mcp-security-hub
Skill by ara.so — Security Skills collection.
Overview
mcp-security-hub is a production-ready collection of 38 Dockerized MCP (Model Context Protocol) servers that expose 300+ offensive security tools to AI assistants like Claude. It enables natural language security assessments, vulnerability scanning, binary analysis, and penetration testing workflows.
Key capabilities:
- 8 reconnaissance servers (Nmap, Shodan, ProjectDiscovery tools, WhatWeb, Masscan, ZoomEye)
- 6 web security servers (Nuclei, SQLMap, Nikto, ffuf, Burp Suite)
- 6 binary analysis servers (radare2, Ghidra, Binwalk, YARA, Capa, IDA Pro)
- 3 blockchain security servers (DAML Viewer, Medusa, Solazy)
- 3 cloud security servers (Trivy, Prowler, RoadRecon)
- Plus: secrets detection, fuzzing, OSINT, threat intelligence, Active Directory, password cracking
Installation
Prerequisites
- Docker 20.10+
- Docker Compose 2.0+
- Claude Desktop or MCP-compatible client
Clone and Build
Verify Installation
Configuration
Claude Desktop Integration
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
Project-Level Configuration
Create .mcp.json in your project root:
Environment Variables
Many MCP servers require API keys for external services:
Pass environment variables to Docker containers:
Key MCP Servers
Nmap MCP (Network Scanning)
Available tools (8):
scan_hosts- Basic host discoveryscan_ports- Port scanning with service detectionscan_os- OS fingerprintingscan_vuln- Vulnerability scanning with NSE scriptsscan_custom- Custom nmap command executionlist_nse_scripts- List available NSE scriptsget_nse_script_info- Get NSE script detailsscan_with_script- Run specific NSE script
Example prompts:
- "Scan 192.168.1.0/24 for open ports"
- "Perform OS detection on 10.0.0.1"
- "Run vulnerability scan on example.com"
Nuclei MCP (Vulnerability Scanning)
Available tools (7):
scan_target- Scan with default templatesscan_with_severity- Filter by severity (critical, high, medium, low)scan_with_tags- Use specific tags (cve, exposure, xss, sqli)scan_with_templates- Use custom template pathslist_templates- Show available templatesupdate_templates- Update template databasescan_multiple_targets- Bulk scanning
Example prompts:
- "Scan https://example.com for critical vulnerabilities"
- "Check example.com for CVEs using nuclei"
- "Run nuclei with exposure and misconfiguration templates"
Gitleaks MCP (Secrets Detection)
Available tools (5):
scan_repo- Scan git repositoryscan_file- Scan individual filescan_directory- Scan directory treegenerate_baseline- Create baseline for false positivesscan_commits- Scan specific commit range
Example prompts:
- "Scan /app/target/myrepo for secrets"
- "Check this project for exposed API keys"
- "Find credentials in the last 10 commits"
Volume mounting required:
Radare2 MCP (Binary Analysis)
Available tools (32+):
analyze_binary- Load and analyze binarydisassemble- Disassemble functionsdecompile- Decompile to C-like codelist_functions- Show all functionsfind_strings- Extract stringsfind_imports- List imported functionsfind_exports- List exported functionssearch_bytes- Search byte patternsanalyze_entropy- Detect packed sections
Example prompts:
- "Analyze /samples/malware.exe for suspicious functions"
- "Decompile main function in this binary"
- "Find strings in /samples/firmware.bin"
Volume mounting required:
SQLMap MCP (SQL Injection)
Available tools (8):
test_url- Test URL for SQL injectiondump_database- Extract database contentsdump_table- Extract specific tablelist_databases- Enumerate databaseslist_tables- Enumerate tablesget_dbs- Get database namesget_current_user- Get DB usertest_forms- Test web forms for SQLi
Example prompts:
- "Test https://example.com/page?id=1 for SQL injection"
- "Dump database from vulnerable URL"
- "Check this form for SQL injection vulnerabilities"
Trivy MCP (Container Security)
Available tools (7):
scan_image- Scan Docker imagescan_filesystem- Scan local filesystemscan_config- Scan IaC files (Terraform, K8s)scan_repo- Scan git repositorylist_vulnerabilities- Show known CVEsget_sbom- Generate SBOMscan_kubernetes- Scan K8s cluster
Example prompts:
- "Scan nginx:latest for vulnerabilities"
- "Check this Dockerfile for security issues"
- "Generate SBOM for python:3.11 image"
Common Workflows
Network Reconnaissance Workflow
Web Application Security Assessment
Binary Analysis Pipeline
Secrets Scanning in CI/CD
Cloud Security Audit
Docker Compose Orchestration
Start All Services
Start Specific Category
Resource Limits
Edit docker-compose.yml to adjust resource constraints:
Health Monitoring
Development
Building Individual Servers
Testing MCP Server
Adding Custom MCP Server
Security Hardening
All MCP servers follow security best practices:
Required Capabilities
Some tools need specific Linux capabilities:
Read-Only Mounts
Always mount target directories read-only:


