Nobody Pentest MCP Server v2
MCP server yang menghubungkan Claude Code dengan Nobody AI Pentest Engine. v2: Real tool execution -- tools dijalankan secara lokal, bukan hanya prompt ke API.
Features
Real Executors (lokal, tidak perlu API)
- port_scan: nmap port scan + service detection + vuln suggestions
- web_audit: technology detection, security headers, misconfigs, dir enumeration, SQLi/XSS indicators
- cve_search: CVE databases (NIST NVD + circl.lu) + exploit references
- payload_gen: reverse shell, bind shell, web shell, SQLi, XSS, command injection templates
AI-Based (via Nobody API)
- exploit_gen: AI-generated exploit code
- code_audit: AI-powered SAST
- report: AI-formatted pentest report
- custom: AI general pentest
Quick Setup
Install (Recommended)
pip install nobody-pentest-mcp
Add to Claude Code
# First, find where nobody-pentest-mcp is installed
python -c "import nobody_pentest_mcp.server; print(nobody_pentest_mcp.server.__file__)"
# Output: C:\...\Lib\site-packages\nobody_pentest_mcp\server.py
# Then add to Claude Code using the full path
claude mcp add nobody-pentest -- python "C:\...\Lib\site-packages\nobody_pentest_mcp\server.py"
# Using your own API key (for external endpoints)
claude mcp add nobody-pentest -e NOBODY_API_KEY=sk-nobody-xxx -- python "C:\...\Lib\site-packages\nobody_pentest_mcp\server.py"
Note: Claude Code does not support
python -msyntax. Use full path to server.py instead.
Manual Setup
# Install dependencies
pip install mcp httpx python-nmap
# Run server
python -m nobody_pentest_mcp.server
Requirements
- Python 3.10+
- nmap (for port scanning) -- https://nmap.org/download.html
- mcp pip package
- httpx pip package
- python-nmap pip package (optional, nmap CLI works too)
- NOBODY_API_KEY (optional for Nobody AI endpoint, required for external endpoints)
API Key
Using Default Nobody AI Endpoint (v2.nobody0x.com)
API key is optional. The default endpoint handles authentication automatically.
# Just install and use
pip install nobody-pentest-mcp
claude mcp add nobody-pentest nobody-pentest-mcp
Using External Endpoints (OpenAI, OpenRouter, etc.)
API key is required. Set it via environment variable or .env file.
# Set API key
export NOBODY_API_KEY=sk-your-key-here
# Or use .env file
echo "NOBODY_API_KEY=sk-your-key-here" > .env
Architecture
User (Claude Code)
| MCP protocol (tool call)
Nobody Pentest MCP Server (local)
|-- REAL EXECUTION: nmap, httpx, CVE APIs, templates
|-- AI EXECUTION: POST /v1/messages -> Backend AI
v
Results returned to Claude Code
Tools
| Tool | Executor | API Required |
|---|---|---|
nobody_pentest_scan |
nmap (local) | No |
nobody_pentest_web_audit |
httpx + manual checks (local) | No |
nobody_pentest_cve_search |
NVD + circl.lu APIs (local) | No |
nobody_pentest_payload_gen |
Templates (local) | No |
nobody_pentest_exploit_gen |
Nobody AI API | Yes (external only) |
nobody_pentest_code_audit |
Nobody AI API | Yes (external only) |
nobody_pentest_report |
Nobody AI API | Yes (external only) |
nobody_pentest_custom |
Nobody AI API | Yes (external only) |
Environment Variables
| Variable | Default | Description |
|---|---|---|
NOBODY_API_KEY |
(none) | API key (optional for Nobody AI endpoint) |
NOBODY_API_URL |
https://v2.nobody0x.com/v1/messages |
API endpoint |
NOBODY_MODEL |
nobody-pentest |
Model name |
NMAP_PATH |
nmap |
Path to nmap binary |
SCAN_TIMEOUT |
300 |
Max scan time in seconds |
HTTP_TIMEOUT |
15.0 |
HTTP request timeout |
Metadata
Release files for nobody-pentest-mcp 2.0.6
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nobody_pentest_mcp-2.0.6.tar.gz | 37.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nobody_pentest_mcp-2.0.6-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 58.2 kB
Release files / nobody_pentest_mcp-2.0.6.tar.gz
| Download URL | nobody_pentest_mcp-2.0.6.tar.gz |
|---|---|
| Size | 37.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
77148a7ee3c6fc176ba2da34140cd11b4093c9be49f3fb66da065d61e960f7b4
|
|
BLAKE2b-256 checksum How to use checksums |
b2f3fa45c689b194011e2d0472102fe0a16fc2b22b787792a8457cb7f79b119b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.10
|
Release files / nobody_pentest_mcp-2.0.6-py3-none-any.whl
| Download URL | nobody_pentest_mcp-2.0.6-py3-none-any.whl |
|---|---|
| Size | 21.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2dcc8402636d1b791cde2be96e6aaf513bd6e03dde27e88c0e0bc779a9041bab
|
|
BLAKE2b-256 checksum How to use checksums |
28726ec554f89979df6cafd42ef884aa08d18b3c6bfd433afaff062eb31d6900
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.10
|