{"repo":"DMontgomery40/pentest-mcp","free":true,"listed":false,"github":"https://github.com/DMontgomery40/pentest-mcp","clone":"git clone https://github.com/DMontgomery40/pentest-mcp.git","description":"NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR, hashcat, wordlist building, and more.","language":"JavaScript","stars":141,"topics":["cybersecurity","dirbuster","gobuster","john-the-ripper","jtr","mcp","mcp-server","model-context-protocol","nikto","nmap"],"license":"MIT","category":"mcp-servers","readme_excerpt":"Pentest MCP Professional penetration-testing MCP server with modern transport/auth support and expanded recon tooling. What Changed in 0.9.0 - Upgraded MCP SDK to @modelcontextprotocol/sdk@^1.26.0 - Kept MCP Inspector at the latest release ( @modelcontextprotocol/inspector@^0.20.0 ) with bundled launcher - Streamable HTTP is now the primary network transport ( MCP TRANSPORT=http ) - SSE is still available only as a deprecated compatibility mode - Added bearer-token auth with OIDC JWKS and introspection support - Added first-class tools: subfinderEnum , httpxProbe , ffufScan , nucleiScan , trafficCapture , hydraBruteforce , privEscAudit , extractionSweep - Added report-admin tools: listEngagementRecords , getEngagementRecord - Added SoW capture flow for reports using MCP elicitation ( scopeMode=ask ) with safe template fallback - Hardened command resolution so web probing uses httpx-toolkit (preferred) or validated ProjectDiscovery httpx , avoiding Python httpx CLI collisions - Integrated bundled MCP Inspector launcher ( pentest-mcp inspector ) - Runtime baseline is now Node.js 22.7.5+ - Added invocation metadata in new tool outputs when auth/session context is available Included Tools - nmapScan - runJohnTheRipper - runHashcat - gobuster - nikto - subfinderEnum - httpxProbe - ffufScan - nucleiScan - trafficCapture - hydraBruteforce - privEscAudit - extractionSweep - generateWordlist - listEngagementRecords - getEngagementRecord - createClientReport - cancelScan Quick Start In","default_branch":null,"files":null,"tree":[],"storefront":"/r/DMontgomery40","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/DMontgomery40/pentest-mcp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}