History of attack-surface-mcp-server in namespace io.github
io.github.cyanheads/attack-surface-mcp-server · Registry status: active
No name of its own reaches this register for this entry. The heading therefore carries the trailing segment of the identifier; the identifier itself is listed below as a coordinate.
Every published change to this entry, most recent first.
| 2026-10-01 | Declared version: 0.2.2 → 0.2.3 |
|---|---|
| 2026-10-01 | Last changed in the registry (raw): 2026-09-22 → 2026-09-30 |
| 2026-10-01 | First listed in the registry (raw): 2026-09-22 → 2026-09-30 |
| 2026-10-01 | Connection paths (source structure): {"packages":[{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.2","runtimeHint":"bun","transport":"stdio","environment":[{"name":"SHODAN_API_KEY","description":"Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.","format":"string","required":false,"secret":true},{"name":"CERTSPOTTER_API_KEY","description":"Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.","format":"string","required":false,"secret":true},{"name":"ATTACKSURFACE_DEFAULT_RESOLVERS","description":"Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_HTTP_USER_AGENT","description":"Default User-Agent for attacksurface_probe_http (overridable per call).","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_MAX_SUBDOMAINS","description":"Cap on subdomains resolved during a map_domain run.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_RDAP_BOOTSTRAP_URL","description":"RDAP bootstrap base URL; override for a private/mirrored RDAP.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS","description":"Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.2","runtimeHint":"bun","transport":"streamable-http","environment":[{"name":"MCP_HTTP_HOST","description":"The hostname for the HTTP server.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_PORT","description":"The port to run the HTTP server on.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_ENDPOINT_PATH","description":"The endpoint path for the MCP server.","format":"string","required":false,"secret":false},{"name":"MCP_AUTH_MODE","description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.3","runtimeHint":"bun","transport":"stdio","environment":[{"name":"SHODAN_API_KEY","description":"Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.","format":"string","required":false,"secret":true},{"name":"CERTSPOTTER_API_KEY","description":"Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.","format":"string","required":false,"secret":true},{"name":"ATTACKSURFACE_DEFAULT_RESOLVERS","description":"Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_HTTP_USER_AGENT","description":"Default User-Agent for attacksurface_probe_http (overridable per call).","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_MAX_SUBDOMAINS","description":"Cap on subdomains resolved during a map_domain run.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_RDAP_BOOTSTRAP_URL","description":"RDAP bootstrap base URL; override for a private/mirrored RDAP.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS","description":"Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.3","runtimeHint":"bun","transport":"streamable-http","environment":[{"name":"MCP_HTTP_HOST","description":"The hostname for the HTTP server.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_PORT","description":"The port to run the HTTP server on.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_ENDPOINT_PATH","description":"The endpoint path for the MCP server.","format":"string","required":false,"secret":false},{"name":"MCP_AUTH_MODE","description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-10-01 | Package versions (raw): 0.2.2 → 0.2.3 |
| 2026-09-23 | Declared version: 0.2.1 → 0.2.2 |
| 2026-09-23 | Last changed in the registry (raw): 2026-08-30 → 2026-09-22 |
| 2026-09-23 | First listed in the registry (raw): 2026-08-30 → 2026-09-22 |
| 2026-09-23 | Connection paths (source structure): {"packages":[{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.1","runtimeHint":"bun","transport":"stdio","environment":[{"name":"SHODAN_API_KEY","description":"Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.","format":"string","required":false,"secret":true},{"name":"CERTSPOTTER_API_KEY","description":"Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.","format":"string","required":false,"secret":true},{"name":"ATTACKSURFACE_DEFAULT_RESOLVERS","description":"Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_HTTP_USER_AGENT","description":"Default User-Agent for attacksurface_probe_http (overridable per call).","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_MAX_SUBDOMAINS","description":"Cap on subdomains resolved during a map_domain run.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_RDAP_BOOTSTRAP_URL","description":"RDAP bootstrap base URL; override for a private/mirrored RDAP.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS","description":"Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.1","runtimeHint":"bun","transport":"streamable-http","environment":[{"name":"MCP_HTTP_HOST","description":"The hostname for the HTTP server.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_PORT","description":"The port to run the HTTP server on.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_ENDPOINT_PATH","description":"The endpoint path for the MCP server.","format":"string","required":false,"secret":false},{"name":"MCP_AUTH_MODE","description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.2","runtimeHint":"bun","transport":"stdio","environment":[{"name":"SHODAN_API_KEY","description":"Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.","format":"string","required":false,"secret":true},{"name":"CERTSPOTTER_API_KEY","description":"Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.","format":"string","required":false,"secret":true},{"name":"ATTACKSURFACE_DEFAULT_RESOLVERS","description":"Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_HTTP_USER_AGENT","description":"Default User-Agent for attacksurface_probe_http (overridable per call).","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_MAX_SUBDOMAINS","description":"Cap on subdomains resolved during a map_domain run.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_RDAP_BOOTSTRAP_URL","description":"RDAP bootstrap base URL; override for a private/mirrored RDAP.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS","description":"Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.2","runtimeHint":"bun","transport":"streamable-http","environment":[{"name":"MCP_HTTP_HOST","description":"The hostname for the HTTP server.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_PORT","description":"The port to run the HTTP server on.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_ENDPOINT_PATH","description":"The endpoint path for the MCP server.","format":"string","required":false,"secret":false},{"name":"MCP_AUTH_MODE","description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-09-23 | Package versions (raw): 0.2.1 → 0.2.2 |
| 2026-09-08 | Connection paths (source structure): – → {"packages":[{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.1","runtimeHint":"bun","transport":"stdio","environment":[{"name":"SHODAN_API_KEY","description":"Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.","format":"string","required":false,"secret":true},{"name":"CERTSPOTTER_API_KEY","description":"Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.","format":"string","required":false,"secret":true},{"name":"ATTACKSURFACE_DEFAULT_RESOLVERS","description":"Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_HTTP_USER_AGENT","description":"Default User-Agent for attacksurface_probe_http (overridable per call).","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_MAX_SUBDOMAINS","description":"Cap on subdomains resolved during a map_domain run.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_RDAP_BOOTSTRAP_URL","description":"RDAP bootstrap base URL; override for a private/mirrored RDAP.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS","description":"Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.1","runtimeHint":"bun","transport":"streamable-http","environment":[{"name":"MCP_HTTP_HOST","description":"The hostname for the HTTP server.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_PORT","description":"The port to run the HTTP server on.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_ENDPOINT_PATH","description":"The endpoint path for the MCP server.","format":"string","required":false,"secret":false},{"name":"MCP_AUTH_MODE","description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-08-31 | Declared version: 0.2.0 → 0.2.1 |
| 2026-08-31 | Last changed in the registry (raw): 2026-08-21 → 2026-08-30 |
| 2026-08-31 | First listed in the registry (raw): 2026-08-21 → 2026-08-30 |
| 2026-08-31 | Package versions (raw): 0.2.0 → 0.2.1 |
| 2026-08-26 | Description (raw): – → Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan. |
| 2026-08-22 | Declared version: 0.1.1 → 0.2.0 |
| 2026-08-22 | Last changed in the registry (raw): 2026-06-14 → 2026-08-21 |
| 2026-08-22 | First listed in the registry (raw): 2026-06-14 → 2026-08-21 |
| 2026-08-22 | Package versions (raw): 0.1.1 → 0.2.0 |
| 2026-08-16 | Last changed in the registry (raw): – → 2026-06-14 |
| 2026-08-16 | First listed in the registry (raw): – → 2026-06-14 |
| 2026-08-16 | Registry status message (raw): – → – |
| 2026-08-16 | Schema version of the raw record (raw): – → https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json |
| 2026-08-16 | Icon formats (raw): – → – |
| 2026-08-16 | Environment variable descriptions (raw): – → ATTACKSURFACE_ALLOW_PRIVATE_TARGETS=Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only). · ATTACKSURFACE_DEFAULT_RESOLVERS=Comma-separated default DNS resolver IPs for attacksurface_resolve_dns. · ATTACKSURFACE_HTTP_USER_AGENT=Default User-Agent for attacksurface_probe_http (overridable per call). · ATTACKSURFACE_MAX_SUBDOMAINS=Cap on subdomains resolved during a map_domain run. · ATTACKSURFACE_RDAP_BOOTSTRAP_URL=RDAP bootstrap base URL; override for a private/mirrored RDAP. · CERTSPOTTER_API_KEY=Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier. · MCP_AUTH_MODE=Authentication mode to use: 'none', 'jwt', or 'oauth'. · MCP_HTTP_ENDPOINT_PATH=The endpoint path for the MCP server. · MCP_HTTP_HOST=The hostname for the HTTP server. · MCP_HTTP_PORT=The port to run the HTTP server on. · MCP_LOG_LEVEL=Sets the minimum log level for output (e.g., 'debug', 'info', 'warn'). · SHODAN_API_KEY=Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works. |
| 2026-08-16 | Environment variable formats (raw): – → string |
| 2026-08-16 | Delivery form (raw): – → package |
| 2026-08-16 | Remote hosts (raw): – → – |
| 2026-08-16 | Remote URLs (raw): – → – |
| 2026-08-16 | Runtime hints (raw): – → bun |
| 2026-08-16 | Package versions (raw): – → 0.1.1 |
| 2026-08-16 | Package identifiers (raw): – → @cyanheads/attack-surface-mcp-server |
| 2026-08-16 | Repository subfolder (raw): – → – |
| 2026-08-16 | Repository platform (raw): – → github |
| 2026-08-16 | Path environment variables (raw): – → – |
| 2026-08-16 | Required secret headers (raw): – → – |
| 2026-08-06 | Declared version: – → 0.1.1 |
| 2026-08-06 | Repository URL listed: – → yes |
| 2026-08-06 | Path argument present: – → no |
| 2026-08-06 | Execution location: – → local |
| 2026-08-06 | Required secrets declared: – → no |
| 2026-08-06 | Package registries (raw): – → npm, npm |
| 2026-08-06 | Repository (raw): – → https://github.com/cyanheads/attack-surface-mcp-server |
| 2026-08-06 | Path arguments (raw): – → – |
| 2026-08-06 | Transports (raw): – → stdio, streamable-http |
| 2026-08-06 | Required secret variables (raw): – → – |
| 2026-08-06 | Environment variables (raw): – → SHODAN_API_KEY, CERTSPOTTER_API_KEY, ATTACKSURFACE_DEFAULT_RESOLVERS, ATTACKSURFACE_HTTP_USER_AGENT, ATTACKSURFACE_MAX_SUBDOMAINS, ATTACKSURFACE_RDAP_BOOTSTRAP_URL, ATTACKSURFACE_ALLOW_PRIVATE_TARGETS, MCP_LOG_LEVEL, MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE, MCP_LOG_LEVEL |
tracevero · https://tracevero.com/mcp/io-github-cyanheads-attack-surface-mcp-server/aenderungen