Static source inference · medium confidence · detected: Logging
Deprecated protocol patterns detected
Summary
nuclei-mcp exhibits moderate-to-poor definition quality. While tool names follow verb-noun conventions and descriptions are present, there are significant gaps in parameter documentation, schema completeness, and error handling guidance. Only 2 of 5 tools have fully documented input schemas with type information. Parameters lack constraint information (enums, ranges, formats), and descriptions are brief without explaining when to use tools or what dependencies exist. Output schemas are entirely undocumented. The server's focus on security scanning is clear, but the tool definitions do not meet production standards for LLM-driven agents.
Tools (5)
add_templatewritesource verified67/100
Adds a new Nuclei template.
basic_scanread onlysource verified55/100
Performs a basic Nuclei vulnerability scan on a target without requiring template IDs
Critical: Parameters lack type definitions in visible schema. 'protocols', 'template_ids', and 'template_id' are documented as strings but lack format/pattern constraints. No indication of comma-separated syntax or valid protocol names.
Convert severity parameter to enum: severity: {type: 'string', enum: ['info', 'low', 'medium', 'high', 'critical'], description: 'Minimum severity level to report. Defaults to info. Only vulnerabilities at or above this level are included in results.'}
Document protocols parameter with examples and constraints: 'Comma-separated list of protocols to scan. Valid values: http, https, tcp, udp, dns, ftp, ssh. Defaults to http. Example: "http,https,tcp".'
Document template_id vs template_ids constraint: 'Provide either template_id (single template by ID) or template_ids (comma-separated list), not both. If both are provided, template_ids takes precedence.'
Add thread_safe description: 'Enable thread-safe scanning engine for parallel vulnerability checks. Use when scanning multiple targets or large scan scopes. Slightly slower per-target but tolerates concurrent agent calls.'
Enhance basic_scan description: 'Simplified Nuclei scan using a curated default template set optimized for common web vulnerabilities (CVE detection, auth bypass, info disclosure). Use when you don't know specific templates to test. For advanced scanning with custom templates, use nuclei_scan.',
Add list_templates output documentation: 'Returns array of template objects: [{id: string, name: string, severity: string, author: string, tags: [string]}]. Maximum 100 results per call. Use pagination with limit and offset for large template libraries.'
Spec posture evidence
Inferred effective spec: <=2025-11-25.
Relies on Logging (deprecated) - log to stderr or use OpenTelemetry
High: basic_scan lacks explanation of how it differs from nuclei_scan or when to prefer it. Description does not mention what templates it uses by default or constraints compared to the full-featured tool.
High: No error handling or recovery guidance. Tools lack descriptions of failure modes (e.g., invalid target, scan timeout, no vulnerabilities found). LLMs receive no context for retrying or alternative actions.
Medium: Mutually exclusive parameters not documented. nuclei_scan accepts both 'template_id' and 'template_ids', this is ambiguous. Should state in description: 'Provide either template_id (single) or template_ids (comma-separated), not both.'
Medium: thread_safe parameter lacks any description of what it does or when to enable it. Is it a performance optimization? A concurrency limit? LLMs cannot decide when to use it.
Medium: list_templates returns empty input schema ({}). No description of pagination, result limits, or filtering. If the template library is large, LLMs may be overwhelmed with output.
Medium: add_template and get_template reference 'template file' but do not clarify file format. Are these YAML? JSON? Plain text? No schema validation rules documented.
Low: Descriptions are brief (55-70 chars average). According to production baselines, A+ tools average 194 chars. Current descriptions lack context on when/why to call tools or what depends on them.
nuclei_scanbasic_scanlist_templatesget_template
Document get_template output: 'Returns template object with fields: {name: string, content: string, format: "yaml", severity: string, tags: [string]}. Content is the raw YAML template definition.'
Add error handling guidance to nuclei_scan: 'If target is unreachable, returns {error: "target unreachable", recovery: "Verify target hostname/IP and network connectivity."}. If templates not found, returns {error: "templates not found", recovery: "Call list_templates() to see available IDs."}.'
Add pagination parameters to list_templates: {limit: {type: 'integer', min: 1, max: 100, default: 20, description: 'Number of templates to return per page.'}, offset: {type: 'integer', min: 0, default: 0, description: 'Number of templates to skip for pagination.'}}
Clarify add_template parameter constraints: 'content must be valid YAML (validated on upload). Template must include id, name, and requests sections per Nuclei template specification.'
Expand nuclei_scan description to 150+ chars explaining when to use it vs basic_scan and what preparatory steps might be needed (e.g., 'Ensure target is accessible before calling').