Pentesting MCP
A pentesting MCP server for your coding agent
HyperSec's MCP server puts confirmed pentest findings where your coding agent works. Ask for your applications, scan status, vulnerabilities, evidence and recommendations from Claude Code, Cursor, Codex or another MCP-compatible client, then fix and retest.
What a pentesting MCP server does
The Model Context Protocol (MCP) lets a coding agent call tools on an external server. HyperSec exposes your security results that way, so the agent that writes your code can read what an attacker-style test found in it, without you copying findings between dashboards.
Connect your client
Add the server
Point an MCP-compatible client at https://mcp.hypersec.ai/mcp.
Authenticate
Sign in with browser OAuth in your editor, or use an API key for CI.
Ask in plain language
Ask for your applications, scan status, confirmed vulnerabilities, the evidence behind one, and recommendations for what to fix first.
What the agent can read
Every confirmed finding carries its risk, confidence, CWE, affected request, reproduction steps, machine-captured evidence, remediation guidance and retest status. Your agent gets that same detail, so a fix can start from the reproduction steps instead of a vague warning.
Read-only by design
The v1 connection is read-only. Your coding agent can read results but cannot change your applications or scans through it, and applying a fix stays with you or your agent.
From finding to fix to retest
Ask your client for the confirmed findings and what to fix first, apply the change, then use each finding's retest status to check that it is closed. Findings come from testing the live application, so it does not matter whether a person or an agent wrote the code.
Start free
Run a surface scan on your deployed app first. It takes under 60 seconds, and paid plans start at $15 per month when you want the full AI hacker scan.
Frequently asked questions
What is a pentesting MCP server?
It is an MCP server that gives an AI coding agent access to penetration-testing results. HyperSec's lets clients such as Claude Code, Cursor and Codex read your applications, scans, confirmed vulnerabilities, evidence and recommendations.
Which clients can connect?
Any MCP-compatible client, including Claude Code, Cursor and Codex.
How do I authenticate?
Sign in with browser OAuth from your editor, or use an API key in CI. See the pricing page for which plans include API access.
Can the MCP server change my code or applications?
No. The v1 connection is read-only. Applying fixes stays with you or your coding agent.
Where do the findings come from?
From HyperSec's attack agents testing your live application, with each finding confirmed by a Judge agent before it is saved. The MCP server exposes those confirmed results.
How much does it cost?
A surface scan and a basic A–F security grade are free, with a monthly allowance of AI credits. Paid plans start at $15 per month for the full AI hacker scan, a findings list and PDF export. The $100 per month plan adds more AI credits, scheduled scans and API access, and a custom plan adds white-label reports. See the pricing page for current limits.