MCP server for AI-powered network scanning with Nmap. Port scanning, service detection, OS fingerprinting, and vulnerability scanning for AI agents.
nmap-mcp demonstrates solid foundational quality with clear naming conventions, comprehensive parameter schemas, and well-documented tools. All 6 tools follow verb_noun patterns (scan-*, discover-*, detect-*). Parameter descriptions are detailed and include constraints (gt, le, ge). However, there are notable gaps: output schemas are not explicitly documented in the tool definitions (only inferred from code), some parameters lack explicit enum constraints despite having enumerated options (e.g., scan_type, timing, script_category are strings without enum declarations), and error handling is not evident in the visible tool signatures. The server emphasizes authorization warnings extensively but lacks actionable error recovery guidance in the tool schemas themselves. Transport is STDIO-only, which impacts practical deployability but does not directly affect definition quality scoring.
Detect the operating system of a target using TCP/IP stack fingerprinting. Uses nmap's OS detection (-O) to attempt identification of the target's operating system. This requires elevated privileges (root/sudo) and responds best to full port scans. IMPORTANT: Only scan targets you are authorized to scan. Returns: ScanResult with OS detection matches and confidence scores.
Detect services and versions running on open ports. Uses nmap's service detection probes (-sV) to identify software names, versions, and CPE identifiers for services running on open ports. IMPORTANT: Only scan targets you are authorized to scan. Returns: ScanResult with service information for each open port.
Discover live hosts on a network without performing a port scan. Uses nmap ping scan (-sn) to identify which hosts are up on the target network. This is typically the first step in a network assessment. IMPORTANT: Only scan networks you are authorized to scan. Returns: HostDiscoveryResult with lists of hosts that are up and down.
Perform a fast scan of the top N most common ports. Quickly scans the most commonly used ports on a target using nmap's --top-ports feature. Good for a quick security overview without waiting for a full port scan. IMPORTANT: Only scan targets you are authorized to scan. Returns: ScanResult with discovered open ports on the target.
Enum constraints not declared in schema for enumerated parameters. scan_type accepts 'connect', 'syn', 'udp', 'fin', 'xmas', 'null', 'ack' but is defined as a plain string without enum constraint. Similarly, timing accepts 'paranoid', 'sneaky', 'polite', 'normal', 'aggressive', 'insane' and script_category accepts specific categories, but none are declared as enums. This invites LLMs to hallucinate invalid values rather than picking from a self-documenting list.
Output schemas (return types) are not documented in tool definitions. The rubric requires 'Tools returning lists should... return a total count or next_cursor' and 'Document the output schema.' Descriptions mention 'Returns: ScanResult' or 'Returns: HostDiscoveryResult' but the actual schema structure (field names, types) is not visible in the tool registration. LLMs cannot know what fields to extract for downstream chaining.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 65 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 37 | - | v1 |
Scan ports on a target host or network. Performs a port scan using nmap with the specified parameters. Validates all inputs to prevent command injection. IMPORTANT: Only scan targets you are authorized to scan. Returns: ScanResult with discovered hosts, ports, and their states.
Run NSE (Nmap Scripting Engine) vulnerability detection scripts. Executes nmap NSE scripts from safe categories (auth, default, discovery, safe, version, vuln) to detect known vulnerabilities on the target. IMPORTANT: Only scan targets you are authorized to scan. Returns: VulnScanResult with discovered vulnerabilities.
Error handling and recovery guidance absent from tool schemas. No indication of what errors can occur, how to classify them (retryable vs. fatal), or what the LLM should do next. The tool descriptions warn about authorization but do not guide the agent if a scan fails (e.g., 'Host unreachable, try discover-hosts first').
scan-vulnerabilities script_category parameter is a string without enum constraint, despite having a documented safe set: 'auth', 'default', 'discovery', 'safe', 'version', 'vuln'. Should be an enum to prevent hallucinated category names and to enforce safety guardrails.
Pagination and result limits not explicitly declared. While the tools appear to accept targets and return results, there is no indication of whether results are paginated, what the default/max result count is, or how to handle large result sets. The rubric requires: 'Tools returning lists should accept page/offset and limit parameters and return a total count or next_cursor.'