Tengu

Orchestrates 80 penetration testing tools from Nmap to Metasploit with built-in safety controls, audit logging, PTES methodology,

rfunix 56
Claude CodeClaude DesktopGeneric
View source ↗

Comprehensive pentesting MCP server that orchestrates 80 security tools across reconnaissance, web scanning, injection testing, exploitation, Active Directory attacks, cloud security, and stealth operations. Features a safety pipeline with input sanitization, target allowlists, rate limiting, and audit logging. Includes 35 pre-built workflow prompts, 20 reference resources (OWASP Top 10, MITRE ATT&CK, PTES methodology), and tiered Docker images (minimal/core/full). Supports both interactive copilot mode via MCP and a fully autonomous agent mode using LangGraph that follows the 7-phase PTES methodology with human-in-the-loop gates for destructive actions.

Source

Repository: https://github.com/rfunix/tengu

Maintain Tengu?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

[Tengu on getagentictools](https://getagentictools.com/mcp/rfunix-tengu?ref=badge)