Skip to main content

English · Русский (RU)

🧠 pentool-mcp-server

MCP server for Pentool — the local AI assistant for web pentesting

PyPI version Python License: AGPL-3.0 Install: uv Open in GitHub

A self-contained stdio JSON-RPC 2.0 server that brings AI capabilities to any MCP client — first of all to Pentool (BYO-LLM: picking checks, bypassing WAF, finding non-obvious endpoints). Installed with uv in one command.


Why a separate package

MCP is the open protocol for connecting LLM models to tools. pentool-mcp-server encapsulates Pentool's MCP layer as a reusable PyPI package: attached locally (stdio), no network, no ports, installs in seconds, no heavy dependencies.

🔗 Built for Pentool

This server is the MCP component of Pentool, a professional web-security testing terminal (Burp-compatible proxy, scanner, spider, intruder — all in a TUI). It powers Pentool's AI:

  • 🎯 picking the relevant scan checks for a concrete target;
  • 🛡 WAF bypass / payload suggestions;
  • 🕷 finding non-obvious endpoints during spider crawling.

Try the full stack: uv tool install "pentool[ai]"pentool ai setuppentool.

⚡ Quick start (uv)

# Install uv (if not present): https://docs.astral.sh/uv/
curl -LsSf https://astral.sh/uv/install.sh | sh

# Standalone — just the MCP server
uv tool install pentool-mcp-server
pentool-mcp-server --version

# Or together with Pentool and its AI extras
uv tool install "pentool[ai]"

Health check (stdio):

echo '{"jsonrpc":"2.0","id":1,"method":"ping"}' | pentool-mcp-server
# → {"jsonrpc": "2.0", "id": 1, "result": {"status": "ok"}}

uv is the standard install path — isolated environment, exactly how Pentool itself is installed. It keeps the server out of your system Python.

🚀 Deploy on a VPS / in a container

The server opens no ports and runs as a local subprocess — safe on any host. With uv it stays out of the system Python:

uv tool install pentool-mcp-server

Full user guide — docs/GUIDE.md. Russian — README.ru.

🧩 MCP tools

Tool Description
initialize MCP protocol handshake
tools/list List available tools
tools/call generate Generate an LLM answer for a task (task + payload)
tools/call health Readiness check (is a model installed)
tools/call configure Point to a GGUF model path
ping Process liveness

🔒 Security

  • No network by default. pentool-mcp-server listens only on stdio (stdin → stdout) inside the local process. External access is impossible — neither from other processes nor from another host.
  • Do not expose it over TCP/0.0.0.0 without auth. If run on a network port outwardly, anyone able to write to stdin/port gets tools/call generate (resource usage + sending target data to the LLM). MCP has no built-in authentication — bind to 127.0.0.1 and gate via a firewall.
  • Target privacy. Data (URL, payload) leaves the host only if an external LLM provider is connected; with a local GGUF model the traffic stays on the machine.

More — docs/GUIDE.md.

🗺 Roadmap

  • stdio JSON-RPC 2.0 server (initialize / tools/list / tools/call / ping)
  • generate, health, configure tools
  • real LLM runner (llama-cpp-python) in model.py
  • optional TCP mode with HMAC auth

📄 License

AGPL-3.0 — the same license as Pentool.


Support / bugs: issues · Designed for Pentool · User Guide

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pentool_mcp_server-0.1.0.tar.gz (8.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pentool_mcp_server-0.1.0-py3-none-any.whl (9.5 kB view details)

Uploaded Python 3

File details

Details for the file pentool_mcp_server-0.1.0.tar.gz.

File metadata

  • Download URL: pentool_mcp_server-0.1.0.tar.gz
  • Upload date:
  • Size: 8.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for pentool_mcp_server-0.1.0.tar.gz
Algorithm Hash digest
SHA256 d23b555988867e81d5882132948a137ef81bd8f99ea6a9c1582cc5baa945bb24
MD5 d6e7c94369759c8ae86c3e014330c2ea
BLAKE2b-256 92092d417f64b5ba22a01e67d8df543617573e9ba27440dfd62712b8d504caca

See more details on using hashes here.

File details

Details for the file pentool_mcp_server-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: pentool_mcp_server-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 9.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for pentool_mcp_server-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 b96d92ba341b94b70c1adec763d9df08c2efe60f83a7f962b3d728515a73c5d6
MD5 1edd8527edc46f9f2907889ec5c68c24
BLAKE2b-256 886849d31c792b90e2647065e9c680840b1e32f28fbcf39e3663045f60c5db92

See more details on using hashes here.

Release history Release notifications | RSS feed

0.2.0

2 files

This release

0.1.0 This release

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page