# Tengu

> Use this tool when you need to conduct comprehensive security testing and vulnerability assessments across multiple domains, including web applications, networks, and cloud infrastructure. Tengu solves problems related to security reconnaissance, exploitation, and penetration testing, providing a robust framework for identifying and addressing potential threats. It takes in target specifications and configuration inputs, producing detailed reports and audit logs as output, and is ideal for use cases requiring automated or guided security testing and compliance evaluation.

Canonical page: https://skillsregistry.net/skills/rfunix-tengu  
JSON: https://api.skillsregistry.net/v1/skills/rfunix-tengu

## Description

Comprehensive pentesting MCP server that orchestrates 80 security tools across reconnaissance, web scanning, injection testing, exploitation, Active Directory attacks, cloud security, and stealth operations. Features a safety pipeline with input sanitization, target allowlists, rate limiting, and audit logging. Includes 35 pre-built workflow prompts, 20 reference resources (OWASP Top 10, MITRE ATT&CK, PTES methodology), and tiered Docker images (minimal/core/full). Supports both interactive copilot mode via MCP and a fully autonomous agent mode using LangGraph that follows the 7-phase PTES methodology with human-in-the-loop gates for destructive actions.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-04-29

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/rfunix-tengu)
- **Repository:** <https://github.com/rfunix/tengu>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "rfunix-tengu"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/rfunix-tengu` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/rfunix-tengu/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
