Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Status โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ”’ Security
  3. Cybersec Toolkit
Cybersec Toolkit logo
Health: ActiveRecent health check succeeded.Last checked 10/4/2026, 7:01:17 AM

Cybersec Toolkit

User RatingsBe the first to rate and review this MCP server!
View Repository66 GitHub StarsTotal stargazers on GitHub for the source repository (66 stars).Visit Website
securitypenetration-testingdfirctfsandbox

Governed MCP access to 670+ security tools for CTF, pentesting, bug bounty, DFIR, and blue-team workflows.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "cybersec-toolkit": {
      "command": "uvx",
      "args": [
        "pwntools"
      ]
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing Alternatives๐Ÿ”’ More in Security

Overview

The cybersec-toolkit MCP server lets AI agents discover, recommend, and run security tools from a shared registry. It uses a governed execution path with allowlists, argument checks, network policies, rate limits, output caps, and timeouts. Tools run in a disposable Kata Containers VM by default, while host execution is available through an explicit local mode. Reach for it when an agent needs structured access to installed security tooling for authorized CTF, pentest, DFIR, or defensive work.

Use cases

โ€ขDiscover tools for a CTF challenge
โ€ขTriage a binary with an AI agent
โ€ขMap an authorized lab attack surface
โ€ขRun DFIR tools through a sandbox
โ€ขInstall security tools from a selected profile

Key features

โ€ข670+ security tools across 18 modules
โ€ข15 MCP tools for discovery and execution
โ€ขKata Containers sandbox by default
โ€ขAllowlist and argument validation
โ€ขPrivate-network target policy by default
โ€ข872 Agent Skills for security workflows

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Cybersec Toolkit.

Extracted Tool Capabilities
670+ security tools across 18 modules
15 MCP tools for discovery and execution
Kata Containers sandbox by default
Allowlist and argument validation
Private-network target policy by default
872 Agent Skills for security workflows

How Cybersec Toolkit works

What cybersec-toolkit MCP server does

The cybersec-toolkit MCP server exposes an installed security-tool collection to MCP-compatible AI clients. The repository describes more than 670 tools organized into 18 modules and 14 profiles, covering activities such as CTF work, penetration testing, bug bounty research, digital forensics and incident response, and blue-team analysis. It also includes 872 Agent Skills that provide procedural context for these workflows, although the skills remain outside the tool-execution path.

An agent can inspect the registry, get recommendations, and request governed execution through 15 MCP tools. The system is intended to support an operator working with an agent by default. An autonomous solver loop is available only when explicitly authorized.

How it works

The installer places tools on the host or prepares them inside the sandbox image. The MCP server and installer use tools_config.json as their shared registry, so the server can reason about the tools installed by the selected modules and profiles.

The cybersec-toolkit MCP server starts through a root-aware launcher. In its default configuration, the launcher boots one disposable Kata Containers VM per client session. The VM uses a separate kernel, runs as a non-root user with capabilities removed, and applies memory, CPU, and process limits. It does not expose the host filesystem except for an optional workspace mount and does not receive a Docker socket.

Execution is controlled by security.py. Governed tools use direct subprocess execution rather than a shell, with registry allowlists, argument sanitization, blocked-flag checks, target and network policy, rate limiting, timeouts, and output limits. External targets and arbitrary script execution are disabled by default. The separate run_script capability requires an explicit opt-in.

Setup and configuration

Clone the repository and run the installer on a supported Linux distribution or Termux. The documented quick start uses ./install.sh --doctor for a read-only preflight, followed by a profile installation such as sudo ./install.sh --profile ctf. Without profile restrictions, the installer can install all modules.

Sandbox mode requires Linux with KVM, Docker 23 or newer with a Kata runtime, and Node.js 22 or newer. Build the sandbox image with make sandbox-image, then install sandbox dependencies with npm --prefix sandbox ci --ignore-scripts. macOS, Windows, and virtual machines without nested virtualization should use host mode instead. Host mode requires uv and can be selected with the launcher's --local option or CYBERSEC_SANDBOX_MODE=local.

Tracked configurations are provided for Claude Code, Codex, Gemini CLI, and OpenCode through scripts/mcp-launch.sh. After connecting a client, restart it so the MCP tools become available.

Tools and capabilities

The cybersec-toolkit MCP server supports these categories of work:

  • Discovering tools across modules and profiles.
  • Recommending tools for an identified problem type.
  • Running individual tools through the governed execution path.
  • Running approved tool pipelines.
  • Executing scripts only when scripting has been enabled explicitly.
  • Applying Agent Skills for CTF, pentest, bug bounty, DFIR, and blue-team methodology.
  • Logging actions as owner-readable JSON lines with rotation.

The default network policy rejects targets that resolve outside private or loopback ranges. Operators can configure external access explicitly, but the address check is not a firewall. A filtered Docker network or CYBERSEC_SANDBOX_NETWORK=none may be needed for stronger network isolation.

Limitations and notes

The sandbox is the default isolation layer, not a complete network boundary. Tools can reach whatever the Docker network permits, and allowed tools run with the server user's permissions. Some tools may spawn child processes or load plugins. Host mode removes the VM boundary and runs tools on the host as the server user.

The repository is designed for authorized security work. External targets, script execution, and the host execution mode are deliberate configuration choices rather than defaults. The project is released under the MIT license.

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Security View all alternatives
  • Pentest Tools.com CLI & MCP Server logoPentest Tools.com CLI & MCP Server

    MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.

    ๐Ÿ”’ Security2 views
    Compare vs Pentest Tools.com CLI & MCP Server โ†’
  • Ida Pro MCP logoIda Pro MCP

    MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

    ๐Ÿ”’ Security4 views
    Compare vs Ida Pro MCP โ†’
  • Auth0 MCP Server logoAuth0 MCP Server

    Auth0 MCP Server: Manage Auth0 applications, APIs, actions, logs, and forms using natural language

    ๐Ÿ”’ Security2 views
    Compare vs Auth0 MCP Server โ†’
  • Agentward logoAgentward

    Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

    ๐Ÿ”’ Security6 views
    Compare vs Agentward โ†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks โ€” not a rating.

GitHub stars
66
Stargazers on the source repository.
npm downloads
20
Package downloads in the last 30 days.
Last commit
8d ago
Most recent push to the default branch.

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Cybersec Toolkit

cybersec-toolkit is an MCP server that connects AI clients to a registry of 670+ installed security tools for CTF, pentesting, bug bounty, DFIR, and blue-team work. Its main tools support discovery, recommendations, governed tool execution, pipelines, and separately gated script execution inside a Kata sandbox by default.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewCybersec Toolkit AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/cybersec-toolkit?style=directory)](https://allmcps.com/mcp/cybersec-toolkit)
HTML Embed
<a href="https://allmcps.com/mcp/cybersec-toolkit"><img src="https://allmcps.com/api/badge/cybersec-toolkit?style=directory" alt="Cybersec Toolkit on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ”’Security
More technical detailsExpand โ–พ
TransportSTDIO
RuntimePython
LicenseMIT
ClientsClaude Code, OpenAI Codex CLI, Gemini CLI, Claude Desktop, Cursor, Cline / VS Code, Windsurf, VS Code (GitHub Copilot), Zed, JetBrains AI Assistant, Roo Code, Continue, LM Studio
Last updatedOct 6, 2026
7/7 checks healthy over the last 45d
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars66
GitHub Star CountTotal stargazers on GitHub representing community popularity (66 stars).
Last commit8d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Oct 2, 2026
npm downloads20/mo
Monthly npm DownloadsAverage monthly package installs recorded from npm registry statistics.
43Quality signal: Fair ยท 43/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership7/20
Documentation & tools16/30
Adoption & activity9/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

1 high-severity advisory on record for this package. Most advisories affect transitive dependencies and may not be exploitable in this server's actual usage โ€” this is a directional signal, not a security audit.

Critical 1High 0Medium 0Low 1

Scanned 6d ago via OSV.dev ยท pwntools (PyPI)

โ˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ”’ Security โ†’Best MCP servers for Security โ†’Alternatives to Cybersec Toolkit โ†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients