Registry listed
attack-surface-mcp-server
io.github.cyanheads/attack-surface-mcp-server
Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
Registry namespace and declared repository point to the same GitHub account; vendor affiliation is not independently certified.
Source version 0.2.1 · metadata updated 2026-08-30 · observed 2026-09-08
Requirements & setup
Facts belong to the specific distribution and mode shown. Combining facts from different modes can produce an unusable configuration.
npm: @cyanheads/attack-surface-mcp-server
- Run location
- Local process · stdio
- Authentication
- Unknown — absence of metadata is not no-auth.
- Dependencies
- Review the source package instructions. A local process may still use remote services.
- Costs
- Unknown — source availability does not establish total service costs.
- Documented clients
- Unknown; review client and publisher documentation.
Distribution metadata
- Package
@cyanheads/attack-surface-mcp-server- Declared variable names
SHODAN_API_KEY,CERTSPOTTER_API_KEY,ATTACKSURFACE_DEFAULT_RESOLVERS,ATTACKSURFACE_HTTP_USER_AGENT,ATTACKSURFACE_MAX_SUBDOMAINS,ATTACKSURFACE_RDAP_BOOTSTRAP_URL,ATTACKSURFACE_ALLOW_PRIVATE_TARGETS,MCP_LOG_LEVELValues and defaults are never retained here.
npm: @cyanheads/attack-surface-mcp-server
- Run location
- Local process · streamable-http
- Authentication
- Unknown — absence of metadata is not no-auth.
- Dependencies
- Review the source package instructions. A local process may still use remote services.
- Costs
- Unknown — source availability does not establish total service costs.
- Documented clients
- Unknown; review client and publisher documentation.
Distribution metadata
- Package
@cyanheads/attack-surface-mcp-server- Declared variable names
MCP_HTTP_HOST,MCP_HTTP_PORT,MCP_HTTP_ENDPOINT_PATH,MCP_AUTH_MODE,MCP_LOG_LEVELValues and defaults are never retained here.
Observed versions & changes
This directory observed 1 release record for this identity. A latest-only initial scan is not a complete release archive. Metadata changes are not runtime or breaking-change verdicts.
- 0.2.1active · source-designated latest · 2026-08-30Source
Catalog observation history
- artifact observed2026-09-07 · 0.2.1
Prepare a correction
Create a local note for review. This does not submit anything. This preview has no live moderation inbox. Include only public facts, never credentials or private logs.