Security testing MCP server for penetration testing, forensics, and vulnerability assessment
[]( []( []( []( []( []( Security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. Add to your MCP config: — Test OR-based WHERE clause bypass — Test login form SQL injection — UNION-based data extraction — Boolean-based blind SQLi — Time-based blind SQLi — Read files via LOADFILE() — Test reflected XSS with 10 payloads —…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
idor_testNo description publishedThis tool published no description. Forge does not invent one.
role_escalation_testNo description publishedThis tool published no description. Forge does not invent one.
auth_csrf_extractNo description publishedThis tool published no description. Forge does not invent one.
auth_bruteforceNo description publishedThis tool published no description. Forge does not invent one.
auth_cookie_tamperNo description publishedThis tool published no description. Forge does not invent one.
price_manipulation_testNo description publishedThis tool published no description. Forge does not invent one.
coupon_abuse_testNo description publishedThis tool published no description. Forge does not invent one.
clickjacking_testNo description publishedThis tool published no description. Forge does not invent one.
frame_buster_bypassNo description publishedThis tool published no description. Forge does not invent one.
cloudtrail_analyzeNo description publishedThis tool published no description. Forge does not invent one.
cloudtrail_find_anomaliesNo description publishedThis tool published no description. Forge does not invent one.
cmdi_testNo description publishedThis tool published no description. Forge does not invent one.
cmdi_blind_detectNo description publishedThis tool published no description. Forge does not invent one.
cors_testNo description publishedThis tool published no description. Forge does not invent one.
deserialization_testNo description publishedThis tool published no description. Forge does not invent one.
file_upload_testNo description publishedThis tool published no description. Forge does not invent one.
graphql_introspectNo description publishedThis tool published no description. Forge does not invent one.
graphql_find_hiddenNo description publishedThis tool published no description. Forge does not invent one.
oob_start_listenerNo description publishedThis tool published no description. Forge does not invent one.
oob_poll_interactionsNo description publishedThis tool published no description. Forge does not invent one.
oob_generate_payloadNo description publishedThis tool published no description. Forge does not invent one.
maldoc_analyzeNo description publishedThis tool published no description. Forge does not invent one.
maldoc_extract_macrosNo description publishedThis tool published no description. Forge does not invent one.
volatility_linuxNo description publishedThis tool published no description. Forge does not invent one.
volatility_windowsNo description publishedThis tool published no description. Forge does not invent one.
memory_detect_rootkitNo description publishedThis tool published no description. Forge does not invent one.
nosqli_auth_bypassprivilegedNo description publishedThis tool published no description. Forge does not invent one.
nosqli_detectprivilegedNo description publishedThis tool published no description. Forge does not invent one.
pcap_overviewNo description publishedThis tool published no description. Forge does not invent one.
pcap_extract_credentialsNo description publishedThis tool published no description. Forge does not invent one.
pcap_dns_analysisNo description publishedThis tool published no description. Forge does not invent one.
pcap_http_objectsNo description publishedThis tool published no description. Forge does not invent one.
pcap_detect_scanNo description publishedThis tool published no description. Forge does not invent one.
pcap_follow_streamNo description publishedThis tool published no description. Forge does not invent one.
pcap_tls_analysisNo description publishedThis tool published no description. Forge does not invent one.
pcap_llmnr_ntlmNo description publishedThis tool published no description. Forge does not invent one.
race_single_packetNo description publishedThis tool published no description. Forge does not invent one.
race_last_byte_syncNo description publishedThis tool published no description. Forge does not invent one.
raw_http_sendNo description publishedThis tool published no description. Forge does not invent one.
raw_h2_smuggleNo description publishedThis tool published no description. Forge does not invent one.
0 of 40 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
[]( []( []( []( []( []( Security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. Add to your MCP config: — Test OR-based WHERE clause bypass — Test login form SQL injection — UNION-based data extraction — Boolean-based blind SQLi — Time-based blind SQLi — Read files via LOAD_FILE() — Test reflected XSS with 10 payloads — Generate context-aware XSS payloads — Test OS command injection — Blind command injection via sleep…
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This package was last scanned before Forge began storing the resolved tree. The next scan will record it.