Attack Surface MCP Server
by cyanheadsio.github.cyanheads/attack-surface-mcp-serverv0.2.3
Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
context tax
queued
security
queued
cold start
queued
freshness
Active10d ago
Install Attack Surface MCP server
Install in Claude Code
claude mcp add attack-surface-cyanheads -e SHODAN_API_KEY='<shodan-api-key>' -e CERTSPOTTER_API_KEY='<certspotter-api-key>' -- npx -y @cyanheads/attack-surface-mcp-server run start:stdioInstall in Cursor
{
"mcpServers": {
"attack-surface-cyanheads": {
"command": "npx",
"args": [
"-y",
"@cyanheads/attack-surface-mcp-server",
"run",
"start:stdio"
],
"env": {
"SHODAN_API_KEY": "<shodan-api-key>",
"CERTSPOTTER_API_KEY": "<certspotter-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"attack-surface-cyanheads": {
"command": "npx",
"args": [
"-y",
"@cyanheads/attack-surface-mcp-server",
"run",
"start:stdio"
],
"env": {
"SHODAN_API_KEY": "<shodan-api-key>",
"CERTSPOTTER_API_KEY": "<certspotter-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"attack-surface-cyanheads": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@cyanheads/attack-surface-mcp-server",
"run",
"start:stdio"
],
"env": {
"SHODAN_API_KEY": "<shodan-api-key>",
"CERTSPOTTER_API_KEY": "<certspotter-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"attack-surface-cyanheads": {
"command": "npx",
"args": [
"-y",
"@cyanheads/attack-surface-mcp-server",
"run",
"start:stdio"
],
"env": {
"SHODAN_API_KEY": "<shodan-api-key>",
"CERTSPOTTER_API_KEY": "<certspotter-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| SHODAN_API_KEY | — | yes | Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works. |
| CERTSPOTTER_API_KEY | — | yes | Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier. |
| ATTACKSURFACE_DEFAULT_RESOLVERS | — | — | Comma-separated default DNS resolver IPs for attacksurface_resolve_dns. |
| ATTACKSURFACE_HTTP_USER_AGENT | — | — | Default User-Agent for attacksurface_probe_http (overridable per call). |
| ATTACKSURFACE_MAX_SUBDOMAINS | — | — | Cap on subdomains resolved during a map_domain run. |
| ATTACKSURFACE_RDAP_BOOTSTRAP_URL | — | — | RDAP bootstrap base URL; override for a private/mirrored RDAP. |
| ATTACKSURFACE_ALLOW_PRIVATE_TARGETS | — | — | Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only). |
| MCP_LOG_LEVEL | — | — | Sets the minimum log level for output (e.g., 'debug', 'info', 'warn'). |
| MCP_HTTP_HOST | — | — | The hostname for the HTTP server. |
| MCP_HTTP_PORT | — | — | The port to run the HTTP server on. |
| MCP_HTTP_ENDPOINT_PATH | — | — | The endpoint path for the MCP server. |
| MCP_AUTH_MODE | — | — | Authentication mode to use: 'none', 'jwt', or 'oauth'. |
Freshness
Active — last maintenance signal 10d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-30 · 10d ago · GitHub
Latest release
2026-09-30 · 10d ago · GitHub · v0.2.3
Package published
no data · npm/PyPI
Registry entry updated
2026-09-30 · 10d ago · official registry · v0.2.3
FAQ
›How do I install the Attack Surface MCP server in Claude Code?
Run: claude mcp add attack-surface-cyanheads -e SHODAN_API_KEY='<shodan-api-key>' -e CERTSPOTTER_API_KEY='<certspotter-api-key>' -- npx -y @cyanheads/attack-surface-mcp-server run start:stdio. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Attack Surface require an API key?
Yes. It expects SHODAN_API_KEY, CERTSPOTTER_API_KEY, of which 2 are secrets.
›Can I use Attack Surface as a remote (hosted) MCP server?
Yes — it offers both a hosted endpoint and a local stdio package.
›Is Attack Surface in the official MCP registry?
Yes, as io.github.cyanheads/attack-surface-mcp-server.