Pentest MCP Server is answering right now. Last checked 13 min ago. 81 installs a week from npm. It exposes 7 tools. Last commit 22 Aug 2026.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 22 August 2026. No other catalogue keeps this.
We read the source, 19 h ago · tools taken from the live server · rules 3dff92dd89df
Things with no honest explanation: a promise that contradicts the code, code that runs at install time while hiding what it does, data leaving the machine.
'AWS: 169.254.169.254/latest/meta-data/ → /latest/meta-data/iam/security-credentials/. GCP: 169.254.169.254/computeMetadata/v1/ (requires Metadata-Flavor: Google header). Azure: 169.254.169.254/metadata/instance?api-version=2021-02-01 (requires Metadata: true header).',
'AWS: 169.254.169.254/latest/meta-data/ → /latest/meta-data/iam/security-credentials/. GCP: 169.254.169.254/computeMetadata/v1/ (requires Metadata-Flavor: Google header). Azure: 169.254.169.254/metadata/instance?api-version=2021-02-01 (requires Metadata: true header).',
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
Code changes quietly between releases, and nobody reads the diff of a dependency. We do, on every release — watch Pentest MCP Server and you get told the day something new turns up.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 13 min ago.
claude mcp add pentest-mcp-server --transport http https://pentest.caseyjhand.com/mcp
{
"mcpServers": {
"pentest-mcp-server": {
"url": "https://pentest.caseyjhand.com/mcp"
}
}
}
[mcp_servers.pentest-mcp-server]
url = "https://pentest.caseyjhand.com/mcp"
{
"mcpServers": {
"pentest-mcp-server": {
"url": "https://pentest.caseyjhand.com/mcp"
}
}
}
{
"mcpServers": {
"pentest-mcp-server": {
"url": "https://pentest.caseyjhand.com/mcp"
}
}
}
This one needs environment variables set before it will start:
MCP_HTTP_HOST (The hostname for the HTTP server.), MCP_HTTP_PORT (The port to run the HTTP server on.), MCP_HTTP_ENDPOINT_PATH (The endpoint path for the MCP server.), MCP_AUTH_MODE (Authentication mode to use: 'none', 'jwt', or 'oauth'.), MCP_LOG_LEVEL (Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').).
The author declared them in the registry entry; get the values from the project itself.
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
pentest_analyze_response
pentest_encode
pentest_generate_payloads
pentest_guide
pentest_lookup_group
pentest_lookup_technique
pentest_map_techniques
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://pentest.caseyjhand.com/mcp | streamable-http | answering | 400 ms | 13 min ago |
Authorization-gated MCP server to discover and run 670+ security tools for CTF, pentest, and DFIR.
Security testing MCP server for penetration testing, forensics, and vulnerability assessment
AI-callable tools for API mocking, testing, monitoring, security, and automation.
AI-driven penetration testing - 22 security tools behind safety-hardened MCP endpoints
Remote MCP security gateway for auth, redaction, policy enforcement, and audit logging.
MCP server for Niubiz — Peru card acquirer: security token, session, authorize, reverse
🔍 Read-only MCP server for secure filesystem exploration, searching, and analysis
Paid AI utilities for web comparison, code checks, document extraction, security, and research.
Answers built from our own checks of this server.