{
  "markdown": "# cybersec-mcp\n\nMCP server with 323 cybersecurity prompts and 7 chained workflows. Install it and Claude (or any MCP-compatible client) can run an incident-response plan, a cloud audit, or a pentest by calling tools instead of you copy-pasting prompts.\n\n[Live demo](https://cybersec-mcp.vercel.app) · [MIT License](LICENSE) · [Model Context Protocol](https://modelcontextprotocol.io)\n\n## Install\n\n```bash\nnpx -y @xu-c0/cybersec-mcp\n```\n\nClaude Desktop config (`~/Library/Application Support/Claude/claude_desktop_config.json` on macOS, `%APPDATA%\\Claude\\claude_desktop_config.json` on Windows):\n\n```json\n{\n  \"mcpServers\": {\n    \"cybersec\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@xu-c0/cybersec-mcp\"]\n    }\n  }\n}\n```\n\nThen:\n\n> Use cybersec to plan an incident response for unusual outbound traffic from a SIEM-flagged host. SIEM is Splunk, EDR is CrowdStrike.\n\nThe agent picks the `incident-response` scenario, fills your variables in, and walks through detection, triage, containment, eradication, and post-mortem with concrete commands at each step.\n\n## Tools\n\n323 prompts across 8 categories. Every prompt takes typed variables and returns output in a defined shape (steps, tables, SIEM queries, MITRE tags).\n\n| Category | Prompts | Covers |\n|---|---|---|\n| Red Team | 45 | Pentest methodology, AD attack paths, C2 infra, social engineering |\n| Blue Team | 42 | Log analysis, IR playbooks, detection engineering, deception |\n| SOC Operations | 42 | Splunk/Sentinel/Elastic queries, alert triage, runbooks, shift handover |\n| Cloud Security | 38 | AWS/Azure/GCP audits, IAM, container security, CSPM |\n| OSINT | 38 | Domain intel, threat actor profiling, footprinting, attribution |\n| GRC | 38 | ISO 27001, SOC 2, NIST CSF, risk assessment, policy generation |\n| Vulnerability Analysis | 42 | CVE triage, CVSS 4.0, patch prioritization, pentest reports |\n| AI Agent Security | 38 | LLM red teaming, prompt injection, agent guardrails, supply chain |\n\nSource: `content/prompts-master.md` → generated `web-app/js/data.js`.\n\n## Scenarios\n\nSeven end-to-end workflows that chain prompts and pass variables between steps:\n\n1. **Web App Penetration Test** — recon → mapping → fingerprinting → API testing → exploitation → post-exploit → reporting\n2. **Incident Response** — detection → log investigation → severity → containment → eradication → comms → lessons learned\n3. **Cloud Security Audit** — IAM → network → storage → database → logging → compliance\n4. **Bug Bounty Recon** — subdomains → ports → tech → OSINT → surface → vuln assessment\n5. **Compliance Audit (ISO 27001)** — scoping → risk → controls → evidence → gaps → docs\n6. **Threat Hunting** — hypothesis → query design → pivot → validation → response\n7. **AI Security Assessment** — inventory → access control → red team → prompt injection → supply chain → monitoring\n\nDefinitions live in `web-app/js/scenarios.js`.\n\n## Web demo\n\n[**cybersec-mcp.vercel.app**](https://cybersec-mcp.vercel.app) — browse every prompt, fill in variables, copy the rendered text into any LLM. Dark mode, English / 한국어 / 日本語, no signup. Same data as the MCP server, different interface.\n\nUseful when you want to inspect what a tool will send before wiring up the server, or hand a teammate a one-off prompt.\n\n## ATT&CK mapping\n\nRed team, blue team, and SOC prompts are tagged to [MITRE ATT&CK](https://attack.mitre.org/) tactics. The full mapping is in [ATTACK_MATRIX.md](ATTACK_MATRIX.md) — useful for purple-team exercises and detection-coverage reviews.\n\n## Layout\n\n```\nmcp/         MCP server (TypeScript, in progress)\nweb-app/     Static demo deployed to Vercel\ncontent/     prompts-master.md — prompt source of truth\nexamples/    Client configs (Claude Desktop, Cursor, Claude Code)\n```\n\n`parse_prompts.py` regenerates `web-app/js/data.js` from `content/prompts-master.md`.\n\n## Contributing\n\nPRs welcome — new prompts, MITRE tags, scenario workflows, translations, MCP tool fixes. Schema and quality bar in [CONTRIBUTING.md](CONTRIBUTING.md).\n\nThis project is for authorized security testing, defensive operations, security research, and education. PRs promoting unauthorized access will be rejected. See [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md).\n\n## License\n\nMIT — see [LICENSE](LICENSE). MITRE ATT&CK® is a registered trademark of The MITRE Corporation; this project is not affiliated with MITRE.\n",
  "bytes": 4352,
  "sha": "05e7386ac2897b09bb444ff5c9c5992f8d0bf2f85d3393acd626c5bcfe2a7f69",
  "repo_slug": "xu-c0/cybersec-mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_xu_c0_cybersec_mcp_85dcde33/readme"
}