MCP Tools Directory
← Browse integrations

Developer tools

io.github.cyanheads/attack-surface-mcp-server

Free account · sign-in required

Contact io.github.cyanheads/attack-surface-mcp-server

Loading secure sign-in…

Tools for autonomous AI agents

About this integration

Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.

Transport
stdio
Authentication
none
Initial setup
none
Runtime
unattended
Evidence
documented
Version
0.2.1
Package
@cyanheads/attack-surface-mcp-server
Last compatibility test
Not independently tested

Connect your agent

@cyanheads/attack-surface-mcp-server

Publisher README and executable manifest reviewed offline; package and provider endpoints were not executed or independently security-audited. Publisher documentation limits the tool to authorized passive defensive use; no package or target was executed during review.

Capabilities: Enumerate public subdomains, Inspect DNS, TLS, and HTTP posture, Look up registration and optional Shodan host data

Connected profiles

Additional details

Registry identifier

io.github.cyanheads/attack-surface-mcp-server

Source ↗ · Checked 2026-09-17
Published version

0.2.1

Source ↗ · Checked 2026-09-17
Metadata license

CC0-1.0; package licenses are separate

Source ↗ · Checked 2026-09-17
Package ecosystem

npm

Source ↗ · Checked 2026-09-17
Source artifact

@cyanheads/attack-surface-mcp-server

Source ↗ · Checked 2026-09-19
Source manifest version

0.2.1

Source ↗ · Checked 2026-09-19
Unattended configuration

Publisher documents a client-launched, non-interactive local MCP process. The documented configuration launches the npm package over stdio.

Source ↗ · Checked 2026-09-19
Authentication and prerequisites

The keyless core needs no API key; Shodan and Certspotter keys are optional additions for one tool or higher limits.

Source ↗ · Checked 2026-09-19
Connection configuration

The documented configuration launches the npm package over stdio.

Source ↗ · Checked 2026-09-19
Review scope

Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.

Source ↗ · Checked 2026-09-19