Skip to main content

Nobody Pentest Ultra MCP Server

150+ security tools with AI-powered analysis via Nobody AI backend.

MCP server yang menghubungkan Claude Code, GPT, Copilot, atau MCP-compatible agent dengan 150+ tools keamanan.

Features

150+ Security Tools

Category Tools Count
Network Recon nmap, masscan, rustscan, amass, subfinder, fierce, dnsenum, autorecon, theharvester, arp-scan, enum4linux, smbmap, netexec, responder 14+
Web App gobuster, feroxbuster, ffuf, dirsearch, httpx, katana, nuclei, nikto, sqlmap, wpscan, dalfox, wafw00f, wfuzz, commix, nosqlmap, tplmap, testssl, sslscan, sslyze, whatweb, jwt_tool, paramspider, arjun, x8, hakrawler, gau, waybackurls 27+
Auth/Brute hydra, john, hashcat, medusa, evil-winrm, hashid 6+
Binary/RE ghidra, radare2, gdb, binwalk, checksec, strings, objdump, volatility, foremost, steghide, exiftool, msfvenom, ROPgadget, one_gadget, upx, pwntools 16+
Cloud prowler, trivy, kube-hunter, kube-bench, docker-bench, scout-suite, cloudmapper, checkov, falco 9+
CTF/Forensics volatility3, stegsolve, zsteg, outguess, bulk-extractor, scalpel, autopsy 7+
OSINT sherlock, recon-ng, spiderfoot, shodan, censys, social-analyzer, trufflehog 7+

AI-Powered Analysis

  • Tool Selection: AI selects the best tool for each task
  • Parameter Optimization: AI optimizes tool parameters
  • Attack Chain Discovery: AI finds attack paths
  • Report Generation: AI creates professional pentest reports

Smart Features

  • Auto-detect: Detects if tools are installed
  • Graceful Fallback: Suggests installation for missing tools
  • Caching: Smart result caching
  • Timeout: Configurable timeouts

Quick Setup

Install

pip install nobody-pentest-ultra

Add to Claude Code

# First, find where nobody-pentest-ultra is installed
python -c "import nobody_pentest_ultra.server; print(nobody_pentest_ultra.server.__file__)"
# Output: C:\...\Lib\site-packages\nobody_pentest_ultra\server.py

# Then add to Claude Code using the full path
claude mcp add nobody-pentest-ultra -- python "C:\...\Lib\site-packages\nobody_pentest_ultra\server.py"

# With API key (external endpoints)
claude mcp add nobody-pentest-ultra -e NOBODY_API_KEY=sk-nobody-xxx -- python "C:\...\Lib\site-packages\nobody_pentest_ultra\server.py"

Note: Claude Code does not support python -m syntax. Use full path to server.py instead.

Add to OpenCode

Add to your opencode.json or opencode.jsonc project config:

{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "nobody-pentest-ultra": {
      "type": "local",
      "command": ["npx", "-y", "nobody-pentest-ultra"],
      "enabled": true
    }
  }
}

If installed via pip (not npx), use python -m:

{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "nobody-pentest-ultra": {
      "type": "local",
      "command": ["python", "-m", "nobody_pentest_ultra.server"],
      "enabled": true,
      "environment": {
        "NOBODY_API_KEY": "sk-nobody-xxx"
      }
    }
  }
}

Tip: OpenCode supports -m syntax, so python -m nobody_pentest_ultra.server works directly.

After adding the config, restart OpenCode. All 150+ security tools will be available as MCP tools.

Restart Claude Code

> Scan example.com for all vulnerabilities
> Perform full web app security test on target.com
> Enumerate subdomains for company.com

Usage Examples

Network Scanning

> Scan 192.168.1.1 for open ports and services
> Run masscan on 10.0.0.0/24
> Enumerate subdomains for example.com

Web Application Testing

> Test example.com for SQL injection
> Enumerate directories on target.com
> Scan for XSS vulnerabilities
> Check SSL/TLS configuration

Complete Pentest

> Perform full penetration test on example.com
> Run all security checks on target.com

Tool Installation

Why tools are not bundled

Nobody Pentest Ultra is a Python orchestration layer — it manages and executes 86+ industry-standard security tools. These tools are native binaries (C, Go, Rust, Java) maintained independently by their respective projects. Bundling them would mean:

  • Size: 86 native binaries would exceed 5GB — PyPI limit is 100MB
  • Platform lock: Each tool needs different compilation for Linux/macOS/Windows
  • Stale versions: Bundled binaries wouldn't get security patches
  • Dependency conflicts: Ghidra needs JDK 17, Masscan needs libpcap-dev, Nuclei needs Go 1.21+

This is the industry standard. Metasploit, Cobalt Strike, HexStrike AI — none bundle their tools.

Auto-Install Engine (recommended)

v3.0 includes a cross-platform auto-install engine. Set AUTO_INSTALL=true and tools are installed on-demand:

# Enable auto-install
export AUTO_INSTALL=true

# Tools will be installed automatically when first used:
# - nmap_scan -> apt install nmap / brew install nmap / choco install nmap
# - nuclei_scan -> go install nuclei@latest
# - sqlmap_scan -> pip install sqlmap
# - and 83 more...

The engine detects your OS and picks the right package manager — apt, brew, choco, winget, pacman, dnf, yum, pip, npm, go, cargo.

Manual Installation (optional)

Prefer full control? Install tools you need:

# === Recommended: Install all common tools at once ===
# Linux (Kali/Ubuntu)
curl -sL https://nobody0x.com/install-tools.sh | bash

# macOS
brew install nmap masscan nikto sqlmap binwalk radare2

# Windows (PowerShell as Admin)
choco install nmap masscan -y
pip install sqlmap

# === Or install per category ===
# Network Recon
apt install nmap masscan arp-scan dnsenum
go install github.com/owasp-amass/amass/v4/...@master
go install github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest

# Web Application
go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
go install github.com/projectdiscovery/httpx/cmd/httpx@latest
go install github.com/OJ/gobuster/v3@latest
pip install sqlmap wpscan wafw00f

# Authentication
apt install hydra john hashcat

# Binary Analysis
apt install radare2 gdb binwalk foremost steghide
pip install pwntools ROPgadget

# Cloud
pip install prowler checkov
go install github.com/aquasecurity/trivy/cmd/trivy@latest

# OSINT
pip install sherlock-cli social-analyzer
go install github.com/trufflesecurity/trufflehog/v3@latest

Check Installed Tools

# Dry-run: see which tools would be auto-installed
nobody-pentest-ultra --dry-run

Environment Variables

Variable Default Description
NOBODY_API_KEY (none) API key for AI analysis (optional for Nobody endpoint)
NOBODY_API_URL https://v2.nobody0x.com/v1/messages AI backend URL
NOBODY_MODEL nobody-pentest AI model name
SCAN_TIMEOUT 300 Max scan time in seconds
HTTP_TIMEOUT 30 HTTP request timeout

License

MIT License

Metadata

Release files for nobody-pentest-ultra 3.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for nobody-pentest-ultra 3.0.4
File Interpreter ABI Platform
nobody_pentest_ultra-3.0.4-py3-none-any.whl Python 3 none any Details

Release files / nobody_pentest_ultra-3.0.4-py3-none-any.whl

Download URL nobody_pentest_ultra-3.0.4-py3-none-any.whl
Size 80.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8eb76eec87545becd704cf968b63980410dfce429b924cc9fa491f0f9bae446e
BLAKE2b-256 checksum
How to use checksums
1d4b0e70b1696923b0690d33a28a97981ebce55aa373e523aa044d5bd9bea2ed
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.10

Release history Release notifications | RSS feed

3.0.5

1 release file

This release

3.0.4 This release

1 release file

3.0.3

1 release file

3.0.2

1 release file

3.0.1

1 release file

3.0.0

1 release file

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page