## https://sploitus.com/exploit?id=A8BA3225-0EF8-50FA-9C4A-22D3BE52D2FB
# PrismSec π·
**Secure, modular MCP server for pentesting tools.**
Wraps 7 industry-standard security tools (nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap) into 13 registered MCP tools β ready to use with Claude, Cursor, Copilot, and any MCP-compatible AI agent.
---
## Features
| Feature | Description |
|---------|-------------|
| **Zero shell=True** | All subprocess calls use `asyncio.create_subprocess_exec` β no shell injection |
| **Input validation** | Target, URL, port, severity β all validated before execution |
| **Injection detection** | Blocks shell metacharacters (`;`, `$()`, backticks, `\|`) |
| **Timeout enforcement** | Every tool has configurable timeout β auto-kills hung processes |
| **Structured output** | Parsed XML/JSON/text β clean JSON for AI agents |
| **Modular architecture** | One file per tool β easy to add, maintain, and test |
| **MCP SDK v2** | Built on the latest Model Context Protocol SDK |
---
## Installation
### From source
```bash
git clone https://github.com/azmisyahrul/prismsec.git
cd prismsec
pip install -e .
```
### Prerequisites
Install the security tools you need:
```bash
# Ubuntu/Debian
apt install nmap nikto sqlmap
# Go-based tools
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest
go install github.com/OJ/gobuster/v3@latest
```
---
## Tools (13 registered)
### Nmap β Port Scanning
| MCP Tool | Description |
|----------|-------------|
| `nmap_port_scan` | Port scan with quick/full/service/stealth/aggressive modes |
| `nmap_service_detect` | Service/version detection on open ports |
| `nmap_full_scan` | Scan all 65535 TCP ports |
### Nuclei β Vulnerability Scanning
| MCP Tool | Description |
|----------|-------------|
| `nuclei_vuln_scan` | Full vulnerability scan with all templates |
| `nuclei_severity_scan` | Scan filtered by severity (critical, high, etc.) |
| `nuclei_template_scan` | Targeted scan with specific template |
### Gobuster β Directory/DNS Brute
| MCP Tool | Description |
|----------|-------------|
| `gobuster_directory` | Directory brute-force with configurable extensions |
| `gobuster_dns` | DNS subdomain brute-force |
### Other Tools
| MCP Tool | Description |
|----------|-------------|
| `subfinder_enumerate` | Passive subdomain enumeration (crt.sh, VirusTotal, etc.) |
| `httpx_probe` | Web probing β alive detection, titles, tech fingerprinting |
| `nikto_web_scan` | Web server vulnerability scanning |
| `sqlmap_injection_test` | SQL injection detection and testing |
### Meta
| MCP Tool | Description |
|----------|-------------|
| `check_tools` | Check which security tools are installed |
---
## Usage
### Claude Desktop
Add to `claude_desktop_config.json`:
```json
{
"mcpServers": {
"prismsec": {
"command": "python3",
"args": ["/path/to/prismsec/server.py"],
"env": {}
}
}
}
```
### Claude Code
```bash
claude mcp add prismsec python3 /path/to/prismsec/server.py
```
### Cursor / Windsurf / Cline
Add to `.cursor/mcp.json` or equivalent:
```json
{
"mcpServers": {
"prismsec": {
"command": "python3",
"args": ["/path/to/prismsec/server.py"]
}
}
}
```
### SSE Transport (Remote)
```bash
# Server side
python3 server.py --transport sse --host 0.0.0.0 --port 8000
# Client config
{
"mcpServers": {
"prismsec": {
"url": "http://localhost:8000/sse"
}
}
}
```
---
## Project Structure
```
prismsec/
βββ server.py # MCP server entry point (13 tools)
βββ pyproject.toml # Project config + dependencies
βββ tools/ # Tool wrappers (one file per tool)
β βββ base.py # ToolWrapper ABC + async runner
β βββ nmap.py # Nmap β XML parsing, scan modes
β βββ nuclei.py # Nuclei β JSON output parsing
β βββ gobuster.py # Gobuster β text output parsing
β βββ subfinder.py # Subfinder β subdomain enum
β βββ httpx.py # Httpx β web probing
β βββ nikto.py # Nikto β web vuln scan
β βββ sqlmap.py # Sqlmap β SQL injection testing
βββ parsers/ # Output parsers
β βββ xml_parser.py # nmap XML β structured JSON
β βββ json_parser.py # JSON/JSONL parsing
β βββ text_parser.py # Gobuster, nikto, sqlmap text
βββ utils/ # Shared utilities
βββ runner.py # AsyncRunner with timeout
βββ validator.py # Input validation + injection detection
βββ rate_limiter.py # Token bucket rate limiter
βββ logging.py # Structured logging
```
---
## Configuration
| Environment Variable | Default | Description |
|---------------------|---------|-------------|
| `LOG_LEVEL` | `INFO` | Logging level (DEBUG, INFO, WARNING, ERROR) |
---
## Security Considerations
β οΈ **Authorized testing only.** Use against systems you own or have written permission to test.
- Tool outputs may contain sensitive information (IPs, open ports, vulnerabilities)
- The server binds to `127.0.0.1` by default β never expose to untrusted networks
- Each tool has configurable timeouts to prevent resource exhaustion
---
## License
MIT
---
Built with the [Model Context Protocol](https://modelcontextprotocol.io/) standard for broad client compatibility.