dalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Dalfox is an MCP server that provides XSS (cross-site scripting) vulnerability scanning capabilities to AI agents and assistants. Built in Rust, it automates the detection and analysis of reflected, stored, and DOM-based XSS flaws through parameter analysis, payload injection, and WAF fingerprinting. The server exposes Dalfox's security testing engine via the Model Context Protocol, enabling AI agents to perform web security assessments. Developers can integrate it into their AI workflows to automatically scan URLs, analyze parameters, and verify vulnerabilities through multiple output formats including JSON, SARIF, and Markdown.
Key Features
Use Cases
- 01Enable AI coding assistants to automatically scan web applications for XSS vulnerabilities during development
- 02Integrate security testing into AI agent workflows for continuous security assessment
- 03Automate parameter analysis and vulnerability detection across multiple URLs via pipeline mode
- 04Provide AI agents with WAF detection and bypass analysis capabilities for penetration testing
- 05Generate structured vulnerability reports in SARIF format for AI-driven security dashboards
- 06Allow AI assistants to verify and validate XSS findings through DOM and AST analysis
Related MCP Servers
View moremarkitdown
Python tool for converting files and office documents to Markdown.
firecrawl
The context API to search, scrape, and interact with the web at scale. 🔥
prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
langflow
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
dalfox — FAQ
What is the Dalfox MCP server?+
Dalfox is an MCP server that brings XSS vulnerability scanning capabilities to AI agents and assistants. It exposes Dalfox's automated security testing engine through the Model Context Protocol, allowing AI tools to detect cross-site scripting flaws, analyze parameters, and fingerprint web application firewalls.
How do I install the Dalfox MCP server?+
You can install Dalfox via Homebrew (brew install dalfox), Snapcraft (sudo snap install dalfox), AUR for Arch Linux (yay -S dalfox), or Nix/NixOS (nix-shell -p dalfox). Prebuilt binaries are also available on the GitHub Releases page for manual installation.
Which AI clients work with Dalfox?+
Dalfox supports the Model Context Protocol stdio server mode, making it compatible with MCP-enabled AI clients like Claude Desktop and other tools that implement the MCP standard. It can be configured in any MCP client's server configuration.
Do I need API keys to use Dalfox?+
No API keys are required for basic Dalfox functionality. However, if you want to use callback-based testing for blind XSS detection, you'll need to provide your own callback server URL using the -b flag.
Is Dalfox free to use?+
Yes, Dalfox is a free and open-source tool released under an open-source license. The complete codebase is available on GitHub, and all features are available at no cost.
What happened to the Go version of Dalfox?+
Dalfox v3 is a complete rewrite in Rust, while the previous Go-based v2.x codebase is preserved on the v2 branch and continues to receive security backports. A migration guide is available in the documentation for users upgrading from v2 to v3.
How do I install dalfox?+
Open the source repository on GitHub and follow its README. dalfox is a mcp server — MCP Agents Market links you directly to the official repo.
Is dalfox free?+
dalfox is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.