pentestMCP strictly adheres to the MCP specification, functioning solely as an **MCP Server**. It does not embed or directly communicate with any
Pentestmcp MCP server is a locally run integration for AI assistants that speak the Model Context Protocol. pentestMCP strictly adheres to the MCP specification, functioning solely as an MCP Server. It does not embed or directly communicate with any specific LLM. The interaction flow is mediated by an MCP Client Host application:.
Setup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client.
Once Pentestmcp is connected, these are the calls the assistant has available:
Non — Blocking Scans:** Efficiently handles long-running scans without locking up the interaction flowmacOS — ** ~/Library/Application Support/Claude/claude_desktop_config.jsonWindows — ** %APPDATA%\Claude\claude_desktop_config.jsonrun_subfinder — Discovers subdomains using ProjectDiscovery's Subfinderrun_dig_tool — Executes DNS dig queriesfetch_whois_data — Retrieves WHOIS information for a domainrun_curl_tool — Executes cURL commands for HTTP interactionrun_searchsploit — Searches the local Exploit-DB database using SearchsploitEnumeration — ** ad_user_enum, ad_shares_enum, ad_smb_signing_check, ad_certipy_enum, ad_ldap_dump, ad_bloodhound_collectgit clone step). * (Optional but Recommended) OWASP ZAP Instance: For using ZAP-related tools (run_zap_*, run_active_scan_*, run_ajax_*). This ZAP instance needs to be running andThis sits in the database access group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Pentestmcp's toolset — Non, macOS, Windows and 6 more — is a fair guide to whether it matches your workflow. It is maintained by ramkansal; worth a glance at recent repository activity before you build anything load-bearing on it.
This entry was verified against Pentestmcp's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.
| Tool | What it does |
|---|---|
| Non | Blocking Scans:** Efficiently handles long-running scans without locking up the interaction flow. |
| macOS | ** ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | ** %APPDATA%\Claude\claude_desktop_config.json |
| run_subfinder | Discovers subdomains using ProjectDiscovery's Subfinder. |
| run_dig_tool | Executes DNS dig queries. |
| fetch_whois_data | Retrieves WHOIS information for a domain. |
| run_curl_tool | Executes cURL commands for HTTP interaction. |
| run_searchsploit | Searches the local Exploit-DB database using Searchsploit. |
| Enumeration | ** ad_user_enum, ad_shares_enum, ad_smb_signing_check, ad_certipy_enum, ad_ldap_dump, ad_bloodhound_collect |
git clone step). * (Optional but Recommended) OWASP ZAP Instance: For using ZAP-related tools (run_zap_*, run_active_scan_*, run_ajax_*). This ZAP instance needs to be running andRead-only SQL access to Postgres — let your assistant inspect schemas and answer questions from real data.
Manage your whole Supabase project in conversation — database, auth, storage, Edge Functions and branches.
Query, modify and analyse local SQLite databases in conversation — the fastest way to chat with a data file.
Metabase ships its own MCP endpoint — search your BI content, build and run queries, and save questions and dashboards without leaving the chat.
Official MongoDB server covering data, schemas and Atlas management — from find queries to spinning up clusters.
Serverless Postgres with database branching — point your assistant at Neon and let it work on disposable copies.