

Get detailed Metasploit module information

msf_run_module

Execute a Metasploit module (requires explicit confirmation)

msf_search

Search Metasploit modules

msf_session_cmd

Execute a command on an active session (shell/Meterpreter)

msf_sessions_list

List active Metasploit sessions

nikto_scan

Web server misconfiguration and outdated software scanner

nmap_scan

Port scanning and service/OS detection

nuclei_scan

Template-based vulnerability scanner (CVEs, misconfigs)

rustscan_scan

Ultra-fast port scanning (finds open ports for Nmap follow-up)

shodan_lookup

Shodan host and asset search

snmpwalk_scan

SNMP enumeration and MIB walking

sqlmap_scan

Automated SQL injection detection and exploitation

ssl_tls_check

SSL/TLS certificate and cipher check (sslyze)

subfinder_enum

Passive subdomain enumeration

subjack_check

Subdomain takeover detection

test_cors

CORS misconfiguration detection

testssl_check

Comprehensive SSL/TLS configuration analysis

theharvester_scan

Email, subdomain, and host enumeration from public sources

wafw00f_scan

Web Application Firewall detection and fingerprinting

whatweb_scan

Web technology fingerprinting (CMS, WAF, frameworks)

whois_lookup

WHOIS domain and IP lookup

wpscan_scan

WordPress vulnerability scanner

xss_scan

XSS detection via Dalfox

工具变更历史

比较相同配置的完整检查。只列出工具,未调用工具。此处不测量输入结构的变化。

尚无完整工具检查。