pentool-mcp-server
English · Русский (RU)
🧠 pentool-mcp-server
MCP сервер для Pentool — локального AI-ассистента для веб-пентестинга
Автономный stdio JSON-RPC 2.0 сервер, предоставляющий AI-возможности любому MCP-клиенту — в первую очередь Pentool (BYO-LLM: подбор проверок, обход WAF, поиск неочевидных конечных точек). Устанавливается одной командой uv.
Зачем отдельный пакет
MCP — это открытый протокол для подключения LLM
моделей к инструментам. pentool-mcp-server инкапсулирует MCP-слой Pentool как
переиспользуемый пакет PyPI: подключается локально (stdio), без сети, без портов,
устанавливается за секунды, без тяжелых зависимостей.
Related MCP server: pentestMCP
🔗 Создан для Pentool
Этот сервер является MCP-компонентом Pentool, профессионального терминала для веб-безопасности (прокси, совместимый с Burp, сканер, паук, интрудер — всё в TUI). Он обеспечивает AI-функционал Pentool:
🎯 подбор подходящих проверок сканирования для конкретной цели;
🛡 обход WAF / предложения полезных нагрузок;
🕷 поиск неочевидных конечных точек во время сканирования пауком.
Попробуйте полный стек:
uv tool install "pentool[ai]"→pentool ai setup→pentool.
⚡ Быстрый старт (uv)
# Install uv (if not present): https://docs.astral.sh/uv/
curl -LsSf https://astral.sh/uv/install.sh | sh
# Standalone — just the MCP server
uv tool install pentool-mcp-server
pentool-mcp-server --version
# Or together with Pentool and its AI extras
uv tool install "pentool[ai]"Проверка работоспособности (stdio):
echo '{"jsonrpc":"2.0","id":1,"method":"ping"}' | pentool-mcp-server
# → {"jsonrpc": "2.0", "id": 1, "result": {"status": "ok"}}uv — это стандартный путь установки — изолированная среда, именно так, как устанавливается сам Pentool. Это держит сервер вне системного Python.
🚀 Развёртывание на VPS / в контейнере
Сервер не открывает порты и работает как локальный подпроцесс — безопасно на любом хосте. С uv он не влияет на системный Python:
uv tool install pentool-mcp-serverПолное руководство пользователя — docs/GUIDE.md. На русском — README.ru.
🧩 MCP инструменты
Инструмент | Описание |
| MCP протокольное рукопожатие |
| Список доступных инструментов |
| Генерация ответа LLM для задачи ( |
| Проверка готовности (установлена ли модель) |
| Указать путь к модели GGUF |
| Проверка активности процесса |
🔒 Безопасность
По умолчанию без сети.
pentool-mcp-serverпрослушивает только stdio (stdin → stdout) внутри локального процесса. Внешний доступ невозможен — ни из других процессов, ни с другого хоста.Не открывайте его через TCP/0.0.0.0 без аутентификации. Если запустить на сетевом порту, любой, кто может писать в stdin/порт, получит доступ к
tools/call generate(использование ресурсов + отправка целевых данных LLM). В MCP нет встроенной аутентификации — привязывайтесь к127.0.0.1и используйте брандмауэр.Конфиденциальность целей. Данные (URL, полезная нагрузка) покидают хост только при подключении внешнего LLM-провайдера; с локальной моделью GGUF трафик остаётся на машине.
Подробнее — docs/GUIDE.md.
🗺 Дорожная карта
stdio JSON-RPC 2.0 сервер (initialize / tools/list / tools/call / ping)
инструменты
generate,health,configureреальный раннер LLM (llama-cpp-python) в
model.pyопциональный TCP-режим с HMAC-аутентификацией
📄 Лицензия
AGPL-3.0 — та же лицензия, что и Pentool.
Поддержка / баги: issues · Спроектировано для Pentool · Руководство пользователя
Available Tools
3 toolsconfigureC
Принять параметры конфигурации сервера (напр. путь модели).
| Name | Required | Description | Default |
|---|---|---|---|
| model | No | Путь к GGUF-файлу модели |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must fully disclose behavior. It only says 'accept parameters' without explaining side effects, persistence, validation, or restart requirements. This is insufficient for a configuration tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence with no wasted words. It is concise and to the point, though it sacrifices valuable behavioral detail for brevity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool has one optional parameter, no output schema, and no annotations, the description still leaves key context missing: what configuration does, whether it is required for sibling tools, and what happens after invocation. It is too sparse to be fully complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, and the description's mention of 'model path' merely mirrors the schema's own description for the 'model' parameter. No additional meaning is added, so the baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states it accepts server configuration parameters with an example (model path), which clearly identifies the tool's purpose. It is distinct from siblings 'generate' and 'health', though the verb 'accept' is somewhat passive and the exact effect is implied rather than explicit.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives, nor are prerequisites or ordering requirements (e.g., configure before generate) mentioned. The description implies usage context but gives no explicit when/when-not guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
generateB
Сгенерировать ответ LLM по задаче. payload — строка запроса (данные цели), model — путь к GGUF-файлу модели (необязательно). При отсутствии модели вернёт ошибку setup required.
| Name | Required | Description | Default |
|---|---|---|---|
| task | Yes | Имя задачи (напр. choose_checks, crawl_endpoints) | |
| model | No | Путь к GGUF-файлу модели | |
| payload | Yes | Данные цели / контекст (JSON-строка) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It discloses that the model parameter is optional and that omitting it causes an error ('setup required'), which is useful behavioral insight. However, it does not mention whether the tool is read-only or has side effects (e.g., logging), or any rate limits or auth requirements. The behavior is partially transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is very concise at two sentences, front-loading the main purpose. Every phrase adds value, though the error clause could be more specific (e.g., 'returns an error' instead of 'вернёт ошибку'). No extraneous text, well-structured for quick parsing.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description should clarify what the tool returns (e.g., generated response text). It does not, leaving a gap. With only 3 params all documented in schema, the description is adequate for basic use but incomplete for understanding return behavior or error responses beyond the 'setup required' case.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, and the description adds some value by explaining that model is optional and payload is the query data. It does not elaborate on 'task' beyond the example values in schema, and does not clarify the format of payload (JSON string) beyond the schema. As coverage is high, baseline 3 is appropriate given the minimal added context.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states the tool generates an LLM response for a task, specifying the payload as the query string and model as an optional GGUF file path. It clearly identifies the verb (генерировать) and resource (ответ LLM по задаче), and distinguishes from siblings like 'health' and 'configure' by its focus on generation rather than status checks or setup.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage when an LLM response is needed for a task, and mentions that missing model leads to a 'setup required' error. However, it does not explicitly state when to use this vs. 'configure' (e.g., to set the model first) or when not to use it (e.g., if no model is configured). The sibling tools are named but no direct comparison is made.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
healthB
Проверка готовности: вернёт статус, установлена ли модель.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It indicates the tool is read-only (returns status) and non-destructive, but does not disclose error behavior, return format details, or potential side effects. The description is minimally transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, short sentence that is front-loaded and contains no redundant information. Every word earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity, the description is mostly adequate for a health check. However, it lacks specification of the return value format (e.g., boolean, JSON) and does not mention any edge cases. With no output schema, more detail would improve completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters and schema coverage is 100% (trivially). Per the baseline rule for 0 parameters, the description does not need to add parameter semantics, and it appropriately omits any.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool performs a readiness check and returns whether the model is installed. The verb 'Проверка готовности' (readiness check) and resource 'model' are specific. However, it does not explicitly differentiate from sibling tools 'generate' and 'configure', though the purpose is distinct enough.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. There is no mention of preconditions, context, or scenarios where 'health' is appropriate compared to 'generate' or 'configure'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v0.1.0- First observed
configure - First observed
generate - First observed
health
TDQS
Each tool has a clearly distinct purpose: 'generate' for LLM inference, 'health' for readiness checking, and 'configure' for setting parameters. There is no overlap or ambiguity between them.
All tool names are simple, lowercase verbs that accurately describe their action ('generate', 'health', 'configure'). The pattern is uniform and predictable.
With 3 tools, the count is appropriate for a minimal MCP server focused on LLM inference. It could potentially benefit from a status tool or a list-models tool, but the current set is sufficient for its core purpose.
The tool surface covers basic lifecycle: configure (setup), health (readiness), and generate (infer). However, there is no tool for cancelling generation, listing available models, or inspecting current configuration, which are notable gaps for a production server.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Security-first WordPress MCP server. 129 tools for Claude, ChatGPT, Gemini. Free on wp.org.
Self-hosted MCP server: 26 deterministic dev, security, and EVM tools.
Related MCP Servers
- AlicenseDqualityCmaintenanceA Model Context Protocol server that integrates essential penetration testing tools (Nmap, Gobuster, Nikto, John the Ripper) into a unified natural language interface, allowing security professionals to execute and chain multiple tools through conversational commands.9139143MIT
- FlicenseNot gradedqualityBmaintenanceAn MCP server that exposes over 20 standard penetration testing utilities, such as Nmap, SQLMap, and OWASP ZAP, as callable tools for AI agents. It enables natural language control over complex security workflows for automated and interactive penetration testing.93-
- AlicenseAqualityDmaintenanceMCP server for TurboPentest — run AI-powered penetration tests and review findings from your coding assistant.855MIT
- AlicenseNot gradedqualityCmaintenanceMCP server that connects an LLM via Ollama to security tools for autonomous or guided penetration testing from a terminal interface.9GPL 3.0
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/DrXOps/pentool-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server