pentool-mcp-server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@pentool-mcp-serverfind non-obvious endpoints on example.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
English · Русский (RU)
🧠 pentool-mcp-server
MCP server for Pentool — the local AI assistant for web pentesting
A self-contained stdio JSON-RPC 2.0 server that brings AI capabilities to any MCP client — first of all to Pentool (BYO-LLM: picking checks, bypassing WAF, finding non-obvious endpoints). Installed with uv in one command.
Why a separate package
MCP is the open protocol for connecting LLM
models to tools. pentool-mcp-server encapsulates Pentool's MCP layer as a
reusable PyPI package: attached locally (stdio), no network, no ports, installs
in seconds, no heavy dependencies.
Related MCP server: pentestMCP
🔗 Built for Pentool
This server is the MCP component of Pentool, a professional web-security testing terminal (Burp-compatible proxy, scanner, spider, intruder — all in a TUI). It powers Pentool's AI:
🎯 picking the relevant scan checks for a concrete target;
🛡 WAF bypass / payload suggestions;
🕷 finding non-obvious endpoints during spider crawling.
Try the full stack:
uv tool install "pentool[ai]"→pentool ai setup→pentool.
⚡ Quick start (uv)
# Install uv (if not present): https://docs.astral.sh/uv/
curl -LsSf https://astral.sh/uv/install.sh | sh
# Standalone — just the MCP server
uv tool install pentool-mcp-server
pentool-mcp-server --version
# Or together with Pentool and its AI extras
uv tool install "pentool[ai]"Health check (stdio):
echo '{"jsonrpc":"2.0","id":1,"method":"ping"}' | pentool-mcp-server
# → {"jsonrpc": "2.0", "id": 1, "result": {"status": "ok"}}uv is the standard install path — isolated environment, exactly how Pentool itself is installed. It keeps the server out of your system Python.
🚀 Deploy on a VPS / in a container
The server opens no ports and runs as a local subprocess — safe on any host. With uv it stays out of the system Python:
uv tool install pentool-mcp-serverFull user guide — docs/GUIDE.md. Russian — README.ru.
🧩 MCP tools
Tool | Description |
| MCP protocol handshake |
| List available tools |
| Generate an LLM answer for a task ( |
| Readiness check (is a model installed) |
| Point to a GGUF model path |
| Process liveness |
🔒 Security
No network by default.
pentool-mcp-serverlistens only on stdio (stdin → stdout) inside the local process. External access is impossible — neither from other processes nor from another host.Do not expose it over TCP/0.0.0.0 without auth. If run on a network port outwardly, anyone able to write to stdin/port gets
tools/call generate(resource usage + sending target data to the LLM). MCP has no built-in authentication — bind to127.0.0.1and gate via a firewall.Target privacy. Data (URL, payload) leaves the host only if an external LLM provider is connected; with a local GGUF model the traffic stays on the machine.
More — docs/GUIDE.md.
🗺 Roadmap
stdio JSON-RPC 2.0 server (initialize / tools/list / tools/call / ping)
generate,health,configuretoolsreal LLM runner (llama-cpp-python) in
model.pyoptional TCP mode with HMAC auth
📄 License
AGPL-3.0 — the same license as Pentool.
Support / bugs: issues · Designed for Pentool · User Guide
Available Tools
3 toolsconfigureC
Принять параметры конфигурации сервера (напр. путь модели).
| Name | Required | Description | Default |
|---|---|---|---|
| model | No | Путь к GGUF-файлу модели |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must fully disclose behavior. It only says 'accept parameters' without explaining side effects, persistence, validation, or restart requirements. This is insufficient for a configuration tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence with no wasted words. It is concise and to the point, though it sacrifices valuable behavioral detail for brevity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has one optional parameter, no output schema, and no annotations, the description still leaves key context missing: what configuration does, whether it is required for sibling tools, and what happens after invocation. It is too sparse to be fully complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, and the description's mention of 'model path' merely mirrors the schema's own description for the 'model' parameter. No additional meaning is added, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states it accepts server configuration parameters with an example (model path), which clearly identifies the tool's purpose. It is distinct from siblings 'generate' and 'health', though the verb 'accept' is somewhat passive and the exact effect is implied rather than explicit.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives, nor are prerequisites or ordering requirements (e.g., configure before generate) mentioned. The description implies usage context but gives no explicit when/when-not guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
generateB
Сгенерировать ответ LLM по задаче. payload — строка запроса (данные цели), model — путь к GGUF-файлу модели (необязательно). При отсутствии модели вернёт ошибку setup required.
| Name | Required | Description | Default |
|---|---|---|---|
| task | Yes | Имя задачи (напр. choose_checks, crawl_endpoints) | |
| model | No | Путь к GGUF-файлу модели | |
| payload | Yes | Данные цели / контекст (JSON-строка) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It discloses that the model parameter is optional and that omitting it causes an error ('setup required'), which is useful behavioral insight. However, it does not mention whether the tool is read-only or has side effects (e.g., logging), or any rate limits or auth requirements. The behavior is partially transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is very concise at two sentences, front-loading the main purpose. Every phrase adds value, though the error clause could be more specific (e.g., 'returns an error' instead of 'вернёт ошибку'). No extraneous text, well-structured for quick parsing.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description should clarify what the tool returns (e.g., generated response text). It does not, leaving a gap. With only 3 params all documented in schema, the description is adequate for basic use but incomplete for understanding return behavior or error responses beyond the 'setup required' case.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, and the description adds some value by explaining that model is optional and payload is the query data. It does not elaborate on 'task' beyond the example values in schema, and does not clarify the format of payload (JSON string) beyond the schema. As coverage is high, baseline 3 is appropriate given the minimal added context.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states the tool generates an LLM response for a task, specifying the payload as the query string and model as an optional GGUF file path. It clearly identifies the verb (генерировать) and resource (ответ LLM по задаче), and distinguishes from siblings like 'health' and 'configure' by its focus on generation rather than status checks or setup.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage when an LLM response is needed for a task, and mentions that missing model leads to a 'setup required' error. However, it does not explicitly state when to use this vs. 'configure' (e.g., to set the model first) or when not to use it (e.g., if no model is configured). The sibling tools are named but no direct comparison is made.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
healthB
Проверка готовности: вернёт статус, установлена ли модель.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It indicates the tool is read-only (returns status) and non-destructive, but does not disclose error behavior, return format details, or potential side effects. The description is minimally transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, short sentence that is front-loaded and contains no redundant information. Every word earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity, the description is mostly adequate for a health check. However, it lacks specification of the return value format (e.g., boolean, JSON) and does not mention any edge cases. With no output schema, more detail would improve completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters and schema coverage is 100% (trivially). Per the baseline rule for 0 parameters, the description does not need to add parameter semantics, and it appropriately omits any.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool performs a readiness check and returns whether the model is installed. The verb 'Проверка готовности' (readiness check) and resource 'model' are specific. However, it does not explicitly differentiate from sibling tools 'generate' and 'configure', though the purpose is distinct enough.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. There is no mention of preconditions, context, or scenarios where 'health' is appropriate compared to 'generate' or 'configure'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v0.1.0- First observed
configure - First observed
generate - First observed
health
TDQS
Each tool has a clearly distinct purpose: 'generate' for LLM inference, 'health' for readiness checking, and 'configure' for setting parameters. There is no overlap or ambiguity between them.
All tool names are simple, lowercase verbs that accurately describe their action ('generate', 'health', 'configure'). The pattern is uniform and predictable.
With 3 tools, the count is appropriate for a minimal MCP server focused on LLM inference. It could potentially benefit from a status tool or a list-models tool, but the current set is sufficient for its core purpose.
The tool surface covers basic lifecycle: configure (setup), health (readiness), and generate (infer). However, there is no tool for cancelling generation, listing available models, or inspecting current configuration, which are notable gaps for a production server.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.
Self-hosted MCP server: 26 deterministic dev, security, and EVM tools.
Related MCP Servers
- AlicenseDqualityCmaintenanceA Model Context Protocol server that integrates essential penetration testing tools (Nmap, Gobuster, Nikto, John the Ripper) into a unified natural language interface, allowing security professionals to execute and chain multiple tools through conversational commands.9139143MIT
- FlicenseNot gradedqualityBmaintenanceAn MCP server that exposes over 20 standard penetration testing utilities, such as Nmap, SQLMap, and OWASP ZAP, as callable tools for AI agents. It enables natural language control over complex security workflows for automated and interactive penetration testing.93-
- AlicenseAqualityDmaintenanceMCP server for TurboPentest — run AI-powered penetration tests and review findings from your coding assistant.855MIT
- AlicenseNot gradedqualityCmaintenanceMCP server that connects an LLM via Ollama to security tools for autonomous or guided penetration testing from a terminal interface.9GPL 3.0
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/DrXOps/pentool-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server