FOFA API, MCP 2.0 and vendor-neutral workflow agent for internet asset reconnaissance
FofaMap MCP server demonstrates moderately strong definition quality with consistent naming conventions and tool annotations, but suffers from incomplete parameter descriptions and missing output schema documentation. All 10 tools follow verb_noun naming patterns (fofa_* prefix). Tool annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) are properly declared for all tools. However, parameter descriptions are sparse or missing in several tools, and output schemas are not explicitly documented in the visible code. The server provides clear descriptions for most tools (average ~80 chars), meeting baseline expectations, but parameter-level documentation is inconsistent.
Return the current FOFA account tier, API capabilities and quota information.
Return the versioned FOFA field and membership capability catalogue without using quota.
Get FOFA Host aggregation for one IP or DNS name. Registered users have no Host API.
Fetch a public website favicon safely, calculate its FOFA MurmurHash3 value, and search matching assets.
Search bundled official app= names; call before product searches and use returned queries verbatim.
Run one read-only FOFA search page. If the user named a product/OA/VPN, call fofa_rules first and paste its query verbatim.
Output schemas not documented in tool definitions. Return types (SearchToolResult, GenericResult) are defined as Pydantic models but not described in tool docstrings. LLMs cannot plan subsequent operations without knowing what fields to expect.
Parameter descriptions vary in completeness. fofa_search has descriptions for all params, but fofa_fields and fofa_syntax accept no parameters (empty input schema). fofa_host_profile's 'detail' parameter lacks type and constraint information. Missing format guidance (e.g., 'IP address or DNS name format validation' for host parameter).
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 53 | - | v1 |
Continue a FOFA search using the opaque cursor returned by fofa_search.
Get FOFA stats. Personal/education accounts have no stats API. size is Top-N (default 5).
Return official FOFA query operators and syntax fields from the API appendix.
Perform local syntax checks without spending FOFA quota.
No pagination guidance in tool descriptions. fofa_search and fofa_search_next support cursor-based pagination but descriptions do not explain when to use next_cursor or warn about context window impact of large result sets.
No error handling guidance in tool descriptions. Tools do not document what errors can occur (quota exhaustion, invalid query syntax, auth failure) or provide recovery hints to LLMs.
Tool dependencies not documented. MCP_INSTRUCTIONS mention 'call fofa_rules first and use returned query verbatim', but individual tool descriptions do not include these dependency hints. LLMs must infer from instructions rather than per-tool guidance.