Skip to content

History of MCP server in namespace io.github

io.github.cyanheads/attack-surface-mcp-server · Status: active

The source provides no name of its own for this entry. The identifier therefore appears on this page as a coordinate, not as the heading.

If you find your own account name here: write informally to German.saas@web.de, stating the identifier concerned. No reason has to be given. How to object

Every published change to this entry, most recent first.

Changes
2026-08-22Version: 0.1.1 → 0.2.0
2026-08-22Last changed in the registry (raw): 2026-06-14 → 2026-08-21
2026-08-22First listed in the registry (raw): 2026-06-14 → 2026-08-21
2026-08-22Package versions (raw): 0.1.1 → 0.2.0
2026-08-16Last changed in the registry (raw): – → 2026-06-14
2026-08-16First listed in the registry (raw): – → 2026-06-14
2026-08-16Registry status message (raw): – → –
2026-08-16Schema version of the raw record (raw): – → https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json
2026-08-16Icon formats (raw): – → –
2026-08-16Environment variable descriptions (raw): – → ATTACKSURFACE_ALLOW_PRIVATE_TARGETS=Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only). · ATTACKSURFACE_DEFAULT_RESOLVERS=Comma-separated default DNS resolver IPs for attacksurface_resolve_dns. · ATTACKSURFACE_HTTP_USER_AGENT=Default User-Agent for attacksurface_probe_http (overridable per call). · ATTACKSURFACE_MAX_SUBDOMAINS=Cap on subdomains resolved during a map_domain run. · ATTACKSURFACE_RDAP_BOOTSTRAP_URL=RDAP bootstrap base URL; override for a private/mirrored RDAP. · CERTSPOTTER_API_KEY=Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier. · MCP_AUTH_MODE=Authentication mode to use: 'none', 'jwt', or 'oauth'. · MCP_HTTP_ENDPOINT_PATH=The endpoint path for the MCP server. · MCP_HTTP_HOST=The hostname for the HTTP server. · MCP_HTTP_PORT=The port to run the HTTP server on. · MCP_LOG_LEVEL=Sets the minimum log level for output (e.g., 'debug', 'info', 'warn'). · SHODAN_API_KEY=Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.
2026-08-16Environment variable formats (raw): – → string
2026-08-16Delivery form (raw): – → paket
2026-08-16Remote hosts (raw): – → –
2026-08-16Remote URLs (raw): – → –
2026-08-16Runtime hints (raw): – → bun
2026-08-16Package versions (raw): – → 0.1.1
2026-08-16Package identifiers (raw): – → @cyanheads/attack-surface-mcp-server
2026-08-16Repository subfolder (raw): – → –
2026-08-16Repository platform (raw): – → github
2026-08-16Path environment variables (raw): – → –
2026-08-16Required secret headers (raw): – → –
2026-08-06Version: – → 0.1.1
2026-08-06Repository URL listed: – → true
2026-08-06Path argument present: – → false
2026-08-06Execution location: – → local
2026-08-06Credentials required: – → false
2026-08-06Package registries (raw): – → npm, npm
2026-08-06Repository (raw): – → https://github.com/cyanheads/attack-surface-mcp-server
2026-08-06Path arguments (raw): – → –
2026-08-06Transports (raw): – → stdio, streamable-http
2026-08-06Required secret variables (raw): – → –
2026-08-06Environment variables (raw): – → SHODAN_API_KEY, CERTSPOTTER_API_KEY, ATTACKSURFACE_DEFAULT_RESOLVERS, ATTACKSURFACE_HTTP_USER_AGENT, ATTACKSURFACE_MAX_SUBDOMAINS, ATTACKSURFACE_RDAP_BOOTSTRAP_URL, ATTACKSURFACE_ALLOW_PRIVATE_TARGETS, MCP_LOG_LEVEL, MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE, MCP_LOG_LEVEL

tracevero · https://tracevero.com/mcp/io-github-cyanheads-attack-surface-mcp-server/aenderungen