appsecco/pentesting-mcp-servers-checklist
A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.
Platform-specific configuration:
{
"mcpServers": {
"pentesting-mcp-servers-checklist": {
"command": "npx",
"args": [
"-y",
"pentesting-mcp-servers-checklist"
]
}
}
}Add the config above to .claude/settings.json under the mcpServers key.
Loading reviews...