Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"cybersec": {
"args": [
"-y",
"@xu-c0/cybersec-mcp"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Cybersecurity MCP server: 323 prompts + 7 workflows for red team, blue team, SOC, cloud, OSINT.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y '@xu-c0/cybersec-mcp' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
No known CVEs.
Checked @xu-c0/cybersec-mcp against OSV.dev.
This server is missing a description. Tools and install config are also missing.If you've used it, help the community.
Add informationBe the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in security
An evil MCP server used for redteam testing
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
Proof primitive for AI agents on MultiversX. Anchor file hashes on-chain as verifiable proofs.
mcpki-server is the backend infrastructure for https://www.mcpki.org, enabling secure public key management and autonomous certificate handling for large language models (LLMs).
MCP Security Weekly
Get CVE alerts and security updates for io.github.xu-c0/cybersec-mcp and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
MCP server with 323 cybersecurity prompts and 7 chained workflows. Install it and Claude (or any MCP-compatible client) can run an incident-response plan, a cloud audit, or a pentest by calling tools instead of you copy-pasting prompts.
Live demo · MIT License · Model Context Protocol
npx -y @xu-c0/cybersec-mcp
Claude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json on macOS, %APPDATA%\Claude\claude_desktop_config.json on Windows):
{
"mcpServers": {
"cybersec": {
"command": "npx",
"args": ["-y", "@xu-c0/cybersec-mcp"]
}
}
}
Then:
Use cybersec to plan an incident response for unusual outbound traffic from a SIEM-flagged host. SIEM is Splunk, EDR is CrowdStrike.
The agent picks the incident-response scenario, fills your variables in, and walks through detection, triage, containment, eradication, and post-mortem with concrete commands at each step.
323 prompts across 8 categories. Every prompt takes typed variables and returns output in a defined shape (steps, tables, SIEM queries, MITRE tags).
| Category | Prompts | Covers |
|---|---|---|
| Red Team | 45 | Pentest methodology, AD attack paths, C2 infra, social engineering |
| Blue Team | 42 | Log analysis, IR playbooks, detection engineering, deception |
| SOC Operations | 42 | Splunk/Sentinel/Elastic queries, alert triage, runbooks, shift handover |
| Cloud Security | 38 | AWS/Azure/GCP audits, IAM, container security, CSPM |
| OSINT | 38 | Domain intel, threat actor profiling, footprinting, attribution |
| GRC | 38 | ISO 27001, SOC 2, NIST CSF, risk assessment, policy generation |
| Vulnerability Analysis | 42 | CVE triage, CVSS 4.0, patch prioritization, pentest reports |
| AI Agent Security | 38 | LLM red teaming, prompt injection, agent guardrails, supply chain |
Source: content/prompts-master.md → generated web-app/js/data.js.
Seven end-to-end workflows that chain prompts and pass variables between steps:
Definitions live in web-app/js/scenarios.js.
cybersec-mcp.vercel.app — browse every prompt, fill in variables, copy the rendered text into any LLM. Dark mode, English / 한국어 / 日本語, no signup. Same data as the MCP server, different interface.
Useful when you want to inspect what a tool will send before wiring up the server, or hand a teammate a one-off prompt.
Red team, blue team, and SOC prompts are tagged to MITRE ATT&CK tactics. The full mapping is in ATTACK_MATRIX.md — useful for purple-team exercises and detection-coverage reviews.
mcp/ MCP server (TypeScript, in progress)
web-app/ Static demo deployed to Vercel
content/ prompts-master.md — prompt source of truth
examples/ Client configs (Claude Desktop, Cursor, Claude Code)
parse_prompts.py regenerates web-app/js/data.js from content/prompts-master.md.
PRs welcome — new prompts, MITRE tags, scenario workflows, translations, MCP tool fixes. Schema and quality bar in CONTRIBUTING.md.
Thi