CyberStrikeAI
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
CyberStrikeAI is an AI-native cybersecurity platform that implements MCP server capabilities for authorized penetration testing and security operations. Built in Go with Eino-powered agents, it exposes over 100 security tools through MCP integration supporting HTTP, stdio, and SSE transports, enabling AI assistants to perform governed security assessments, vulnerability scanning, and attack-chain modeling. The platform combines RAG knowledge retrieval, visual workflows, human-in-the-loop approval, and comprehensive audit trails for traceable security operations. It includes web console management, role-based access control, and integrations with chat platforms for collaborative security testing on authorized systems.
Key Features
Use Cases
- 01AI-assisted penetration testing with natural language security task execution on authorized networks
- 02Automated vulnerability scanning and enumeration across web applications, APIs, and infrastructure
- 03Subdomain discovery and reconnaissance workflows combining multiple OSINT and network tools
- 04Post-exploitation operations with auditable WebShell management and command-and-control sessions
- 05Security knowledge management with RAG-powered vulnerability research and exploit documentation
- 06Collaborative security assessments through chatbot integration with Slack, Discord, WeChat, and Telegram
Related MCP Servers
View moremarkitdown
Python tool for converting files and office documents to Markdown.
firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥
prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
langflow
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
CyberStrikeAI — FAQ
What is CyberStrikeAI?+
CyberStrikeAI is an MCP-enabled security platform that connects AI agents to 100+ penetration testing and vulnerability scanning tools through standardized MCP protocols. It provides governed execution, audit trails, and attack-chain modeling for authorized security operations.
How do I install and run CyberStrikeAI?+
Clone the repository, ensure Go 1.25+ and Python 3.10+ are installed, then run './run.sh' which automatically configures the environment, builds the project, and starts the HTTPS server on port 8080. Configure AI channels in the web UI or config.yaml before first use.
Which AI clients can connect to CyberStrikeAI as an MCP server?+
CyberStrikeAI supports MCP clients that can connect via HTTP, stdio, or SSE protocols. The platform can also integrate externally via MCP federation and includes plugins for Burp Suite and browser extensions.
Do I need API keys to use CyberStrikeAI?+
Yes, you must configure at least one AI channel with provider credentials (OpenAI, DeepSeek, etc.) in the AI Channel Configuration section. Security tools like Shodan or FOFA may require separate API keys if using those specific scanners.
Is CyberStrikeAI free and open source?+
Yes, CyberStrikeAI is licensed under Apache License 2.0 and available on GitHub. However, it requires explicit authorization to test systems and should only be used on infrastructure you own or have written permission to assess.
What security tools need to be installed separately?+
The 100+ tool recipes require installing the underlying tools (nmap, sqlmap, nuclei, etc.) via package managers like Homebrew or apt. Python-based tools automatically use the managed virtual environment created by run.sh.
How do I install CyberStrikeAI?+
Open the source repository on GitHub and follow its README. CyberStrikeAI is a mcp server — MCP Agents Market links you directly to the official repo.
Is CyberStrikeAI free?+
CyberStrikeAI is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.