mcpbeat Sign in

Operant MCP Server

by operantlabs Your server? Claim it
local only

Operant MCP runs on your own machine — the client starts it, so there is no endpoint to ping. 49 installs a week from npm. Last commit 1 Apr 2026.

Security testing MCP server for penetration testing, forensics, and vulnerability assessment

Installs per day peak 13 · avg 7 · -44% w/w
a month agotoday
49
Installs / week
npm · operant-mcp
23
Stars
1 open issues
1 Apr 2026
Last commit
0 releases in 90 days
MIT
License
TypeScript

What the code does

We read the source, 21 h ago · rules 3dff92dd89df

Capabilities

What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.

    const path = execSync(`which ${name}`, { encoding: "utf-8" }).trim();
Touches key and credential files src/prompts.ts:798, src/resources.ts:474
- Check /etc/shadow access in file operations.

Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.

This code can reach further than it looks

We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.

Three servers free · no card

Connect this server

This server runs on your own machine — install it with the package manager and the client starts it for you. Package name taken from the official registry entry.

run in your terminal
claude mcp add operant-mcp -- npx -y operant-mcp
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "operant-mcp": {
      "args": [
        "-y",
        "operant-mcp"
      ],
      "command": "npx"
    }
  }
}
~/.codex/config.toml
[mcp_servers.operant-mcp]
command = "npx"
args = ["-y", "operant-mcp"]
.cursor/mcp.json
{
  "mcpServers": {
    "operant-mcp": {
      "args": [
        "-y",
        "operant-mcp"
      ],
      "command": "npx"
    }
  }
}
.vscode/mcp.json
{
  "mcpServers": {
    "operant-mcp": {
      "args": [
        "-y",
        "operant-mcp"
      ],
      "command": "npx"
    }
  }
}

Alternatives to Operant MCP

same job, measured the same way
Vulnicheck
by andrasfe

HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.

local only
Bawbel Scanner
by bawbel

Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

176 installs/wk local only
Bawbel Scanner
by bawbel

Security scanner for MCP servers and skill files. Detects AVE vulnerabilities before production.

local only
Snyk API & Web MCP Server
by snyk

MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage

96 installs/wk local only
npm MCP
by alisaitteke

MCP server for npm package management, security analysis, and compatibility checking

32 installs/wk local only
MCP Server for OSCAL
by awslabs

AI agent tools for Open Security Controls Assessment Language (OSCAL)

156 installs/wk local only
Web Recon Agent
by joepangallo

Owned-target web security assessment MCP server for authenticated, high-friction apps.

17 installs/wk local only
Bright Security
by neuralegion

AI-powered application security testing — scan APIs, discover endpoints, and find vulnerabilities.

answering

Operant MCP — questions

Answers built from our own checks of this server.

Why is there no uptime for Operant MCP?
Operant MCP runs on your own machine over stdio — there is no network address to reach, so uptime cannot be measured for it by anyone. What can be measured is adoption: the npm package operant-mcp was installed 49 times last week.
How do I connect Operant MCP?
Copy the ready config from this page — we generate it for Claude Code, Claude Desktop, Codex, Cursor and VS Code, each with the file path that client actually reads. It runs locally, so the command pulls operant-mcp straight from npm; nothing to host, nothing to sign up for.
How many people use Operant MCP?
The npm package operant-mcp was installed 49 times in the last week. Week over week that is -44%. We show installs rather than GitHub stars on purpose: a star is a bookmark, an install is someone actually running it.
Is Operant MCP open source?
Yes — it is published under the MIT licence, written in TypeScript, 23 stars on GitHub and 1 open issue. The source link is on this page, so you can read exactly what it does with your data before you connect it.