MCP Autopentest Orchestrator

Semi-autonomous orchestrator for authorized MCP security assessment. Drives the deterministic probe_runner (read-only battery) plus optional parallel read-only sub-agents (discovery / authz-sweep / injection-probe), holds engagement state (tokens, discovered IDs), reasons over structured results, and produces the report. Safe-by-default: read-only, write/destructive tools are human-gated, scope-locked to one host. Use to run the kit with minimal manual curl.

rwcod Updated

File contents

rwcod/mcp-remote-oauth-pentest-kit/tree/main/skills/mcp-autopentest-orchestrator commit 069e8367ae

Frequently asked questions

npx skillmds@latest add rwcod/mcp-autopentest-orchestrator