io.github.cyanheads/attack-surface-mcp-server
Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.
Own this server? Screen its description →
SHODAN_API_KEYOptional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.
CERTSPOTTER_API_KEYOptional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.
ATTACKSURFACE_DEFAULT_RESOLVERSComma-separated default DNS resolver IPs for attacksurface_resolve_dns.
ATTACKSURFACE_HTTP_USER_AGENTDefault User-Agent for attacksurface_probe_http (overridable per call).
ATTACKSURFACE_MAX_SUBDOMAINSCap on subdomains resolved during a map_domain run.
ATTACKSURFACE_RDAP_BOOTSTRAP_URLRDAP bootstrap base URL; override for a private/mirrored RDAP.
ATTACKSURFACE_ALLOW_PRIVATE_TARGETSSet true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).
MCP_LOG_LEVELSets the minimum log level for output (e.g., 'debug', 'info', 'warn').
MCP_HTTP_HOSTThe hostname for the HTTP server.
MCP_HTTP_PORTThe port to run the HTTP server on.
MCP_HTTP_ENDPOINT_PATHThe endpoint path for the MCP server.
MCP_AUTH_MODEAuthentication mode to use: 'none', 'jwt', or 'oauth'.
MCP_LOG_LEVELSets the minimum log level for output (e.g., 'debug', 'info', 'warn').
GEO scores and content-rewrite suggestions for any web page, as MCP tools.
Real-world location intelligence: foot traffic, trade areas, demographics, site scoring, and more.
Deterministic AI governance platform. Validates agent outputs, discovers patterns, solves math.