Skip to main content
Glama
DrXOps
by DrXOps

English · Русский (RU)

🧠 pentool-mcp-server

MCP server for Pentool — the local AI assistant for web pentesting

PyPI version Python License: AGPL-3.0 Install: uv Open in GitHub

A self-contained stdio JSON-RPC 2.0 server that brings AI capabilities to any MCP client — first of all to Pentool (BYO-LLM: picking checks, bypassing WAF, finding non-obvious endpoints). Installed with uv in one command.


Why a separate package

MCP is the open protocol for connecting LLM models to tools. pentool-mcp-server encapsulates Pentool's MCP layer as a reusable PyPI package: attached locally (stdio), no network, no ports, installs in seconds, no heavy dependencies.

Related MCP server: pentestMCP

🔗 Built for Pentool

This server is the MCP component of Pentool, a professional web-security testing terminal (Burp-compatible proxy, scanner, spider, intruder — all in a TUI). It powers Pentool's AI:

  • 🎯 picking the relevant scan checks for a concrete target;

  • 🛡 WAF bypass / payload suggestions;

  • 🕷 finding non-obvious endpoints during spider crawling.

Try the full stack: uv tool install "pentool[ai]"pentool ai setuppentool.

⚡ Quick start (uv)

# Install uv (if not present): https://docs.astral.sh/uv/
curl -LsSf https://astral.sh/uv/install.sh | sh

# Standalone — just the MCP server
uv tool install pentool-mcp-server
pentool-mcp-server --version

# Or together with Pentool and its AI extras
uv tool install "pentool[ai]"

Health check (stdio):

echo '{"jsonrpc":"2.0","id":1,"method":"ping"}' | pentool-mcp-server
# → {"jsonrpc": "2.0", "id": 1, "result": {"status": "ok"}}

uv is the standard install path — isolated environment, exactly how Pentool itself is installed. It keeps the server out of your system Python.

🚀 Deploy on a VPS / in a container

The server opens no ports and runs as a local subprocess — safe on any host. With uv it stays out of the system Python:

uv tool install pentool-mcp-server

Full user guide — docs/GUIDE.md. Russian — README.ru.

🧩 MCP tools

Tool

Description

initialize

MCP protocol handshake

tools/list

List available tools

tools/call generate

Generate an LLM answer for a task (task + payload)

tools/call health

Readiness check (is a model installed)

tools/call configure

Point to a GGUF model path

ping

Process liveness

🔒 Security

  • No network by default. pentool-mcp-server listens only on stdio (stdin → stdout) inside the local process. External access is impossible — neither from other processes nor from another host.

  • Do not expose it over TCP/0.0.0.0 without auth. If run on a network port outwardly, anyone able to write to stdin/port gets tools/call generate (resource usage + sending target data to the LLM). MCP has no built-in authentication — bind to 127.0.0.1 and gate via a firewall.

  • Target privacy. Data (URL, payload) leaves the host only if an external LLM provider is connected; with a local GGUF model the traffic stays on the machine.

More — docs/GUIDE.md.

🗺 Roadmap

  • stdio JSON-RPC 2.0 server (initialize / tools/list / tools/call / ping)

  • generate, health, configure tools

  • real LLM runner (llama-cpp-python) in model.py

  • optional TCP mode with HMAC auth

📄 License

AGPL-3.0 — the same license as Pentool.


Support / bugs: issues · Designed for Pentool · User Guide

Available Tools

3 tools
configureC

Принять параметры конфигурации сервера (напр. путь модели).

ParametersJSON Schema
NameRequiredDescriptionDefault
modelNoПуть к GGUF-файлу модели

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must fully disclose behavior. It only says 'accept parameters' without explaining side effects, persistence, validation, or restart requirements. This is insufficient for a configuration tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, front-loaded sentence with no wasted words. It is concise and to the point, though it sacrifices valuable behavioral detail for brevity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool has one optional parameter, no output schema, and no annotations, the description still leaves key context missing: what configuration does, whether it is required for sibling tools, and what happens after invocation. It is too sparse to be fully complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, and the description's mention of 'model path' merely mirrors the schema's own description for the 'model' parameter. No additional meaning is added, so the baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states it accepts server configuration parameters with an example (model path), which clearly identifies the tool's purpose. It is distinct from siblings 'generate' and 'health', though the verb 'accept' is somewhat passive and the exact effect is implied rather than explicit.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance is provided on when to use this tool versus alternatives, nor are prerequisites or ordering requirements (e.g., configure before generate) mentioned. The description implies usage context but gives no explicit when/when-not guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

generateB

Сгенерировать ответ LLM по задаче. payload — строка запроса (данные цели), model — путь к GGUF-файлу модели (необязательно). При отсутствии модели вернёт ошибку setup required.

ParametersJSON Schema
NameRequiredDescriptionDefault
taskYesИмя задачи (напр. choose_checks, crawl_endpoints)
modelNoПуть к GGUF-файлу модели
payloadYesДанные цели / контекст (JSON-строка)

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It discloses that the model parameter is optional and that omitting it causes an error ('setup required'), which is useful behavioral insight. However, it does not mention whether the tool is read-only or has side effects (e.g., logging), or any rate limits or auth requirements. The behavior is partially transparent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is very concise at two sentences, front-loading the main purpose. Every phrase adds value, though the error clause could be more specific (e.g., 'returns an error' instead of 'вернёт ошибку'). No extraneous text, well-structured for quick parsing.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, the description should clarify what the tool returns (e.g., generated response text). It does not, leaving a gap. With only 3 params all documented in schema, the description is adequate for basic use but incomplete for understanding return behavior or error responses beyond the 'setup required' case.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, and the description adds some value by explaining that model is optional and payload is the query data. It does not elaborate on 'task' beyond the example values in schema, and does not clarify the format of payload (JSON string) beyond the schema. As coverage is high, baseline 3 is appropriate given the minimal added context.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states the tool generates an LLM response for a task, specifying the payload as the query string and model as an optional GGUF file path. It clearly identifies the verb (генерировать) and resource (ответ LLM по задаче), and distinguishes from siblings like 'health' and 'configure' by its focus on generation rather than status checks or setup.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage when an LLM response is needed for a task, and mentions that missing model leads to a 'setup required' error. However, it does not explicitly state when to use this vs. 'configure' (e.g., to set the model first) or when not to use it (e.g., if no model is configured). The sibling tools are named but no direct comparison is made.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

healthB

Проверка готовности: вернёт статус, установлена ли модель.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

B3.4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden. It indicates the tool is read-only (returns status) and non-destructive, but does not disclose error behavior, return format details, or potential side effects. The description is minimally transparent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, short sentence that is front-loaded and contains no redundant information. Every word earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity, the description is mostly adequate for a health check. However, it lacks specification of the return value format (e.g., boolean, JSON) and does not mention any edge cases. With no output schema, more detail would improve completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters and schema coverage is 100% (trivially). Per the baseline rule for 0 parameters, the description does not need to add parameter semantics, and it appropriately omits any.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool performs a readiness check and returns whether the model is installed. The verb 'Проверка готовности' (readiness check) and resource 'model' are specific. However, it does not explicitly differentiate from sibling tools 'generate' and 'configure', though the purpose is distinct enough.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance is provided on when to use this tool versus alternatives. There is no mention of preconditions, context, or scenarios where 'health' is appropriate compared to 'generate' or 'configure'.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 3 tool updatesv0.1.0
    • First observedconfigure
    • First observedgenerate
    • First observedhealth

TDQS

A3.5/5.0
Disambiguation5/5

Each tool has a clearly distinct purpose: 'generate' for LLM inference, 'health' for readiness checking, and 'configure' for setting parameters. There is no overlap or ambiguity between them.

Naming Consistency5/5

All tool names are simple, lowercase verbs that accurately describe their action ('generate', 'health', 'configure'). The pattern is uniform and predictable.

Tool Count4/5

With 3 tools, the count is appropriate for a minimal MCP server focused on LLM inference. It could potentially benefit from a status tool or a list-models tool, but the current set is sufficient for its core purpose.

Completeness3/5

The tool surface covers basic lifecycle: configure (setup), health (readiness), and generate (infer). However, there is no tool for cancelling generation, listing available models, or inspecting current configuration, which are notable gaps for a production server.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    D
    quality
    C
    maintenance
    A Model Context Protocol server that integrates essential penetration testing tools (Nmap, Gobuster, Nikto, John the Ripper) into a unified natural language interface, allowing security professionals to execute and chain multiple tools through conversational commands.
    9
    139
    143
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    An MCP server that exposes over 20 standard penetration testing utilities, such as Nmap, SQLMap, and OWASP ZAP, as callable tools for AI agents. It enables natural language control over complex security workflows for automated and interactive penetration testing.
    93
    -

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/DrXOps/pentool-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server