MCP Security Hub

Offensive Security MCP Servers

A set of Dockerized MCP servers for offensive security tools: nmap, nuclei, sqlmap, radare2, ghidra and more, driven by an AI assistant

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Gives the agent scanning, exploitation and analysis tools
  • Built for offensive security; use only on your own systems and with authorization
  • Some servers reach external services and require secret keys
All reasons and checks

fuzzinglabs/mcp-security-hub

Install

Manual install

git clone https://github.com/FuzzingLabs/mcp-security-hub
cd mcp-security-hub
docker-compose build
docker-compose up nmap-mcp nuclei-mcp -d

Build the images and start the servers you need.

This is third-party code. Review the repository files before installing.

What it does

The repository gathers dozens of MCP servers by category: reconnaissance, web security, binary analysis, cloud, secrets detection, OSINT, threat intelligence, fuzzing and more. Each server is a separate Docker image that gives an AI client access to a specific tool through natural language. Some servers are written by the authors, others wrap third-party MCP projects. Orchestration runs through docker-compose, images are built to run without root and are Trivy-scanned in CI.

Who it is for. For offensive security specialists who want one collection of MCP tools for authorized assessments.

Good fit when

  • You want one repository of MCP servers for different security tasks
  • You want to isolate tools in Docker containers
  • You build a multi-tool workflow through docker-compose

Not a fit when

  • You lack written authorization from the target owner and a defined scope
  • You assess third-party resources without authorization
  • You cannot run Docker with the required privileges

Example request

Scan my lab host example.internal with nuclei and show the issues found

Limitations

Each server must be built as a Docker image first, and several servers wrap third-party projects with their own requirements and API keys. Some tools need extended container network capabilities. The tools are for authorized testing only; the authors list the requirements plainly: written authorization, scope, audit logs, responsible disclosure.

How to disable. Stop the containers with docker-compose down, remove the server entries from the MCP client config and remove the built images with the standard Docker commands.

MCP

Transport
stdio
Authentication
API key
Environment variables
Environment variables
API keys per wrapped server
secret
Individual wrapper servers require their own keys, for example Shodan, VirusTotal, ZoomEye. See the README of the specific server.

Security check

  • Gives the agent scanning, exploitation and analysis tools
  • Built for offensive security; use only on your own systems and with authorization
  • Some servers reach external services and require secret keys

README in short

The README lists servers by category with tool counts and marks which ones wrap third-party projects. It has a docker-compose quick start, a config example for Claude Desktop and Claude Code, a container hardening table and the project structure. It shows examples of network recon, vulnerability assessment and firmware analysis. A separate legal section covers authorization, scope, logs and responsible disclosure.

FAQ

Are all servers written by the authors?

No. Some are original, some wrap third-party MCP projects with their own dependencies and keys.

Is Docker required?

Yes. The servers ship as Docker images that you build before connecting them to a client.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIMCP Security Hub

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.