← Back to search Server uses network capabilities via: fetch(), net Server uses shell capabilities via: child_process, spawn(), spawnSync() Server uses env_vars capabilities via: process.env
io.github.cyanheads/attack-surface-mcp-server
Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
? Not scanned yet
Versions
0.1.0latestfirst seen Jun 30, 2026
Tools 0
No tools indexed yet.
Permissions 3
network medium shell high env_vars low Scan Findings 10
info
Sandbox failed to start for behavioral verification
info
package.json metadata
info
Required env vars (5)
info
Sandbox failed to start for output poisoning scan
medium
Permission: network access detected
high
Permission: shell access detected
low
Permission: env_vars access detected
info
SBOM generated: 13 components
high
Hardcoded Password found in cyanheads-attack-surface-mcp-server-67e9d33/skills/api-utils/references/security.md
medium
No build provenance detected (SLSA L0)