Skip to content
mcp/skillhub

Attack Surface MCP Server

by cyanheadsio.github.cyanheads/attack-surface-mcp-serverv0.2.3

Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.

1Node.jsstdioremoteofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active10d ago

Install Attack Surface MCP server

Install in Claude Code

claude mcp add attack-surface-cyanheads -e SHODAN_API_KEY='<shodan-api-key>' -e CERTSPOTTER_API_KEY='<certspotter-api-key>' -- npx -y @cyanheads/attack-surface-mcp-server run start:stdio

Configuration

VariableRequiredSecretDescription
SHODAN_API_KEY—yesOptional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.
CERTSPOTTER_API_KEY—yesOptional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.
ATTACKSURFACE_DEFAULT_RESOLVERS——Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.
ATTACKSURFACE_HTTP_USER_AGENT——Default User-Agent for attacksurface_probe_http (overridable per call).
ATTACKSURFACE_MAX_SUBDOMAINS——Cap on subdomains resolved during a map_domain run.
ATTACKSURFACE_RDAP_BOOTSTRAP_URL——RDAP bootstrap base URL; override for a private/mirrored RDAP.
ATTACKSURFACE_ALLOW_PRIVATE_TARGETS——Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).
MCP_LOG_LEVEL——Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').
MCP_HTTP_HOST——The hostname for the HTTP server.
MCP_HTTP_PORT——The port to run the HTTP server on.
MCP_HTTP_ENDPOINT_PATH——The endpoint path for the MCP server.
MCP_AUTH_MODE——Authentication mode to use: 'none', 'jwt', or 'oauth'.

Freshness

Active — last maintenance signal 10d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-09-30 · 10d ago · GitHub

  2. Latest release

    2026-09-30 · 10d ago · GitHub · v0.2.3

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-30 · 10d ago · official registry · v0.2.3

FAQ

›How do I install the Attack Surface MCP server in Claude Code?

Run: claude mcp add attack-surface-cyanheads -e SHODAN_API_KEY='<shodan-api-key>' -e CERTSPOTTER_API_KEY='<certspotter-api-key>' -- npx -y @cyanheads/attack-surface-mcp-server run start:stdio. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Attack Surface require an API key?

Yes. It expects SHODAN_API_KEY, CERTSPOTTER_API_KEY, of which 2 are secrets.

›Can I use Attack Surface as a remote (hosted) MCP server?

Yes — it offers both a hosted endpoint and a local stdio package.

›Is Attack Surface in the official MCP registry?

Yes, as io.github.cyanheads/attack-surface-mcp-server.