PentestMCP Server
This is a simple MCP (Model Context Protocol) server that runs within a Docker container based on Kali Linux. The server provides tools to run security scans:
run_nmap: Run nmap scans on targetsrun_gobuster: Run directory brute force scans on web servers
It is an early POC and will be extended with more tools and features soon. To goal is to run pentests with just natural language without having to memorize long commands and lots of tools.
Requirements
- Docker
- Docker Compose
Setup
-
Clone this repository:
-
Build and start the Docker container:
docker-compose up -d -
Configure Claude Desktop to use this MCP server:
Edit your Claude Desktop configuration file located at:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\\Claude\\claude_desktop_config.json
Add the following configuration:
{ "mcpServers": { "pentest-mcp": { "command": "docker", "args": ["exec", "-i", "pentest-mcp", "python3", "/app/pentest_mcp.py"] } } } - macOS:
-
Restart Claude Desktop to load the new configuration.
Usage Examples
Once connected to Claude Desktop, you can ask questions like:
- "Can you scan 192.168.1.1 with nmap to find open ports?"
- "What services run on 192.168.1.1?"
- "Use gobuster to find hidden directories on http://example.com"
Note
This server includes very basic input validation, but you should only use it in trusted environments and on targets you have permission to scan.
Customization
To add custom wordlists, uncomment the volumes section in docker-compose.yml and add your wordlists to a local directory.
Recommend MCP Servers 💡
adx-mcp-server
A Model Context Protocol (MCP) server enabling AI assistants to query and analyze Azure Data Explorer databases via standardized interfaces.
perplexity-mcp-rb
MCP Server for web search using Perplexity.
package-registry-mcp
A Model Context Protocol (MCP) server that enables AI assistants and agents to search and retrieve up-to-date information from NPM, Cargo, PyPI, NuGet, and Go package registries.
@21st-dev/magic
21st dev Magic MCP server for creating UI components via natural language in IDEs like Cursor/WindSurf/Cline
@abhiz123/todoist-mcp-server
An MCP server that integrates Claude with Todoist, enabling natural language task management for creating, updating, completing, and deleting tasks.
urlDNA
The urlDNA MCP Server enables LLM agents to interact with the urlDNA threat intelligence platform for URL scanning and phishing detection via an SSE interface.