npm · @cyanheads/attack-surface-mcp-server
$npx -y @cyanheads/attack-surface-mcp-server@0.2.3 SHODAN_API_KEY · secret — Optional Shodan API key. Enables attacksurface_lookup_host; absent → that one tool returns source_unavailable and the rest of the server works.
CERTSPOTTER_API_KEY · secret — Optional Certspotter API key. Raises CT-fallback rate limits; absent → free unauthenticated tier.
ATTACKSURFACE_DEFAULT_RESOLVERS — Comma-separated default DNS resolver IPs for attacksurface_resolve_dns.
ATTACKSURFACE_HTTP_USER_AGENT — Default User-Agent for attacksurface_probe_http (overridable per call).
ATTACKSURFACE_MAX_SUBDOMAINS — Cap on subdomains resolved during a map_domain run.
ATTACKSURFACE_RDAP_BOOTSTRAP_URL — RDAP bootstrap base URL; override for a private/mirrored RDAP.
ATTACKSURFACE_ALLOW_PRIVATE_TARGETS — Set true to disable the SSRF guard for internal-network assessment (local/trusted deployments only).
MCP_LOG_LEVEL — Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').
npm · @cyanheads/attack-surface-mcp-server
$npx -y @cyanheads/attack-surface-mcp-server@0.2.3 MCP_HTTP_HOST — The hostname for the HTTP server.
MCP_HTTP_PORT — The port to run the HTTP server on.
MCP_HTTP_ENDPOINT_PATH — The endpoint path for the MCP server.
MCP_AUTH_MODE — Authentication mode to use: 'none', 'jwt', or 'oauth'.
MCP_LOG_LEVEL — Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').