Skip to content

Raw values for attack-surface-mcp-server in namespace io.github

io.github.cyanheads/attack-surface-mcp-server · Registry status: active

No name of its own reaches this register for this entry. The heading therefore carries the trailing segment of the identifier; the identifier itself is listed below as a coordinate.

Report data on this entry

What the source declared verbatim, unchanged and uninterpreted. The derived values on the overview page are computed from these.

Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.

Raw values
Description (raw)Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
Source: MCP-Register · collected on 2026-08-26 · self-declared
Environment variables (raw)SHODAN_API_KEY, CERTSPOTTER_API_KEY, ATTACKSURFACE_DEFAULT_RESOLVERS, ATTACKSURFACE_HTTP_USER_AGENT, ATTACKSURFACE_MAX_SUBDOMAINS, ATTACKSURFACE_RDAP_BOOTSTRAP_URL, ATTACKSURFACE_ALLOW_PRIVATE_TARGETS, MCP_LOG_LEVEL, MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE, MCP_LOG_LEVEL
Source: MCP-Register · collected on 2026-08-06 · self-declared
Required secret variables (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-06 · self-declared
Transports (raw)stdio, streamable-http
Source: MCP-Register · collected on 2026-08-06 · self-declared
Path arguments (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-06 · self-declared
Repository (raw)https://github.com/cyanheads/attack-surface-mcp-server
Source: MCP-Register · collected on 2026-08-06 · self-declared
Package registries (raw)npm, npm
Source: MCP-Register · collected on 2026-08-06 · self-declared
Required secret headers (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Path environment variables (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Remote URLs (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Remote hosts (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Registry status message (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
First listed in the registry (raw)2026-09-30
Source: MCP-Register · collected on 2026-10-01 · self-declared
Last changed in the registry (raw)2026-09-30
Source: MCP-Register · collected on 2026-10-01 · self-declared
Schema version of the raw record (raw)https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json
Source: MCP-Register · collected on 2026-08-16 · self-declared
Delivery form (raw)package
Source: MCP-Register · collected on 2026-08-16 · self-declared
Repository platform (raw)github
Source: MCP-Register · collected on 2026-08-16 · self-declared
Repository subfolder (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Package identifiers (raw)@cyanheads/attack-surface-mcp-server
Source: MCP-Register · collected on 2026-08-16 · self-declared
Package versions (raw)0.2.3
Source: MCP-Register · collected on 2026-10-01 · self-declared
Runtime hints (raw)bun
Source: MCP-Register · collected on 2026-08-16 · self-declared
Environment variable formats (raw)string
Source: MCP-Register · collected on 2026-08-16 · self-declared
Environment variable descriptions (raw)ATTACKSURFACE_ALLOW_PRIVATE_TARGETS=Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only). · ATTACKSURFACE_DEFAULT_RESOLVERS=Comma-separated default DNS resolver IPs for attacksurface_resolve_dns. · ATTACKSURFACE_HTTP_USER_AGENT=Default User-Agent for attacksurface_probe_http (overridable per call). · ATTACKSURFACE_MAX_SUBDOMAINS=Cap on subdomains resolved during a map_domain run. · ATTACKSURFACE_RDAP_BOOTSTRAP_URL=RDAP bootstrap base URL; override for a private/mirrored RDAP. · CERTSPOTTER_API_KEY=Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier. · MCP_AUTH_MODE=Authentication mode to use: 'none', 'jwt', or 'oauth'. · MCP_HTTP_ENDPOINT_PATH=The endpoint path for the MCP server. · MCP_HTTP_HOST=The hostname for the HTTP server. · MCP_HTTP_PORT=The port to run the HTTP server on. · MCP_LOG_LEVEL=Sets the minimum log level for output (e.g., 'debug', 'info', 'warn'). · SHODAN_API_KEY=Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.
Source: MCP-Register · collected on 2026-08-16 · self-declared
Icon formats (raw)confirmed absent
Source: MCP-Register · collected on 2026-08-16 · self-declared
Connection paths (source structure){"packages":[{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.3","runtimeHint":"bun","transport":"stdio","environment":[{"name":"SHODAN_API_KEY","description":"Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.","format":"string","required":false,"secret":true},{"name":"CERTSPOTTER_API_KEY","description":"Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.","format":"string","required":false,"secret":true},{"name":"ATTACKSURFACE_DEFAULT_RESOLVERS","description":"Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_HTTP_USER_AGENT","description":"Default User-Agent for attacksurface_probe_http (overridable per call).","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_MAX_SUBDOMAINS","description":"Cap on subdomains resolved during a map_domain run.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_RDAP_BOOTSTRAP_URL","description":"RDAP bootstrap base URL; override for a private/mirrored RDAP.","format":"string","required":false,"secret":false},{"name":"ATTACKSURFACE_ALLOW_PRIVATE_TARGETS","description":"Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"npm","identifier":"@cyanheads/attack-surface-mcp-server","version":"0.2.3","runtimeHint":"bun","transport":"streamable-http","environment":[{"name":"MCP_HTTP_HOST","description":"The hostname for the HTTP server.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_PORT","description":"The port to run the HTTP server on.","format":"string","required":false,"secret":false},{"name":"MCP_HTTP_ENDPOINT_PATH","description":"The endpoint path for the MCP server.","format":"string","required":false,"secret":false},{"name":"MCP_AUTH_MODE","description":"Authentication mode to use: 'none', 'jwt', or 'oauth'.","format":"string","required":false,"secret":false},{"name":"MCP_LOG_LEVEL","description":"Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').","format":"string","required":false,"secret":false}],"additional_arguments_declared":true}],"remotes":[]}
Source: MCP-Register · collected on 2026-10-01 · self-declared

Position within the directory

How many of the 42,239 published entries carry the same measured value. A reference figure, not an assessment.

All 4 values together are carried by 12,199 of 42,239 entries.

tracevero · https://tracevero.com/mcp/io-github-cyanheads-attack-surface-mcp-server/rohangaben