Comprehensive Model Context Protocol server providing extensive pentesting and reconnaissance tools
Description: Returns IPv4 addresses (A records) for a domain.
Description: Returns mail exchange (MX) records for a domain.
Description: Returns TXT records for a domain.
Description: Returns CNAME records for a domain.
Description: Returns nameserver (NS) records for a domain.
Description: Checks for SPF, DKIM, and DMARC records for a domain using DNS TXT lookups.
Description: Checks which subdomains of a given domain resolve.
Description: Checks for common takeover risk patterns on a domain.
Description: Searches for subdomains of a given domain from crt.sh.
Description: Simulates a DNS zone transfer attempt to check for vulnerabilities.
Description: Reports on the presence/absence of important security headers for a URL.
Description: Retrieves SSL certificate details for a domain.
Description: Scans common ports on a given host.
Description: Retrieves server and powered-by information from a given URL.
Description: Checks if directory listing is enabled on a given URL.
Description: Checks for common sensitive files on a web server.
Description: Tests if a URL is vulnerable to CORS misconfiguration.
Description: Tests if a URL is vulnerable to clickjacking.
Description: Checks if a URL is vulnerable to TRACE method enabled.
Description: Checks if external scripts/styles have integrity attributes.
Description: Enumerates allowed HTTP methods for a given URL.
Description: Tests if a URL is vulnerable to host header injection.
Description: Calculates the hash of a favicon on a given URL.
Description: Checks if a URL supports HTTP/2.
Description: Fetches a URL and returns its HTTP status code.
Description: Attempts to crack a hash using a public hash database API.
Description: Analyzes email address reputation and risk factors
Description: Performs reverse phone number lookup and carrier identification
Description: Searches for username across multiple social media platforms
Description: Gathers comprehensive information about a company
Description: Checks if an email address appears in known data breaches
Description: Analyzes domain reputation and security status
Description: Retrieves domain registration information
Description: Performs reverse image search across multiple platforms
Description: Discovers common email formats used by a domain
This MCP server provides a comprehensive suite of pentesting and reconnaissance tools organized into logical categories:
The server supports various API keys for enhanced functionality:
Built on Cloudflare Workers for: