io.github.operantlabs/operant-mcp MCP Server
io.github.operantlabs/operant-mcp
51 security testing tools for penetration testing, forensics, and vulnerability assessment
What is the io.github.operantlabs/operant-mcp MCP server?
The operant-mcp MCP server is a security testing platform with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It covers SQL injection, XSS, command injection, SSRF, PCAP analysis, reconnaissance, malware analysis, cloud security, and more, designed for authorized security professionals and researchers.
operant-mcp provides a comprehensive toolkit for security professionals to conduct penetration tests, analyze network traffic and memory dumps, perform reconnaissance, detect vulnerabilities, and assess cloud security. It integrates with existing CLI tools (curl, tshark, volatility, olevba, etc.) and includes 8 methodology prompts to guide structured security assessments.
How to install io.github.operantlabs/operant-mcp
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
sqli_where_bypass— Test OR-based WHERE clause bypass for SQL injectionsqli_login_bypass— Test login form SQL injectionsqli_union_extract— UNION-based data extractionsqli_blind_boolean— Boolean-based blind SQLisqli_blind_time— Time-based blind SQLisqli_file_read— Read files via LOAD_FILE()xss_reflected_test— Test reflected XSS with 10 payloadsxss_payload_generate— Generate context-aware XSS payloadscmdi_test— Test OS command injectioncmdi_blind_detect— Blind command injection via sleep timingpath_traversal_test— Test directory traversal with encoding variantsssrf_test— Test SSRF with localhost bypass variantsssrf_cloud_metadata— Test cloud metadata access via SSRFpcap_overview— Protocol hierarchy and endpoint statspcap_extract_credentials— Extract FTP/HTTP/SMTP credentialspcap_dns_analysis— DNS query analysispcap_http_objects— Export HTTP objectspcap_detect_scan— Detect port scanningpcap_follow_stream— Follow TCP/UDP streamspcap_tls_analysis— TLS/SNI analysis
Use cases
- Conduct authorized penetration tests on web applications, APIs, and cloud infrastructure
- Analyze network traffic captures (PCAP files) to extract credentials, detect attacks, and investigate security incidents
- Perform memory forensics on Linux and Windows systems to detect rootkits and analyze malware
- Enumerate and discover vulnerabilities in reconnaissance phases (DNS, vhosts, S3 buckets, git repos)
- Test specific vulnerability classes (SQL injection, XSS, SSRF, IDOR, authentication flaws) with automated payloads and detection
io.github.operantlabs/operant-mcp MCP server FAQ
operant-mcp is a security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment. It covers SQL injection, XSS, command injection, SSRF, PCAP analysis, reconnaissance, malware analysis, cloud security, and more.
Yes, operant-mcp is open-source under the MIT license and available on npm.
Use the Cursor install button in the README, or manually add to your MCP config: {"command": "npx", "args": ["-y", "operant-mcp"]}
Add to your Claude MCP configuration with command "npx" and args ["-y", "operant-mcp"], or use the VS Code install link as a reference.
Most tools require curl; PCAP analysis needs tshark, DNS recon needs dig/host, memory forensics needs volatility, malware analysis needs olevba/oledump.py, and cloud analysis needs jq.
No authentication is required to run operant-mcp, but individual tools may require API keys or credentials for cloud services (e.g., AWS for CloudTrail analysis).
README (reference)
Source of truth, from the repository.
operant-mcp
<a href="https://glama.ai/mcp/servers/operantlabs/operant-mcp"> <img width="380" height="200" src="https://glama.ai/mcp/servers/operantlabs/operant-mcp/badge" alt="operant-mcp MCP server" /> </a>Security testing MCP server with 51 tools for penetration testing, network forensics, memory analysis, and vulnerability assessment.
Quick Start
npx operant-mcp
Or install globally:
npm install -g operant-mcp
operant-mcp
Usage with Claude Code
Add to your MCP config:
{
"mcpServers": {
"operant": {
"command": "npx",
"args": ["-y", "operant-mcp"]
}
}
}
Tools (51)
SQL Injection (6)
sqli_where_bypass— Test OR-based WHERE clause bypasssqli_login_bypass— Test login form SQL injectionsqli_union_extract— UNION-based data extractionsqli_blind_boolean— Boolean-based blind SQLisqli_blind_time— Time-based blind SQLisqli_file_read— Read files via LOAD_FILE()
XSS (2)
xss_reflected_test— Test reflected XSS with 10 payloadsxss_payload_generate— Generate context-aware XSS payloads
Command Injection (2)
cmdi_test— Test OS command injectioncmdi_blind_detect— Blind command injection via sleep timing
Path Traversal (1)
path_traversal_test— Test directory traversal with encoding variants
SSRF (2)
ssrf_test— Test SSRF with localhost bypass variantsssrf_cloud_metadata— Test cloud metadata access via SSRF
PCAP/Network Forensics (8)
pcap_overview— Protocol hierarchy and endpoint statspcap_extract_credentials— Extract FTP/HTTP/SMTP credentialspcap_dns_analysis— DNS query analysispcap_http_objects— Export HTTP objectspcap_detect_scan— Detect port scanningpcap_follow_stream— Follow TCP/UDP streamspcap_tls_analysis— TLS/SNI analysispcap_llmnr_ntlm— Detect LLMNR/NTLM attacks
Reconnaissance (7)
recon_quick— Quick recon (robots.txt, headers, common dirs)recon_dns— Full DNS enumerationrecon_vhost— Virtual host discoveryrecon_tls_sans— Extract SANs from TLS certificatesrecon_directory_bruteforce— Directory brute-forcerecon_git_secrets— Search git repos for secretsrecon_s3_bucket— Test S3 bucket permissions
Memory Forensics (3)
volatility_linux— Linux memory analysis (Volatility 2)volatility_windows— Windows memory analysis (Volatility 3)memory_detect_rootkit— Linux rootkit detection
Malware Analysis (2)
maldoc_analyze— Full OLE document analysis pipelinemaldoc_extract_macros— Extract VBA macros
Cloud Security (2)
cloudtrail_analyze— CloudTrail log analysiscloudtrail_find_anomalies— Detect anomalous CloudTrail events
Authentication (3)
auth_csrf_extract— Extract CSRF tokensauth_bruteforce— Username enumeration + credential brute-forceauth_cookie_tamper— Cookie tampering test
Access Control (2)
idor_test— Test for IDOR vulnerabilitiesrole_escalation_test— Test privilege escalation
Business Logic (2)
price_manipulation_test— Test price/quantity manipulationcoupon_abuse_test— Test coupon stacking/reuse
Clickjacking (2)
clickjacking_test— Test X-Frame-Options/CSPframe_buster_bypass— Test frame-busting bypass
CORS (1)
cors_test— Test CORS misconfigurations
File Upload (1)
file_upload_test— Test file upload bypasses
NoSQL Injection (2)
nosqli_auth_bypass— MongoDB auth bypassnosqli_detect— NoSQL injection detection
Deserialization (1)
deserialization_test— Test insecure deserialization
GraphQL (2)
graphql_introspect— Full schema introspectiongraphql_find_hidden— Discover hidden fields
Prompts (8)
Methodology guides for structured security assessments:
web_app_pentest— Full web app pentest methodologypcap_forensics— PCAP analysis workflowmemory_forensics— Memory dump analysis (Linux/Windows)recon_methodology— Reconnaissance checklistmalware_analysis— Malware document analysiscloud_security_audit— CloudTrail analysis workflowsqli_methodology— SQL injection testing guidexss_methodology— XSS testing guide
System Requirements
Tools require various CLI utilities depending on the module:
- Most tools:
curl - PCAP analysis:
tshark(Wireshark CLI) - DNS recon:
dig,host - Memory forensics:
volatility/vol.py/vol3 - Malware analysis:
olevba,oledump.py - Cloud analysis:
jq - Secrets scanning:
git
License
MIT
Related MCP servers
Check an MCP endpoint resolves: liveness, live tool list, schema drift. Free.

Storeboard
Generate exact-size App Store and Google Play screenshots, feature graphics, and listing copy.

Push HTML prototypes to DesignPin for team review and pull reviewer feedback into your AI.

Bounded data, document, web-quality, and operations services purchased with USDC through x402.

OpsConduit Jobber MCP
Customer-hosted read-only MCP server for Jobber ops reports, OAuth setup, and GraphQL validation.
US import duty research: HTS codes, Chapter 99 duties, MPF/HMF fees, landed cost. USITC data.
