A secure MCP (Model Context Protocol) server that enables AI agents to interact with Nikto web server scanner for vulnerability assessment
Three tools with complete input schemas and descriptions. Naming follows verb_noun convention (scan, scan_status, stop_scan). Descriptions are present but brief (27-37 chars), below the 50-200 char ideal for LLM optimization. Schemas include type information and parameter descriptions. However, output schemas are not documented in the source code provided, and error handling guidance is absent. Risk annotations are present (WRITE/READ_ONLY) but not in formal MCP tool annotations format. The server demonstrates decent baseline structure but lacks production-grade polish in description depth and output documentation.
Run a Nikto scan against a target
Get the status of a running scan
Stop a running scan
Output schemas not documented. LLMs cannot plan downstream operations or extract specific fields without knowing what the tools return. Nikto scan results structure is entirely undocumented.
Tool descriptions are too brief (27-37 chars). Below 50-200 char LLM-optimization range. 'Get the status of a running scan' lacks context on what status fields are returned, how to interpret them, or when to call this vs scan.
No error handling guidance visible in tool descriptions. No mention of what happens on invalid targets, network failures, timeout, or partial scan results. Error recovery patterns missing.
scan tool accepts both 'ssl' and 'nossl' boolean parameters. These are mutually exclusive and may conflict. If both are true, behavior is undefined. Should use a single 'protocol' enum: [http, https].
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 6 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 52 | - | v1 |
outputFormat enum only lists 'json' and 'text'. No description of what format difference means, which is default, or when to choose each. LLMs will guess.
timeout parameter (seconds) has no bounds documented. Max value unclear, 3600s is default but is unbounded input allowed? Could LLM pass 1000000?
scanId parameter in scan_status and stop_scan lacks description of format. Is it a UUID? Integer? How do users obtain a scanId? No guidance on the relationship between scan tool execution and the returned scanId.