SkillAgentSearch skills...

mcp-vanguard

Security pentesting MCP Server with 89 tools across 10 categories. Windows/WSL bridge for Kali tools integration with Claude.

Install / Use

claude mcp add skyvanguard -- npx -y github:skyvanguard/mcp-vanguard

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

78/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop

Our assessment of mcp-vanguard

mcp-vanguard scores 78/100 on our quality scale, 718th of 856 Security skills we index.

Its MCP Server is 16 KB long, well organised into 35 sections with 11 code examples: a thorough specification that gives an agent plenty to work with.

It has 3 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
3/20
Freshness
11/15

Maintenance, license and trust

  • The repository was last updated about 7 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
  • Our last check on 2026-09-20 found the source still online.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 86/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

mcp-vanguard compared with similar skills

All 4 of these similar skills score higher than mcp-vanguard; compare them before choosing.

SkillScoreStarsUpdatedFormat
mcp-vanguard (this skill)by skyvanguard7837mo agoMCP Server
Agent-Reachby Panniantong10086.1k13d agoCLAUDE.md
headroomby headroomlabs-ai10074.1ktodayCLAUDE.md
rufloby ruvnet10073.5ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md

Frequently asked questions

How do I install mcp-vanguard?
Run claude mcp add skyvanguard -- npx -y github:skyvanguard/mcp-vanguard. The install tabs above show the steps for each supported agent.
Which AI agents does mcp-vanguard work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is mcp-vanguard safe to use?
It is MIT-licensed and scores 86/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is mcp-vanguard still maintained?
The repository was last updated about 7 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.

mcp-vanguard

License: MIT Node.js TypeScript MCP Tools Tests

A security pentesting MCP Server with 89 tools across 10 categories for Claude integration. Features native Windows/WSL bridge for using Kali Linux tools from any terminal — zero new npm dependencies.

Features

  • 89 Security Tools across 10 categories: recon, web, OSINT, network, exploit, crypto, cloud, container, analysis, and utilities
  • Registry Architecture: Auto-discoverable tools with self-describing schemas, permissions, and execution modes
  • WSL Bridge: Transparently execute Kali Linux tools (nmap, john, enum4linux, etc.) from Windows
  • Hybrid Execution: Native Node.js, external APIs, WSL subprocesses, or automatic fallback
  • Scope Management: Prevent scanning outside authorized targets
  • Permission Tiers: SAFE (passive) / DANGEROUS (active, scope required) / BLOCKED (unknown)
  • Report Generation: Markdown and JSON reports, diff comparisons, risk scoring
  • Attack Chain Detection: Correlate findings across tools to identify multi-step attack paths
  • Security Hardening: Input sanitization, command allowlists, audit logging, safe error handling
  • Caching & Rate Limiting: Built-in controls for efficient and safe scanning

Quick Start

git clone https://github.com/skyvanguard/mcp-vanguard.git
cd mcp-vanguard
npm install
npm run build
npm test

Configuration

Add to your Claude MCP configuration:

Claude Desktop (~/.claude/claude_desktop_config.json):

{
  "mcpServers": {
    "vanguard": {
      "command": "node",
      "args": ["/path/to/mcp-vanguard/dist/index.js"]
    }
  }
}

Claude Code (.mcp.json in project root):

{
  "mcpServers": {
    "vanguard": {
      "command": "node",
      "args": ["C:/path/to/mcp-vanguard/dist/index.js"]
    }
  }
}

Tools (89 total)

Reconnaissance (4 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_subdomain_enum | Enumerate subdomains via crt.sh and DNS bruteforce | DANGEROUS | | vanguard_port_scan | Port scanning with nmap or TCP connect fallback | DANGEROUS | | vanguard_whois | WHOIS lookup for domains and IPs | SAFE | | vanguard_dns_records | Query DNS records (A, AAAA, MX, NS, TXT, etc.) | SAFE |

Web Security (10 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_ffuf | Web fuzzing with ffuf (FUZZ keyword) | DANGEROUS | | vanguard_nuclei_scan | Vulnerability scanning with nuclei templates | DANGEROUS | | vanguard_param_miner | Discover hidden HTTP parameters | DANGEROUS | | vanguard_headers_check | Analyze security headers (HSTS, CSP, X-Frame-Options) | SAFE | | vanguard_tech_detect | Technology fingerprinting (CMS, frameworks, CDN) | SAFE | | vanguard_wayback | Wayback Machine URL history | SAFE | | vanguard_ssl_check | SSL/TLS certificate and configuration analysis | SAFE | | vanguard_cors_check | CORS misconfiguration detection | SAFE | | vanguard_robots_sitemap | Parse robots.txt and sitemap.xml | SAFE | | vanguard_js_endpoints | Extract endpoints and secrets from JavaScript | SAFE |

Network & Infrastructure (15 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_traceroute | Trace network path to target | DANGEROUS | | vanguard_ping_sweep | Discover live hosts in a network range | DANGEROUS | | vanguard_service_detect | Detect services/versions with nmap -sV | DANGEROUS | | vanguard_os_detect | OS fingerprinting with nmap | DANGEROUS | | vanguard_banner_grab | Grab service banners via TCP | DANGEROUS | | vanguard_snmp_enum | Enumerate SNMP data (WSL) | DANGEROUS | | vanguard_smb_enum | Enumerate SMB shares and users (WSL) | DANGEROUS | | vanguard_ldap_enum | Enumerate LDAP directory (WSL) | DANGEROUS | | vanguard_dns_zone_transfer | Attempt DNS zone transfer (AXFR) | DANGEROUS | | vanguard_arp_scan | ARP discovery on local network (WSL) | DANGEROUS | | vanguard_ftp_check | Check FTP for anonymous access | SAFE | | vanguard_ssh_audit | Audit SSH algorithms and configuration | SAFE | | vanguard_reverse_dns | Reverse DNS (PTR) lookup | SAFE | | vanguard_network_cidr | CIDR calculator and subnet operations | SAFE | | vanguard_http_methods | Test allowed HTTP methods on a URL | SAFE |

OSINT (15 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_github_dorks | Generate GitHub dork queries for sensitive data | DANGEROUS | | vanguard_cert_search | Certificate transparency log search | SAFE | | vanguard_cve_lookup | CVE database search (NVD) | SAFE | | vanguard_email_hunter | Find email addresses for a domain | SAFE | | vanguard_social_media | Check username across social platforms | SAFE | | vanguard_domain_reputation | Domain/IP reputation check | SAFE | | vanguard_ip_geolocation | IP geolocation (country, city, ISP, ASN) | SAFE | | vanguard_asn_lookup | ASN lookup by number, IP, or organization | SAFE | | vanguard_google_dorks | Generate Google dork queries for a target | SAFE | | vanguard_shodan_search | Search Shodan for exposed services (API key required) | SAFE | | vanguard_breach_check | Check email/domain in known data breaches | SAFE | | vanguard_metadata_extract | Extract metadata from web pages | SAFE | | vanguard_dns_history | Historical DNS record lookup | SAFE | | vanguard_favicon_hash | Favicon hash for Shodan fingerprinting | SAFE | | vanguard_web_archive_diff | Wayback Machine snapshot analysis | SAFE |

Exploitation (10 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_exploit_search | Search exploits by product/CVE (searchsploit + APIs) | DANGEROUS | | vanguard_reverse_shell_gen | Generate reverse shell payloads (bash, python, php, etc.) | DANGEROUS | | vanguard_sqli_test | SQL injection testing (error, boolean, time, union) | DANGEROUS | | vanguard_xss_test | Reflected XSS testing with multiple payloads | DANGEROUS | | vanguard_ssrf_test | SSRF testing (localhost, cloud metadata, file://) | DANGEROUS | | vanguard_lfi_test | Local File Inclusion (path traversal, PHP wrappers) | DANGEROUS | | vanguard_command_inject_test | OS command injection testing | DANGEROUS | | vanguard_open_redirect_test | Open redirect with bypass techniques | DANGEROUS | | vanguard_crlf_inject_test | CRLF / HTTP header injection testing | DANGEROUS | | vanguard_deserialization_check | Insecure deserialization detection (Java, PHP, .NET, Python) | DANGEROUS |

Password & Crypto (8 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_hash_crack | Crack hashes with John the Ripper (WSL) | DANGEROUS | | vanguard_jwt_attack | JWT vulnerabilities: none alg, weak secrets, alg confusion | DANGEROUS | | vanguard_password_gen | Secure random passwords or CeWL-based wordlists | DANGEROUS | | vanguard_hash_identify | Identify hash type (MD5, SHA, bcrypt, NTLM, etc.) | SAFE | | vanguard_password_policy | Password strength analysis with entropy and crack time | SAFE | | vanguard_jwt_decode | Decode JWT tokens with security checks | SAFE | | vanguard_crypto_audit | HTTPS/TLS security headers and cookie audit | SAFE | | vanguard_base_decode | Multi-format encode/decode (Base64, hex, URL, HTML, Unicode) | SAFE |

Cloud Security (8 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_cloud_metadata | SSRF test for cloud metadata endpoints (AWS, GCP, Azure) | DANGEROUS | | vanguard_subdomain_takeover | Dangling CNAME subdomain takeover detection | DANGEROUS | | vanguard_exposed_env_check | Check for exposed .env, .git, config files | DANGEROUS | | vanguard_s3_bucket_check | AWS S3 bucket public access check | SAFE | | vanguard_azure_blob_check | Azure Blob Storage access check | SAFE | | vanguard_gcp_bucket_check | Google Cloud Storage access check | SAFE | | vanguard_firebase_check | Firebase project exposure check | SAFE | | vanguard_cloud_enum | Enumerate cloud resources by keyword permutations | SAFE |

Container Security (5 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_docker_socket | Check for exposed Docker daemon (TCP 2375/2376) | DANGEROUS | | vanguard_k8s_api | Kubernetes API/Kubelet unauthenticated access check | DANGEROUS | | vanguard_container_escape | Container escape vector detection (socket, caps, mounts) | DANGEROUS | | vanguard_registry_enum | Docker Registry v2 repository/tag enumeration | DANGEROUS | | vanguard_helm_audit | Helm chart security audit (privileged, capabilities, secrets) | SAFE |

Analysis & Reporting (9 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_vuln_correlate | Cross-tool finding correlation and attack chain detection | SAFE | | vanguard_attack_surface | Attack surface mapping from ports, techs, and subdomains | SAFE | | vanguard_risk_score | Risk scoring with context multipliers | SAFE | | vanguard_remediation_plan | Prioritized remediation plan generation | SAFE | | vanguard_encoding_detect | Multi-layer encoding detection and decoding | SAFE | | vanguard_diff_report | Before/after scan comparison (new, fixed, upgraded) | SAFE | | vanguard_timeline | Pentest event timeline with phase analysis | SAFE | | vanguard_scope_manager | Target scope management (set, add, remove, check) | SAFE | | vanguard_report_gen | Security assessment reports in Markdown or JSON | SAFE |

Utilities (5 tools)

| Tool | Description | Permission | |------|-------------|------------| | vanguard_set_scope | Define authorized target scope | SAFE | | vanguard_check_scope | Verify if target is in scope | SAFE | | vanguard_generate_report | Generate markdown security report | SAFE | | vanguard_export_html | Convert report to styled HTML | SAFE | | vanguard_audit_stats | View audit log and security events | SAFE |

Summary

| Category | Tools | SAFE | DANGEROUS | |----------|-------|------|-----------| | Reconnaissance | 4 | 2 | 2 | | Web Security | 10 | 7 | 3 | | Network | 15 | 5 | 10 | | OSINT | 15 | 14 | 1 | | Exploitation | 10 | 0 | 10 | | Crypto | 8 | 5 | 3 | | Cloud | 8 | 5 | 3 | | Container | 5 | 1 | 4 | | Analysis | 9 | 9 | 0 | | Utilities | 5 | 5 | 0 | | Total | 89 | 53 | 36 |

Permission Tiers

| Tier | Description | Example | |------|-------------|---------| | SAFE | Passive operations, no direct target interaction | DNS lookups, hash identification, report generation | | DANGEROUS | Active scanning, requires target authorization | Port scans, injection testing, fuzzing | | BLOCKED | Unregistered/unknown tools (rejected automatically) | — |

Usage Examples

1. Set Scope

vanguard_set_scope with targets: ["example.com", "*.example.com"]

2. Passive Reconnaissance

vanguard_dns_records for example.com
vanguard_cert_search for example.com
vanguard_wayback for example.com
vanguard_ssl_check for example.com
vanguard_tech_detect for https://example.com
vanguard_asn_lookup for example.com
vanguard_favicon_hash for https://example.com

3. Security Analysis

vanguard_headers_check for https://example.com
vanguard_cors_check for https://api.example.com
vanguard_js_endpoints for https://example.com with deep: true
vanguard_cve_lo

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars3
CategorySecurity
Updated7mo ago
Forks2

Languages

TypeScript

Trust signals

86/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

2 low