Security testing MCP server offering 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ we're steadily working through the catalog.
๐ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Operant MCP.
sqli_where_bypassTest OR-based WHERE clause bypass
sqli_login_bypassTest login form SQL injection
sqli_union_extractUNION-based data extraction
sqli_blind_booleanBoolean-based blind SQLi
sqli_blind_timeTime-based blind SQLi
sqli_file_readRead files via LOAD_FILE()
Security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment.
Or install globally:
Add to your MCP config:
sqli_where_bypass โ Test OR-based WHERE clause bypasssqli_login_bypass โ Test login form SQL injectionsqli_union_extract โ UNION-based data extractionsqli_blind_boolean โ Boolean-based blind SQLisqli_blind_time โ Time-based blind SQLisqli_file_read โ Read files via LOAD_FILE()xss_reflected_test โ Test reflected XSS with 10 payloadsxss_payload_generate โ Generate context-aware XSS payloadscmdi_test โ Test OS command injectioncmdi_blind_detect โ Blind command injection via sleep timingpath_traversal_test โ Test directory traversal with encoding variantsssrf_test โ Test SSRF with localhost bypass variantsssrf_cloud_metadata โ Test cloud metadata access via SSRFpcap_overview โ Protocol hierarchy and endpoint statspcap_extract_credentials โ Extract FTP/HTTP/SMTP credentialspcap_dns_analysis โ DNS query analysispcap_http_objects โ Export HTTP objectspcap_detect_scan โ Detect port scanningpcap_follow_stream โ Follow TCP/UDP streamspcap_tls_analysis โ TLS/SNI analysispcap_llmnr_ntlm โ Detect LLMNR/NTLM attacksrecon_quick โ Quick recon (robots.txt, headers, common dirs)recon_dns โ Full DNS enumerationrecon_vhost โ Virtual host discoveryrecon_tls_sans โ Extract SANs from TLS certificatesrecon_directory_bruteforce โ Directory brute-forcerecon_git_secrets โ Search git repos for secretsrecon_s3_bucket โ Test S3 bucket permissionsvolatility_linux โ Linux memory analysis (Volatility 2)volatility_windows โ Windows memory analysis (Volatility 3)memory_detect_rootkit โ Linux rootkit detectionmaldoc_analyze โ Full OLE document analysis pipelinemaldoc_extract_macros โ Extract VBA macroscloudtrail_analyze โ CloudTrail log analysiscloudtrail_find_anomalies โ Detect anomalous CloudTrail eventsauth_csrf_extract โ Extract CSRF tokensauth_bruteforce โ Username enumeration + credential brute-forceauth_cookie_tamper โ Cookie tampering testidor_test โ Test for IDOR vulnerabilitiesrole_escalation_test โ Test privilege escalationprice_manipulation_test โ Test price/quantity manipulationcoupon_abuse_test โ Test coupon stacking/reuseclickjacking_test โ Test X-Frame-Options/CSPframe_buster_bypass โ Test frame-busting bypasscors_test โ Test CORS misconfigurationsfile_upload_test โ Test file upload bypassesnosqli_auth_bypass โ MongoDB auth bypassnosqli_detect โ NoSQL injection detectiondeserialization_test โ Test insecure deserializationgraphql_introspect โ Full schema introspectiongraphql_find_hidden โ Discover hidden fieldsMethodology guides for structured security assessments:
web_app_pentest โ Full web app pentest methodologypcap_forensics โ PCAP analysis workflowmemory_forensics โ Memory dump analysis (Linux/Windows)recon_methodology โ Reconnaissance checklistmalware_analysis โ Malware document analysiscloud_security_audit โ CloudTrail analysis workflowsqli_methodology โ SQL injection testing guidexss_methodology โ XSS testing guideTools require various CLI utilities depending on the module:
curltshark (Wireshark CLI)dig, hostvolatility / vol.py / vol3olevba, oledump.pyjqgitMIT
Factual signals from GitHub, npm, and our automated checks โ not a rating.
No reviews yet โ be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/operantlabs-operant-mcp)<a href="https://allmcps.com/mcp/operantlabs-operant-mcp"><img src="https://allmcps.com/api/badge/operantlabs-operant-mcp?style=directory" alt="Operant MCP on AllMCPs" /></a>