← Back to search

io.github.xu-c0/cybersec-mcp

xu-c0 Scanned 9d ago

Cybersecurity MCP server: 323 prompts + 7 workflows for red team, blue team, SOC, cloud, OSINT.

A
91.3 / 100

Versions

0.1.0latest
first seen Jun 5, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 5

cybersec_list_categories
annotations: none low

List the 8 cybersecurity prompt categories with descriptions and prompt counts. Call this first to see what domains are covered before listing or fetching specific prompts.

cybersec_list_prompts
annotations: none low

Search and filter the prompt library. Returns prompt summaries (id, title, useWhen, variables) — up to 50 per call. Follow up with cybersec_get_prompt for the full text.

cybersec_get_prompt
annotations: none low

Get a specific prompt by id, with optional variable substitution. Returns the full prompt text ready to send to an LLM. Variables not provided remain as [PLACEHOLDERS] in the output and are listed under unfilledVariables.

id number
cybersec_list_scenarios
annotations: none low

List all 7 scenario workflows — multi-step prompt chains for complete engagements (incident response, pentest, cloud audit, etc.). Each scenario takes variables and walks through chained phases.

cybersec_get_scenario
annotations: none low

Get a complete scenario workflow with every step expanded (phase, description, prompt text). Variables are substituted across all steps. Use this when the user describes a full engagement (incident, audit, hunt) rather than a single task.

Permissions 1

filesystem low
Server uses filesystem capabilities via: open(), os

Scan Findings 70

low
Tool 'cybersec_list_categories' has no annotations annotation_checker · 100%
low
Tool 'cybersec_list_prompts' has no annotations annotation_checker · 100%
low
Tool 'cybersec_get_prompt' has no annotations annotation_checker · 100%
low
Tool 'cybersec_list_scenarios' has no annotations annotation_checker · 100%
low
Tool 'cybersec_get_scenario' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.0.4 (GHSA-w48q-cv73-mx4w) dependency_analyzer · 95%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:252 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:263 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:267 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:269 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:270 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:271 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:278 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:279 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:281 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:282 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:283 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:285 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:286 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:287 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:288 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:289 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:291 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:292 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:293 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:294 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:295 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:297 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:298 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:300 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:302 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:310 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:311 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:318 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:319 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:328 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:329 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:334 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:338 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:340 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:341 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:342 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:343 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:344 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:345 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:346 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:347 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:349 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:351 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:353 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:354 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:357 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:358 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:359 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:360 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:361 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:362 entropy_analyzer · 80%
high
Long unicode escape chain in xu-c0-cybersec-mcp-bc9ef05/web-app/js/i18n.js:363 entropy_analyzer · 80%
info
package.json metadata manifest_parser · 100%
info
Tool: cybersec_list_categories manifest_parser · 70%
info
Tool: cybersec_list_prompts manifest_parser · 70%
info
Tool: cybersec_get_prompt manifest_parser · 70%
info
Tool: cybersec_list_scenarios manifest_parser · 70%
info
Tool: cybersec_get_scenario manifest_parser · 70%
info
Transport: stdio manifest_parser · 90%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
low
Permission: filesystem access detected permission_analyzer · 80%
info
SBOM generated: 95 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%