MCPhantom
MCPhantom is a local web dashboard for MCP endpoint recon. Discover resources, templates, tools, and prompts, then interact with them from a security console.
Install / Use
claude mcp add Dragkob -- npx -y github:Dragkob/MCPhantomIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of MCPhantom
MCPhantom scores 75/100 on our quality scale, 895th of 1,002 Security skills we index.
Its MCP Server is 6.0 KB long, split into 4 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated about 3 months ago, so MCPhantom is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
MCPhantom compared with similar skills
All 4 of these similar skills score higher than MCPhantom; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| MCPhantom (this skill)by Dragkob | 75 | 10 | 3mo ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 87.5k | 16d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.7k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install MCPhantom?
- Run
claude mcp add Dragkob -- npx -y github:Dragkob/MCPhantom. The install tabs above show the steps for each supported agent. - Which AI agents does MCPhantom work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is MCPhantom safe to use?
- It is MIT-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is MCPhantom still maintained?
- The repository was last updated about 3 months ago, so MCPhantom is actively maintained.
Skill content
View source on GitHubMCPhantom is a local web dashboard for MCP endpoint reconnaissance and exploitation. Point it at any MCP URL, discover exposed resources, templates, tools, and prompts, then interact with them from a clean security console UI. Runs locally at 127.0.0.1:1337; no cloud, no setup beyond Python. Project's Documentation can be found here.
[!WARNING] MCPhantom is an extensible security auditing framework; not a turnkey, universal scanner. It provides a solid foundation for MCP focused reconnaissance and vulnerability testing, but it is intentionally designed as a <ins><b>starting skeleton</b></ins> that you are expected to adapt to your targets, environments, and methodology.
- Not guaranteed to work out of the box on every MCP server : Capabilities, schemas, transports, and response formats vary widely across implementations. Classification, payload delivery, and proof detection may need tuning per target.
- Payload coverage is deliberately limited : MCPhantom includes representative probes for classes such as SQL injection, command injection, SSRF, path traversal, IDOR, and information disclosure, but it does not ship exhaustive wordlists or engine scale fuzzing comparable to tools like sqlmap, Burp Intruder, or commercial DAST platforms.
- Proof heuristics are best-effort : Findings are scored from response signals (errors, data leaks, version strings, reflected output, etc.). False positives and false negatives are possible without target-specific customization. This is exactly why the framework also allows you to do manual auditing.
- You are encouraged to extend it : The project is open source so you can grow payload libraries, add plugins, refine classifiers, integrate with your CI/CD pipeline, or harden detection logic for your use cases.
- The AutoPwn feature is a WIP and it is highly discouraged to use it in live production encironments. Only use this feature on CTFs and/or local labs.
<div align="center">
Video Demo
</div>https://github.com/user-attachments/assets/b62d3a80-2b38-4b5c-a11b-029192279470
<div align="center"><i>All demonstrations and testing were performed in a controlled environment against intentionally vulnerable systems.<br />No real-world systems were targeted or harmed.</i></div><div align="center">
🛠️ Features 🛠️
</div> <table> <thead> <tr> <th>Category</th> <th>Feature</th> <th>Description</th> </tr> </thead> <tbody> <tr> <td rowspan="2"><strong>Discovery</strong></td> <td>MCP enumeration</td> <td>Discovers resources, resource templates, tools, and prompts from a target MCP endpoint</td> </tr> <tr> <td>Capability classification</td> <td>Tags capabilities (e.g. URL, command, database, path, ID) to decide which tests apply</td> </tr> <tr> <td rowspan="2"><strong>Interface</strong></td> <td>Web dashboard</td> <td>Browser-based console at <code>http://127.0.0.1:1337</code> with dark/light themes</td> </tr> <tr> <td>Live interaction</td> <td>Read resources/templates, invoke tools, run prompts, and fill template placeholders from the UI</td> </tr> <tr> <td rowspan="4"><strong>AutoPwn</strong></td> <td>Smart targeted scanning</td> <td>Runs plugin-matched checks only where tags/parameters suggest relevance - avoids blind fuzzing everywhere</td> </tr> <tr> <td>Parallel execution</td> <td>Runs multiple capability checks concurrently with per-check and per-payload timeouts</td> </tr> <tr> <td>Streaming results</td> <td>NDJSON progress stream with live coverage, findings, and completion percentage</td> </tr> <tr> <td>Scan coverage report</td> <td>Per-capability status (vulnerable, clean, timeout, error) with hit counts and notes</td> </tr> <tr> <td rowspan="6"><strong>Plugins</strong></td> <td>SQL injection</td> <td>Single-column UNION probes, DB version extraction, and schema/table enumeration (SQLite, MySQL, PostgreSQL, MSSQL, Oracle)</td> </tr> <tr> <td>Command injection</td> <td>Shell metacharacter and allowlist-bypass style payloads with MCP response parsing</td> </tr> <tr> <td>SSRF</td> <td>Internal/localhost and metadata-style URL probes</td> </tr> <tr> <td>Path traversal</td> <td>Common filesystem path escape payloads</td> </tr> <tr> <td>IDOR</td> <td>Identifier manipulation probes on ID-like parameters</td> </tr> <tr> <td>Information disclosure</td> <td>Baseline and verbose/error-triggering requests for sensitive output</td> </tr> <tr> <td rowspan="3"><strong>Engine</strong></td> <td>Central payload repository</td> <td>All payloads live in <code>audit/payloads.py</code> - add categories and entries without rewriting plugins</td> </tr> <tr> <td>Proof scoring (SQLi)</td> <td>Ranks findings by evidence strength; filters reflection-only and duplicate error responses</td> </tr> <tr> <td>Plugin architecture</td> <td>Modular plugins loaded via <code>audit/plugin_loader.py</code> - straightforward to add new vulnerability classes</td> </tr> <tr> <td><strong>Extensibility</strong></td> <td>Open source</td> <td>Fork, extend payload lists, add plugins, and tailor detection to your targets and workflows</td> </tr> </tbody> </table> <div align="center">Quick Start
</div>python web_server.py
# Open http://127.0.0.1:1337, enter an MCP endpoint, run Start Recon.
[!CAUTION] MCPhantom is intended solely for authorized security assessments, research, and educational purposes. Use it only against systems you own or have explicit permission to test. See the LICENSE file for warranty and liability terms.
Related Skills
Agent-Reach
87.5kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.7k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
