About this integration
Discover mobile app attack surfaces via BeVigil OSINT — hosts, subdomains, URLs, and more.
- Transport
- stdio
- Authentication
- api-key
- Initial setup
- credentials
- Runtime
- unattended
- Evidence
- documented
- Version
- 1.1.0
- Package
- bevigil-mcp-server
- Last compatibility test
- Not independently tested
Connect your agent
bevigil-mcp-serverExisting identity and connection fields are preserved. Publisher documentation was reviewed without installing the package or spending API credits. Results are observed OSINT leads, not verified vulnerabilities; coverage is limited to indexed Android applications and each API request consumes credits.
Capabilities: Mobile application host and URL discovery, Subdomain and package reverse lookup, S3 reference and wordlist extraction, Combined application investigation reports
Connected profiles
Additional details
io.github.santhosh-005/bevigil
Source ↗ · Checked 2026-09-171.1.0
Source ↗ · Checked 2026-09-17CC0-1.0; package licenses are separate
Source ↗ · Checked 2026-09-17npm
Source ↗ · Checked 2026-09-17BEVIGIL_API_KEY
Source ↗ · Checked 2026-09-17bevigil-mcp-server
Source ↗ · Checked 2026-09-191.1.0
Source ↗ · Checked 2026-09-19The local stdio server is launched by npx and makes bounded requests to known BeVigil OSINT endpoints when tools are called.
Source ↗ · Checked 2026-09-19A BeVigil account and BEVIGIL_API_KEY are required; the key is passed through the MCP client environment.
Source ↗ · Checked 2026-09-19The existing listing remains stdio and spawns npx -y bevigil-mcp-server with BEVIGIL_API_KEY in its environment.
Source ↗ · Checked 2026-09-19Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.
Source ↗ · Checked 2026-09-19