# Pentest Tools

> Use this tool when you need to conduct comprehensive security assessments and penetration tests, solving problems such as vulnerability identification and password cracking. It takes inputs like scan parameters and wordlist paths, and outputs structured JSON results from tools like nmap, nikto, and hashcat. This tool is ideal for security professionals and AI assistants requiring automated access to security testing capabilities.

Canonical page: https://skillsregistry.net/skills/pentest-tools  
JSON: https://api.skillsregistry.net/v1/skills/pentest-tools

## Description

This MCP server provides AI assistants with direct access to penetration testing tools including nmap, gobuster, nikto, nuclei, ffuf, dirsearch, hydra, john, and hashcat for comprehensive security assessments. Built by Vyom Jain using Node.js with the Model Context Protocol SDK, it executes security tools as child processes and parses their output into structured JSON results, supporting various scan types from quick port scans to full vulnerability assessments and password cracking operations. The implementation includes hardcoded wordlist paths, configurable scan parameters, timeout handling, and a comprehensive scan mode that combines multiple tools automatically, making it valuable for security professionals conducting penetration tests, vulnerability assessments, and building AI assistants that need programmatic access to security testing capabilities without manual tool execution.

## Trust

- **Trust score (0–1):** 0.87
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/pentest-tools)
- **Repository:** <https://github.com/vyomjain6904/pentest-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "pentest-tools"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/pentest-tools` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/pentest-tools/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
