Governed MCP access to 670+ security tools for CTF, pentesting, bug bounty, DFIR, and blue-team workflows.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ we're steadily working through the catalog.
๐ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Cybersec Toolkit.
The cybersec-toolkit MCP server exposes an installed security-tool collection to MCP-compatible AI clients. The repository describes more than 670 tools organized into 18 modules and 14 profiles, covering activities such as CTF work, penetration testing, bug bounty research, digital forensics and incident response, and blue-team analysis. It also includes 872 Agent Skills that provide procedural context for these workflows, although the skills remain outside the tool-execution path.
An agent can inspect the registry, get recommendations, and request governed execution through 15 MCP tools. The system is intended to support an operator working with an agent by default. An autonomous solver loop is available only when explicitly authorized.
The installer places tools on the host or prepares them inside the sandbox image. The MCP server and installer use tools_config.json as their shared registry, so the server can reason about the tools installed by the selected modules and profiles.
The cybersec-toolkit MCP server starts through a root-aware launcher. In its default configuration, the launcher boots one disposable Kata Containers VM per client session. The VM uses a separate kernel, runs as a non-root user with capabilities removed, and applies memory, CPU, and process limits. It does not expose the host filesystem except for an optional workspace mount and does not receive a Docker socket.
Execution is controlled by security.py. Governed tools use direct subprocess execution rather than a shell, with registry allowlists, argument sanitization, blocked-flag checks, target and network policy, rate limiting, timeouts, and output limits. External targets and arbitrary script execution are disabled by default. The separate run_script capability requires an explicit opt-in.
Clone the repository and run the installer on a supported Linux distribution or Termux. The documented quick start uses ./install.sh --doctor for a read-only preflight, followed by a profile installation such as sudo ./install.sh --profile ctf. Without profile restrictions, the installer can install all modules.
Sandbox mode requires Linux with KVM, Docker 23 or newer with a Kata runtime, and Node.js 22 or newer. Build the sandbox image with make sandbox-image, then install sandbox dependencies with npm --prefix sandbox ci --ignore-scripts. macOS, Windows, and virtual machines without nested virtualization should use host mode instead. Host mode requires uv and can be selected with the launcher's --local option or CYBERSEC_SANDBOX_MODE=local.
Tracked configurations are provided for Claude Code, Codex, Gemini CLI, and OpenCode through scripts/mcp-launch.sh. After connecting a client, restart it so the MCP tools become available.
The cybersec-toolkit MCP server supports these categories of work:
The default network policy rejects targets that resolve outside private or loopback ranges. Operators can configure external access explicitly, but the address check is not a firewall. A filtered Docker network or CYBERSEC_SANDBOX_NETWORK=none may be needed for stronger network isolation.
The sandbox is the default isolation layer, not a complete network boundary. Tools can reach whatever the Docker network permits, and allowed tools run with the server user's permissions. Some tools may spawn child processes or load plugins. Host mode removes the VM boundary and runs tools on the host as the server user.
The repository is designed for authorized security work. External targets, script execution, and the host execution mode are deliberate configuration choices rather than defaults. The project is released under the MIT license.
Factual signals from GitHub, npm, and our automated checks โ not a rating.
No reviews yet โ be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/cybersec-toolkit)<a href="https://allmcps.com/mcp/cybersec-toolkit"><img src="https://allmcps.com/api/badge/cybersec-toolkit?style=directory" alt="Cybersec Toolkit on AllMCPs" /></a>