Xploit47
Xploit47 is an AI-powered penetration testing reasoning MCP server that helps plan and analyze attack paths for CTF/HTB challenges and authorized pentests — without actually executing exploits.
Attack Path Planning: Uses Beam Search (methodical, fixed-width exploration) or Monte Carlo Tree Search (MCTS) (simulation-based, for uncertain/complex scenarios) to explore and score attack steps.
Step Scoring: Provides deterministic scores with explainable breakdowns for each attack step.
Kill-Chain Classification: Auto-classifies steps into phases — recon, enumeration, vulnerability assessment, exploitation, privilege escalation, and post-exploitation.
Tool Recommendations: Suggests appropriate tools (e.g., nmap, enum4linux, searchsploit, metasploit, linpeas/winPEAS) with confidence levels.
Asset Extraction: Automatically extracts IPs/hostnames from step text when not explicitly provided.
Path Chaining: Links sequential steps automatically and returns the full attack path with an aggregate path score.
Critical Path Highlighting: Flags high-impact steps (e.g., CVE exploitation, privilege escalation).
Next-Step Hints: Provides phase-aware planning suggestions for what to do next.
MCP Integration: Works as a Model Context Protocol server with clients like Claude Desktop, Cursor, and Grok for interactive pentest planning.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Xploit47Next step after SMB enum on 10.10.10.10?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Xploit47
Systematic, AI-powered penetration testing reasoning engine (MCP server) for attack path planning, CTF/HTB solving, and authorized pentest workflows.
Features Beam Search, Monte Carlo Tree Search (MCTS), attack step scoring, tool recommendations, and critical-path highlighting.
What is Xploit47?
Xploit47 is a Model Context Protocol (MCP) server that turns an LLM into a structured, methodical pentest planner and advisor. It does not run exploits against targets — it reasons about attack chains, scores steps, and recommends next actions and tools.
Capability | Description |
Beam Search | Fixed-width exploration of the most promising attack paths |
MCTS | Simulation-based exploration for uncertain / complex scenarios |
Deterministic scoring | Same input → same score; explainable breakdown (no randomness) |
Kill-chain phase | Auto-classifies recon → enum → vuln → exploit → privesc → post-ex |
Tool recommendation | Auto-suggests tools (nmap, enum4linux, searchsploit, …) with confidence |
Asset extraction | Pulls IP/hostname from step text when not provided |
Path chaining | Auto-links sequential steps; returns full path + pathScore |
Critical path | Auto-flags high-impact steps (CVE exploit, privesc, …) |
Next-step hints | Phase-aware planning suggestions |
MCP-native | Works with Claude Desktop, Cursor, Grok, and other MCP clients |
Related MCP server: PentestThinkingMCP
How it works
Input — You (or your AI) provide the current attack step/state
e.g."Enumerate SMB on 10.10.10.10"Reasoning — Xploit47 uses Beam Search or MCTS to score and track the path
Output — Returns step metadata, score, strategy used, and tree statistics
Example HTB-style workflow
# | Input step | Suggested direction | Tool |
1 | Start recon on target | Full port scan | nmap |
2 | nmap complete | Enumerate SMB on 445 | enum4linux |
3 | SMB enum done | Search public SMB CVEs | searchsploit |
4 | CVE found | Authorized exploit path | metasploit |
5 | Shell as user | Priv-esc enumeration | winPEAS / linpeas |
6 | Need root | Check common misconfigs | manual |
Installation
git clone https://github.com/aloc999/Xploit47.git
cd Xploit47
npm install
npm run buildRequirements: Node.js ≥ 18
Usage (MCP client config)
Add to your MCP client (Claude Desktop, Cursor, Grok, etc.):
{
"mcpServers": {
"Xploit47": {
"command": "node",
"args": ["/absolute/path/to/Xploit47/dist/index.js"]
}
}
}Or run directly:
npm start
# equivalent: node dist/index.jsTool: xploit47
Parameter | Type | Required | Description |
| string | yes | Current attack step description |
| integer ≥ 1 | yes | Current step number |
| integer ≥ 1 | yes | Estimated total steps |
| boolean | yes | Whether another step is needed |
|
| no | Search strategy (default: beam_search) |
| string | no | Target asset (auto-extracted if omitted) |
| string | no | Tool (auto-recommended if omitted) |
| boolean | no | Critical flag (auto-detected if omitted) |
| string | no | Explicit parent node (auto-links sequential steps) |
Search strategies
Beam Search (beam_search)
Keeps a fixed-width set of the best attack paths
Best for methodical exploit chaining and known patterns
Use for: enumeration sequences, CVE chaining, linear CTF paths
Monte Carlo Tree Search (mcts)
Simulation-based exploration with UCB1 selection
Balances exploring new vectors vs exploiting known weaknesses
Use for: complex networks, uncertain outcomes, multi-stage APT-style planning
Ethics & legal
Xploit47 is a reasoning / planning tool only. Use it only on systems you are authorized to test (your own labs, CTF platforms, or programs with written permission / safe harbor). Unauthorized access is illegal.
Development
npm run dev # tsx src/index.ts
npm run build # tsc → dist/
npm start # node dist/index.jsProject layout
Xploit47/
├── src/
│ ├── index.ts # MCP server entry (stdio)
│ ├── reasoner.ts # Strategy orchestration + auto parent links
│ ├── scoring.ts # Deterministic score + kill-chain phase
│ ├── recommend.ts # Tool / asset inference + next-step hints
│ ├── engine.ts # Lightweight beam engine
│ ├── state.ts # Node cache / path state
│ ├── types.ts # Shared types & config
│ └── strategies/
│ ├── base.ts # Shared evaluation + response builder
│ ├── beam-search.ts # Beam Search
│ ├── mcts.ts # Monte Carlo Tree Search
│ └── factory.ts # Strategy factory
├── scripts/smoke-test.mjs # Accuracy + MCP integration tests
├── tot-engine.js # Standalone Tree-of-Thought helper
├── state-manager.js # Standalone session helper
├── package.json
└── README.mdLicense
MIT — see LICENSE.
Available Tools
1 toolxploit47A
Xploit47 advanced pentest reasoning engine. Breaks down attack paths step by step using Beam Search or Monte Carlo Tree Search (MCTS). Scores steps, tracks attack chains, and returns strategy metrics. Use for CTF/HTB planning and authorized pentest workflows.
| Name | Required | Description | Default |
|---|---|---|---|
| asset | No | Target asset for this step (optional) | |
| critical | No | Whether this step is on the critical path | |
| attackStep | Yes | Current attack step or action in the penetration test | |
| strategyType | No | Attack strategy to use: beam_search (methodical) or mcts (exploratory) | |
| recommendedTool | No | Recommended tool for this step (optional) | |
| attackStepNumber | Yes | Current step number in the attack chain | |
| totalAttackSteps | Yes | Total expected steps in the attack chain | |
| nextAttackStepNeeded | Yes | Whether another attack step is needed |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full burden. It explains the tool's reasoning approach (Beam Search/MCTS, scoring, tracking) but does not disclose behavioral traits like whether it executes commands, modifies data, or requires special permissions. It adds context beyond the schema but lacks details on safety or side effects.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences long, front-loaded with the main purpose, and contains no unnecessary words. Every sentence contributes to understanding the tool's function and use.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the lack of output schema and 8 parameters, the description provides a solid high-level understanding. It covers the algorithms, use case, and key actions but does not describe the output format or how to interpret the returned metrics. It is mostly complete for a reasoning engine.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so baseline is 3. The description does not elaborate on individual parameters beyond the general context of attack steps and strategies. It adds no specific parameter-level meaning that the schema already provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it is a pentest reasoning engine that breaks down attack paths using Beam Search or MCTS. It specifies the domain (CTF/HTB planning, authorized pentests) and the core actions (scoring, tracking, returning metrics). This is specific and unambiguous, with no sibling tools to confuse.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly states when to use it: 'Use for CTF/HTB planning and authorized pentest workflows.' While it doesn't list when not to use it or provide alternatives, the guidance is clear and context-appropriate given the lack of sibling tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
1 tool update
v1.0.0- First observed
xploit47
TDQS
With only one tool, there is no possibility of confusion or overlap.
A single tool name cannot be inconsistent; it trivially follows a pattern.
A single tool for a complex domain like pentesting is extremely thin and insufficient.
The tool only covers reasoning/planning, leaving major pentest stages uncovered.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
MEOK MCP Hardening MCP — automated security red-team for any MCP server. Maps OWASP LLM Top 10
AI-security knowledge as MCP: standards-mapped tools (OWASP, NIST, MITRE) for AI agents.
Offline methodology engine for authorized penetration testing, CTF, and security research.
Related MCP Servers
- AlicenseCqualityDmaintenanceAn AI-powered penetration testing reasoning engine that provides automated attack path planning, step-by-step guidance for CTFs/HTB challenges, and tool recommendations using Beam Search and MCTS algorithms.1MIT
- AlicenseNot gradedqualityDmaintenanceEnables automated penetration testing workflow planning using Beam Search and Monte Carlo Tree Search algorithms to generate step-by-step attack paths, score vulnerabilities, and recommend tools for reconnaissance, exploitation, and privilege escalation tasks.38MIT
- AlicenseNot gradedqualityDmaintenanceAI-Powered Red Team MCP Server enabling autonomous penetration testing via Model Context Protocol with 44+ security tools for AI agents.14MIT
- AlicenseNot gradedqualityCmaintenanceAI-powered penetration testing through 36 MCP tools on a containerized Kali Linux, enabling automated reconnaissance, web testing, exploitation, and evidence collection.1MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/aloc999/Xploit47'
If you have feedback or need assistance with the MCP directory API, please join our Discord server