{"repo":"nedlir/MCPwner","free":true,"listed":false,"github":"https://github.com/nedlir/MCPwner","clone":"git clone https://github.com/nedlir/MCPwner.git","description":"Model Context Protocol server for autonomous vulnerability discovery","language":"Python","stars":54,"topics":[],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"MCPwner Beware the Badger Model Context Protocol server for autonomous security research Compatible with: --- Table of Contents - Overview - Workflow - Integrated Tools - Installation - Documentation - Architecture - Data Persistence - License Overview MCPwner is an MCP server that gives your LLM agent a full offensive-security toolkit. It exposes 55+ containerized tools through a single MCP interface - SAST, SCA, secrets, IaC, reconnaissance, DAST, coverage-guided fuzzing, CodeQL (builtin and custom queries), a headless browser, an OOB callback server, a PoC-script sandbox with deterministic oracles, and a persistent findings ledger. The architecture is designed for agent-driven vulnerability research : a single agent session - model-agnostic (Claude, Cursor, Kiro, Gemini, or any MCP-capable coding agent) - works through the research phases (recon, code audit, PoC validation, adversarial review), recording every step in the shared findings ledger. Each finding progresses from hypothesis through empirical proof to verified report - \"no exploit, no report.\" Note : This project is under active development. Learn more about MCPs here. Workflow MCPwner is the tool server; your LLM agent is the brain. A typical deep-research engagement: Phase What happens MCPwner tools used ------------- ----------------------------------------------- ------------------------------------------------------------------------------------------------ Workspace Clone target, detect stack create workspa","default_branch":null,"files":null,"tree":[],"storefront":"/r/nedlir","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nedlir/MCPwner/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}