{"repo":"hoodoer/MCP-ASD","free":true,"listed":false,"github":"https://github.com/hoodoer/MCP-ASD","clone":"git clone https://github.com/hoodoer/MCP-ASD.git","description":"MCP Attack Surface Detector - Burp plugin to make manual testing of MCP servers easier in Burp Suite","language":"Java","stars":32,"topics":[],"license":null,"category":"mcp-servers","readme_excerpt":"MCP Attack Surface Detector (MCP-ASD) Version: 1.0.2 MCP-ASD is a Burp Suite extension (Montoya API) designed to identify, map, and test the attack surface of Model Context Protocol (MCP) servers. It provides a bridge between Burp's synchronous testing tools (Repeater, Intruder, Scanner) and the asynchronous, persistent nature of MCP connections (SSE & WebSockets). This allows security professionals to audit MCP Tools, Resources, and Prompts using standard web testing workflows. Features - Multi-Protocol Support: Full support for Server-Sent Events (SSE), WebSockets (ws/wss), and HTTP POST-only transport (for servers that don't support GET/SSE). - Endpoint Auto-Discovery: Automated detection of MCP endpoints, including detection of protected endpoints that require authentication. - Attack Surface Enumeration: Automatically discovers and visualizes Tools, Resources, and Prompts, including schema extraction for arguments. - Synchronous Bridging: Enables seamless use of Burp Repeater and Intruder by handling asynchronous ID correlation and session management. - Prototype Generation: Automatically generates valid JSON-RPC payloads based on discovered tool schemas. - Authentication & mTLS: Support for custom HTTP headers (OAuth Bearer tokens, API keys) and mTLS client certificates (PKCS#12). - Native Integration: Reports discovered MCP servers directly to Burp's Target and Dashboard . - Advanced Detection: Includes passive monitoring and active probing for MCP servers on discovere","default_branch":null,"files":null,"tree":[],"storefront":"/r/hoodoer","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/hoodoer/MCP-ASD/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}