MCP server for cybersecurity API testing and vulnerability assessment
CyberMCP has 14 tools with reasonable naming (verb_noun pattern) and descriptions present, but critical gaps undermine quality. Most tools lack documented output schemas, LLMs cannot plan downstream calls or extract results. Parameter descriptions are present but often generic ('API endpoint to test'). No error handling guidance; tools return raw HTTP responses without recovery hints. Security tools lack idempotency documentation despite being read-only. Authentication tools expose credentials in parameters (basic_auth, token_auth, oauth2_auth accept secrets directly), violating secret-injection pattern. Tool composition is weak: auth setup, status check, and clear are separate when they should be unified. No pagination support despite tools that could return large result sets. STDIO transport caps protocol readiness at 50.
Authenticate with a custom API login endpoint
Test for authentication bypass vulnerabilities
Check current authentication status and configuration
Set up HTTP Basic Authentication
Clear all authentication state
Analyze JWT token for security vulnerabilities including algorithm confusion, weak secrets, and claim manipulation
Authenticate using OAuth2 with support for multiple grant types (client_credentials, password, authorization_code, refresh_token)
Credentials exposed as tool parameters. basic_auth, token_auth, oauth2_auth, and api_login accept passwords, tokens, and secrets directly as parameters. These leak into logs, traces, and LLM context.
No output schemas documented. Tools return results but LLMs cannot see what fields to expect. Prevents downstream tool chaining and forces LLMs to parse unstructured responses.
No error handling guidance. Tools fail silently or return raw HTTP errors without recovery hints. LLMs cannot determine if errors are retryable or what to do next.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
Test for directory traversal vulnerabilities using common path traversal payloads
Test for rate limiting implementation and bypass vulnerabilities
Check for missing or misconfigured security headers
Check for sensitive data exposure in API responses including PII, credentials, tokens, and internal information
Test for SQL injection vulnerabilities using common payloads
Set up token-based authentication with optional refresh token and expiration
Test for Cross-Site Scripting (XSS) vulnerabilities
Generic parameter descriptions. 'API endpoint to test' appears in 8 tools but does not explain format, expected response structure, or when to use each tool vs. others. LLMs cannot disambiguate.
No idempotency or dry-run support. Security testing tools (sql_injection_check, xss_check, path_traversal_check) may trigger alerts or cause side effects. No confirmation or dry-run mode documented.