FofaMap

A FOFA-based asset reconnaissance agent: turns a natural-language request into searches, builds an evidence-bounded report and scans only after approval

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Runs active external asset reconnaissance through FOFA
  • Can run Nuclei scans against external targets after approval
All reasons and checks

asaotomo/fofamap

Install

Manual install

git clone https://github.com/asaotomo/FofaMap.git
cd FofaMap
python -m pip install -e .

Needs Python 3.10+ and a FOFA API key (export FOFA_API_KEY=...). Active scanning needs a local Nuclei.

This is third-party code. Review the repository files before installing.

What it does

FofaMap ties FOFA asset reconnaissance, evidence retrieval, model self-reflection and approval-gated Nuclei scanning into one traceable chain. It runs classic FOFA queries like an ordinary CLI and can break one phrase into several queries, refining them against real hits. The result is a report marked as corroborated, observed and candidate assets, and search hits are not passed off as final attribution. For agents there is an MCP with 15 tools and a multi-host skill, and active Nuclei scanning starts only after a one-time approval of the targets, templates and severity.

Who it is for. For security and asset-reconnaissance specialists who work with FOFA through an agent.

Good fit when

  • You need to find an organization's assets and mark them by evidence level
  • You need to turn a natural-language request into a set of FOFA queries
  • You need a baseline Nuclei scan with explicit approval

Not a fit when

  • You have no FOFA account and API key
  • You want to scan assets you are not authorized to touch

Example request

Find this organization's external assets through FOFA and build a report marked by evidence level, without active scanning

Limitations

It requires a FOFA API key, and active scanning needs a locally installed Nuclei and an explicitly enabled scan capability. Install is from source via pip. Keys are stored in the system keychain or, when unavailable, in a local file with restricted permissions. The tool is meant for authorized reconnaissance, and legality is the user's responsibility.

How to disable. Remove the MCP entry or skill from the agent config and uninstall the source-installed package; clear the keys from the keychain or config.

MCP

Transport
stdio
Authentication
API key
Environment variables
Environment variables
FOFA_API_KEY
required, secret
FOFA account API key for asset search.

Security check

  • Runs active external asset reconnaissance through FOFA
  • Can run Nuclei scans against external targets after approval

README in short

The README describes FofaMap as a FOFA-based asset reconnaissance agent that converges CLI, agent, MCP, skill and REST onto one contract. Classic queries work without a model, while natural language is planned into several queries with self-reflection and up to two rounds of fixes. Asset collection marks results as corroborated, observed and candidate with evidence. Active Nuclei scanning runs only after a one-time approval of targets, templates and severity. Install is from source via pip, the FOFA key lives in the system keychain, and platforms are Windows, macOS and Linux.

FAQ

Does it scan on its own?

No. It first builds a plan, and Nuclei scanning runs only after a one-time approval of targets, templates and severity; -batch does not bypass it.

Is a separate model key needed?

Over MCP the host provides the model, so a second key set is usually not needed, but a FOFA key is required.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIFofaMap

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.