Raw values for attack-surface-mcp-server in namespace io.github
io.github.cyanheads/attack-surface-mcp-server · Registry status: active
No name of its own reaches this register for this entry. The heading therefore carries the trailing segment of the identifier; the identifier itself is listed below as a coordinate.
What the source declared verbatim, unchanged and uninterpreted. The derived values on the overview page are computed from these.
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Description (raw) | Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan. Source: MCP-Register · collected on 2026-08-26 · self-declared |
|---|---|
| Environment variables (raw) | SHODAN_API_KEY, CERTSPOTTER_API_KEY, ATTACKSURFACE_DEFAULT_RESOLVERS, ATTACKSURFACE_HTTP_USER_AGENT, ATTACKSURFACE_MAX_SUBDOMAINS, ATTACKSURFACE_RDAP_BOOTSTRAP_URL, ATTACKSURFACE_ALLOW_PRIVATE_TARGETS, MCP_LOG_LEVEL, MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE, MCP_LOG_LEVEL Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Required secret variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Transports (raw) | stdio, streamable-http Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Repository (raw) | https://github.com/cyanheads/attack-surface-mcp-server Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Package registries (raw) | npm, npm Source: MCP-Register · collected on 2026-08-06 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Path environment variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote URLs (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote hosts (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| First listed in the registry (raw) | 2026-09-30 Source: MCP-Register · collected on 2026-10-01 · self-declared |
| Last changed in the registry (raw) | 2026-09-30 Source: MCP-Register · collected on 2026-10-01 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Delivery form (raw) | package Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository subfolder (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package identifiers (raw) | @cyanheads/attack-surface-mcp-server Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package versions (raw) | 0.2.3 Source: MCP-Register · collected on 2026-10-01 · self-declared |
| Runtime hints (raw) | bun Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable formats (raw) | string Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable descriptions (raw) | ATTACKSURFACE_ALLOW_PRIVATE_TARGETS=Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only). · ATTACKSURFACE_DEFAULT_RESOLVERS=Comma-separated default DNS resolver IPs for attacksurface_resolve_dns. · ATTACKSURFACE_HTTP_USER_AGENT=Default User-Agent for attacksurface_probe_http (overridable per call). · ATTACKSURFACE_MAX_SUBDOMAINS=Cap on subdomains resolved during a map_domain run. · ATTACKSURFACE_RDAP_BOOTSTRAP_URL=RDAP bootstrap base URL; override for a private/mirrored RDAP. · CERTSPOTTER_API_KEY=Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier. · MCP_AUTH_MODE=Authentication mode to use: 'none', 'jwt', or 'oauth'. · MCP_HTTP_ENDPOINT_PATH=The endpoint path for the MCP server. · MCP_HTTP_HOST=The hostname for the HTTP server. · MCP_HTTP_PORT=The port to run the HTTP server on. · MCP_LOG_LEVEL=Sets the minimum log level for output (e.g., 'debug', 'info', 'warn'). · SHODAN_API_KEY=Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works. Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Icon formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Connection paths (source structure) | {"packages":[{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.3","runtimeHint":"bun","transport":"stdio","environment":[{"name":"SHODAN_API_KEY","description":"Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.","format":"string","required":false,"secret":true},{"name":"CERTSPOTTER_API_KEY","description":"Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.","format":"string","required":false,"secret":true},{"name":"ATTACKSURFACE_DEFAULT_RESOLVERS","description":"Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_HTTP_USER_AGENT","description":"Default User-Agent for attacksurface_probe_http (overridable per call).","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_MAX_SUBDOMAINS","description":"Cap on subdomains resolved during a map_domain run.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_RDAP_BOOTSTRAP_URL","description":"RDAP bootstrap base URL; override for a private/mirrored RDAP.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS","description":"Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.3","runtimeHint":"bun","transport":"streamable-http","environment":[{"name":"MCP_HTTP_HOST","description":"The hostname for the HTTP server.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_PORT","description":"The port to run the HTTP server on.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_ENDPOINT_PATH","description":"The endpoint path for the MCP server.","format":"string","required":false,"secret":false},{"name":"MCP_AUTH_MODE","description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} Source: MCP-Register · collected on 2026-10-01 · self-declared |
Position within the directory
How many of the 42,239 published entries carry the same measured value. A reference figure, not an assessment.
- Required secrets declaredno36,126 of 42,239 carry this value (86 %)View these entries
- Execution locationlocal17,143 of 42,239 carry this value (41 %)View these entries
- Path argument presentno41,736 of 42,239 carry this value (99 %)View these entries
- Repository URL listedyes30,309 of 42,239 carry this value (72 %)View these entries
All 4 values together are carried by 12,199 of 42,239 entries.
tracevero · https://tracevero.com/mcp/io-github-cyanheads-attack-surface-mcp-server/rohangaben