Model or dataset
FuzzingLabs/mcp-security-hub avatar
FuzzingLabs/mcp-security-hub

mcp-security-hub: 38 Dockerized MCP Servers for Offensive Security Tools

A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.

797 stars102 forksPythonMIT

At a glance

What is it?
mcp-security-hub is an MIT-licensed collection of 38 Dockerized MCP servers that expose offensive security tools to AI assistants via the Model Context Protocol. Reconnaissance, vulnerability scanning, binary analysis, blockchain security, cloud auditing, and secrets detection are all covered, with Docker Compose managing the multi-tool fleet.
Who is it for?
mcp-security-hub is a useful starting point for security practitioners who want to drive penetration testing tools through Claude or another MCP-compatible AI assistant rather than through raw CLI. Its Docker Compose orchestration and Claude Desktop JSON config pattern remove the setup friction for each tool.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 176 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the Hub Provides and Who It Is For

The Model Context Protocol (MCP) lets an AI assistant call external tools by sending structured requests to MCP servers that return structured results. mcp-security-hub packages 38 such servers, each wrapping a different security tool in a Dockerized MCP interface. The result is that a Claude session with the relevant servers configured can run an Nmap port scan, feed the results to Nuclei for vulnerability template matching, and pull a binary into Ghidra for reverse engineering, all described in natural language without manual CLI invocation.

The intended users are security engineers and penetration testers who want to integrate AI assistance into their toolchain. The README frames this as performing security assessments, vulnerability scanning, and binary analysis through Claude or other MCP clients. The tools are standard penetration testing and security research tools: they are appropriate for authorized testing, security audits, CTF work, and lab environments.

The hub covers twelve security categories: reconnaissance, web security, binary analysis, blockchain security, cloud security, code security, secrets detection, threat intelligence, OSINT, active directory, fuzzing, and exploitation. Some servers wrap tools directly (nmap-mcp, nuclei-mcp, sqlmap-mcp), while others are wrappers around existing third-party MCP implementations (shodan-mcp wraps the official Shodan MCP, ghidra-mcp wraps pyghidra-mcp).

Installation and Claude Desktop Configuration

The setup requires Docker and Docker Compose. Clone the repository, build the images, then start the specific servers you need:

bash
git clone https://github.com/FuzzingLabs/mcp-security-hub
cd mcp-security-hub
docker-compose build
docker-compose up nmap-mcp nuclei-mcp -d
docker-compose ps

The README emphasizes that building the images first with docker-compose build is required before attempting to use them. To connect the servers to Claude Desktop, copy the example config or write the relevant entries to the Claude Desktop configuration file. On macOS the path is ~/Library/Application Support/Claude/claude_desktop_config.json; on Windows it is %APPDATA%\Claude\claude_desktop_config.json:

json
{
  "mcpServers": {
    "nmap": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "--cap-add=NET_RAW", "nmap-mcp:latest"]
    },
    "nuclei": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "nuclei-mcp:latest"]
    }
  }
}

Some servers need additional capabilities or volume mounts. Nmap requires NET_RAW for raw socket scanning. Gitleaks and Radare2 need volume mounts pointing at the repositories or binaries to analyze, as shown in the examples/ directory.

For project-level configuration, copy .mcp.json to your project root instead of editing the global Claude Desktop file. The examples/ directory includes full configuration templates with all MCP servers and volume mount patterns.

Reconnaissance and Web Security Coverage

The eight reconnaissance servers include nmap-mcp (port scanning, service detection, OS fingerprinting, NSE scripts, 8 tools), masscan-mcp (high-speed port scanning for large networks, 6 tools), and whatweb-mcp (web technology fingerprinting and CMS detection, 5 tools). Shodan, ZoomEye, and ProjectDiscovery tool integrations are present as wrappers, meaning they delegate to existing MCP implementations rather than wrapping the tools directly.

The six web security servers span template-based vulnerability scanning via nuclei-mcp (7 tools, 8000+ Nuclei templates), SQL injection detection and exploitation via sqlmap-mcp (8 tools), web fuzzing via ffuf-mcp (9 tools for directories, files, parameters, and virtual hosts), historical URL retrieval from the Wayback Machine via waybackurls-mcp, and a wrapper for the official Burp Suite MCP server.

The broad template count in nuclei-mcp is worth noting: 8000+ templates means coverage across a wide range of CVEs and misconfiguration patterns without writing custom checks. ffuf-mcp's nine tools cover the different fuzzing modes (vhost, directory, parameter) as distinct tool calls rather than a single configurable mode, which fits the MCP tool model better.

Binary Analysis, Blockchain, and Cloud Security

The binary analysis section has six servers. radare2-mcp wraps the official radare2 MCP and provides 32 tools covering disassembly and decompilation. binwalk-mcp handles firmware analysis, signature scanning, and extraction (6 tools). yara-mcp exposes pattern matching for malware classification (7 tools). capa-mcp detects capabilities in executables (5 tools). ghidra-mcp and ida-mcp are wrappers for existing headless reverse engineering MCP servers.

Blockchain security covers a DAML access-control table generator, a high-performance smart contract fuzzer for Solidity (medusa-mcp, 4 tools), and a Solana sBPF static analysis and reverse engineering server (solazy-mcp, 8 tools). These are specific enough to be useful for teams auditing smart contracts, where the tooling is otherwise fragmented.

Cloud security provides three servers: trivy-mcp for container, filesystem, and IaC vulnerability scanning (7 tools), prowler-mcp for AWS, Azure, and GCP security auditing and compliance (6 tools), and roadrecon-mcp for Azure AD enumeration. The gitleaks-mcp server in the secrets detection category handles credentials and secrets scanning in git repositories and files (5 tools).

Container Security Posture and Limitations

All containers run as non-root (uid 1000). The images use a dedicated bridge network, read-only filesystems where possible, and all capabilities are dropped by default with only the specific capabilities each tool needs added back. The images are scanned with Trivy as part of the GitHub Actions CI pipeline.

The security posture of the containers is better than a default Docker setup, but using offensive security tools through an AI assistant introduces a different risk: the tool operates correctly but an AI could chain tool calls in ways that are broader or faster than a human would manually. An AI assistant that has Nmap, SQLMap, and Nuclei connected can scan a target, identify an injection point, and attempt to exploit it in rapid succession. This is useful for authorized penetration testing but creates an operational risk in misconfigured environments. The README does not address this consideration explicitly, and users need to evaluate which servers to enable for which sessions.

Another practical limitation is that many of the wrapper servers (Shodan, ZoomEye, Burp Suite, IDA Pro, Ghidra) delegate to external projects and may have different update cadences or additional configuration requirements not documented in this repository's README.

Comparison with Using Tools Directly and Maintenance Status

The primary alternative to mcp-security-hub is using the underlying tools directly from the CLI, which every security professional who uses these tools already does. The hub's value is the MCP interface: instead of memorizing flags, constructing pipelines manually, and interpreting raw output, a security engineer can describe what they need in natural language and let the model handle the command construction and result interpretation.

This does not replace expert knowledge. Understanding what Nmap's NSE scripts do, what Nuclei template categories to search, or what capa's capability detection results mean requires domain expertise. The MCP interface reduces the friction of invocation, not the need for expertise to interpret results.

Comparable projects include individual tool-specific MCP servers available on GitHub for Nmap, Nuclei, and others separately. mcp-security-hub's value over maintaining those separately is the unified Docker Compose orchestration and the breadth of coverage across 38 servers. The downside is that updates to individual wrapped tools require updating this hub rather than the upstream server project.

The last push was on 2026-04-08. The repository has no GitHub releases.

Editorial conclusion

mcp-security-hub is a useful starting point for security practitioners who want to drive penetration testing tools through Claude or another MCP-compatible AI assistant rather than through raw CLI. Its Docker Compose orchestration and Claude Desktop JSON config pattern remove the setup friction for each tool. The collection is best used in controlled lab environments or authorized engagement contexts: these are real offensive tools, and connecting them to an AI assistant that can chain multiple operations raises the importance of understanding what each tool does before asking an agent to run it. The last push was on 2026-04-08 and the project is MIT-licensed.

Frequently asked questions

What is an MCP in security?

In this context, MCP stands for Model Context Protocol, an interface standard that lets AI assistants call external tools through structured requests and responses. mcp-security-hub packages 38 offensive security tools as MCP servers so they can be invoked through Claude or other MCP clients.

What is a MCP server hub?

An MCP server hub is a collection of Model Context Protocol servers managed together, typically with shared orchestration tooling. mcp-security-hub uses Docker Compose to manage all 38 servers so individual tools can be started, stopped, and configured from a single compose file.

Are MCP servers a security risk?

mcp-security-hub's containers run as non-root with dropped capabilities and Trivy-scanned images. The larger operational risk is that connecting offensive tools like SQLMap and Nuclei to an AI assistant allows rapid, automated attack chaining in authorized testing sessions, which requires careful access control over which servers are enabled in which contexts.

Official sources

  1. FuzzingLabs/mcp-security-hub on GitHub
  2. Issues
  3. License: MIT
  4. Project website
  5. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/fuzzinglabs-mcp-security-hub.svg)](https://hysenlabs.com/projects/fuzzinglabs-mcp-security-hub)