Pentest MCP Server
by cyanheadsio.github.cyanheads/pentest-mcp-serverv0.1.9
Offline methodology engine for authorized penetration testing, CTF, and security research.
context tax
queued
security
queued
cold start
queued
freshness
Active19d ago
Install Pentest MCP server
Install in Claude Code
claude mcp add pentest -- npx -y @cyanheads/pentest-mcp-server run start:stdioInstall in Cursor
{
"mcpServers": {
"pentest": {
"command": "npx",
"args": [
"-y",
"@cyanheads/pentest-mcp-server",
"run",
"start:stdio"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"pentest": {
"command": "npx",
"args": [
"-y",
"@cyanheads/pentest-mcp-server",
"run",
"start:stdio"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"pentest": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@cyanheads/pentest-mcp-server",
"run",
"start:stdio"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"pentest": {
"command": "npx",
"args": [
"-y",
"@cyanheads/pentest-mcp-server",
"run",
"start:stdio"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| MCP_LOG_LEVEL | — | — | Sets the minimum log level for output (e.g., 'debug', 'info', 'warn'). |
| MCP_HTTP_HOST | — | — | The hostname for the HTTP server. |
| MCP_HTTP_PORT | — | — | The port to run the HTTP server on. |
| MCP_HTTP_ENDPOINT_PATH | — | — | The endpoint path for the MCP server. |
| MCP_AUTH_MODE | — | — | Authentication mode to use: 'none', 'jwt', or 'oauth'. |
Remote endpoints
- streamable-http
https://pentest.caseyjhand.com/mcp
Freshness
Active — last maintenance signal 19d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-20 · 19d ago · GitHub
Latest release
2026-09-20 · 19d ago · GitHub · v0.1.9
Package published
no data · npm/PyPI
Registry entry updated
2026-09-20 · 19d ago · official registry · v0.1.9
FAQ
›How do I install the Pentest MCP server in Claude Code?
Run: claude mcp add pentest -- npx -y @cyanheads/pentest-mcp-server run start:stdio. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Pentest require an API key?
No required environment variables are declared in its published metadata.
›Can I use Pentest as a remote (hosted) MCP server?
Yes — it offers both a hosted endpoint and a local stdio package.
›Is Pentest in the official MCP registry?
Yes, as io.github.cyanheads/pentest-mcp-server.
Alternatives to Pentest
Other security MCP servers.