gophish-mcp

gophish-mcp

An MCP server that provides a complete interface to the GoPhish API for managing phishing campaigns, groups, templates, landing pages, SMTP profiles, and users through natural language commands.

Category
Visit Server

README

๐ŸŽฃ GoPhish MCP Server

Python MCP GoPhish License

A complete MCP (Model Context Protocol) server for interacting with all GoPhish API functionalities.

Features โ€ข Installation โ€ข Configuration โ€ข Usage โ€ข Tools


๐Ÿ“ Note: This MCP has been tested and works with GoPhish version 0.11.0. If I receive enough love ๐Ÿ˜Š, I might update it with new capabilities!


โœจ Key Features

  • ๐ŸŽฏ Complete Campaign Management: Full CRUD + advanced analysis and statistics
  • ๐Ÿ‘ฅ Group Management: Manage target user groups with search capabilities
  • ๐Ÿ“ง Email Templates: Create, edit and manage email templates
  • ๐ŸŒ Landing Pages: Manage landing pages for campaigns
  • ๐Ÿ“ฎ SMTP Profiles: Configure email sending profiles
  • ๐Ÿ‘ค User Management: Manage system users and administrators
  • ๐Ÿ“Š Analysis and Reports: Detailed statistics, data export and global analysis
  • ๐Ÿ” Utility Tools: Search, validation, duplication and diagnostics

๐Ÿš€ Quick Start

Installation

  1. Clone this repository
git clone <repository-url>
cd gophish-mcp
  1. Install dependencies:
pip install -e .

Configuration

Option 1: .env file (Recommended)

  1. Copy the example file:
cp env.example .env
  1. Edit .env with your credentials:
GOPHISH_URL=https://your-gophish-server:3333
GOPHISH_API_KEY=your-api-key-here

Option 2: Environment variables

export GOPHISH_URL="https://your-gophish-server:3333"
export GOPHISH_API_KEY="your-api-key"

๐Ÿ’ป Usage with Claude, Cursor, VSCode, Kiro

Step 1: Configure Credentials (One time only)

Create a .env file in the project directory:

cp env.example .env
# Edit .env with your real credentials

Step 2: Configure MCP Client

Add the server to your MCP configuration (without credentials):

{
  "mcpServers": {
    "gophish": {
      "command": "python",
      "args": ["/path/to/your/gophish-mcp/server.py"],
      "cwd": "/path/to/your/gophish-mcp",
      "disabled": false,
      "autoApprove": [
        "gophish_get_campaigns",
        "gophish_get_campaign",
        "gophish_get_active_campaigns",
        "gophish_get_completed_campaigns",
        "gophish_get_recent_campaigns",
        "gophish_get_latest_campaign",
        "gophish_get_campaigns_summary",
        "gophish_get_campaign_results",
        "gophish_get_campaign_summary",
        "gophish_get_campaign_analytics",
        "gophish_get_global_analytics",
        "gophish_get_system_status",
        "gophish_search_campaigns",
        "gophish_search_groups",
        "gophish_search_templates",
        "gophish_get_groups",
        "gophish_get_templates",
        "gophish_get_pages",
        "gophish_get_smtp_profiles",
        "gophish_get_users",
        "gophish_get_campaign_by_status",
        "gophish_get_campaign_by_date_range",
        "gophish_get_campaign_targets",
        "gophish_get_campaign_events"
      ]
    }
  }
}

Step 3: Restart MCP Client

Restart your MCP client (Claude, Cursor, etc.)

๐Ÿ”’ Security Note: Credentials are only configured in the server's .env file, not in the client JSON.

All tools listed in autoApprove are read-only according to the API implementation in server.py. Any create, update or delete operation (gophish_create_*, gophish_update_*, gophish_delete_*) will always require manual approval.

๐Ÿ› ๏ธ Tool Categories

Category Description
๐Ÿ“– READ-ONLY These tools only read data and are automatically approved by the MCP client
โœ๏ธ WRITE These tools modify data and require manual approval for security

๐Ÿ“‹ Available Tools

๐ŸŽฏ Campaigns (Complete Management)

Basic Operations

Tool Description Type
gophish_get_campaigns Get all campaigns ๐Ÿ“– READ-ONLY
gophish_get_campaign Get details of a specific campaign ๐Ÿ“– READ-ONLY
gophish_create_campaign Create new campaign โœ๏ธ WRITE
gophish_update_campaign Update existing campaign โœ๏ธ WRITE
gophish_delete_campaign Delete campaign โœ๏ธ WRITE

Analysis and Statistics

Tool Description Type
gophish_get_latest_campaign Get latest campaign with complete statistics ๐Ÿ“– READ-ONLY
gophish_get_campaigns_summary Get summary of last N campaigns ๐Ÿ“– READ-ONLY
gophish_get_campaign_results Get detailed results of a campaign ๐Ÿ“– READ-ONLY
gophish_get_campaign_summary Get summary with statistics of a campaign ๐Ÿ“– READ-ONLY
gophish_get_campaign_analytics Get complete analysis of a campaign ๐Ÿ“– READ-ONLY

Filters and Search

Tool Description Type
gophish_get_active_campaigns Get active campaigns ๐Ÿ“– READ-ONLY
gophish_get_completed_campaigns Get completed campaigns ๐Ÿ“– READ-ONLY
gophish_get_campaign_by_status Filter campaigns by status ๐Ÿ“– READ-ONLY
gophish_get_recent_campaigns Get campaigns from last N days ๐Ÿ“– READ-ONLY
gophish_get_campaign_by_date_range Get campaigns in date range ๐Ÿ“– READ-ONLY
gophish_search_campaigns Search campaigns by name ๐Ÿ“– READ-ONLY

Utilities

Tool Description Type
gophish_get_campaign_targets Get all targets of a campaign ๐Ÿ“– READ-ONLY
gophish_get_campaign_events Get events of a campaign ๐Ÿ“– READ-ONLY

๐Ÿ‘ฅ Groups (Complete Management)

Tool Description Type
gophish_get_groups Get all groups ๐Ÿ“– READ-ONLY
gophish_create_group Create new group โœ๏ธ WRITE
gophish_update_group Update existing group โœ๏ธ WRITE
gophish_delete_group Delete group โœ๏ธ WRITE
gophish_search_groups Search groups by name ๐Ÿ“– READ-ONLY

๐Ÿ“ง Email Templates (Complete Management)

Tool Description Type
gophish_get_templates Get all templates ๐Ÿ“– READ-ONLY
gophish_create_template Create new template โœ๏ธ WRITE
gophish_update_template Update existing template โœ๏ธ WRITE
gophish_delete_template Delete template โœ๏ธ WRITE
gophish_search_templates Search templates by name or subject ๐Ÿ“– READ-ONLY

๐ŸŒ Landing Pages (Complete Management)

Tool Description Type
gophish_get_pages Get all pages ๐Ÿ“– READ-ONLY
gophish_create_page Create new page โœ๏ธ WRITE
gophish_update_page Update existing page โœ๏ธ WRITE
gophish_delete_page Delete page โœ๏ธ WRITE

๐Ÿ“ฎ SMTP Profiles (Complete Management)

Tool Description Type
gophish_get_smtp_profiles Get all SMTP profiles ๐Ÿ“– READ-ONLY
gophish_create_smtp_profile Create new SMTP profile โœ๏ธ WRITE
gophish_update_smtp_profile Update existing SMTP profile โœ๏ธ WRITE
gophish_delete_smtp_profile Delete SMTP profile โœ๏ธ WRITE

๐Ÿ‘ค User Management

Tool Description Type
gophish_get_users Get all users/administrators ๐Ÿ“– READ-ONLY
gophish_create_user Create new user โœ๏ธ WRITE
gophish_update_user Update existing user โœ๏ธ WRITE

๐Ÿ“Š Global Analysis and Reports

Tool Description Type
gophish_get_system_status Get system status and general statistics ๐Ÿ“– READ-ONLY
gophish_get_global_analytics Get global analysis of all campaigns ๐Ÿ“– READ-ONLY

๐Ÿ’ก Usage Examples

Once configured, you can use commands like:

Basic Management

Show me all GoPhish campaigns
Create a new campaign called "Test Campaign" using template with ID 1
Update campaign with ID 5 to change its name to "Updated Campaign"

Analysis and Reports

Show me the complete analysis of campaign with ID 3
Get global statistics of all campaigns
Show me events from campaign 2

Search and Filters

Search campaigns containing "phishing" in the name
Show me all active campaigns
Get campaigns created in the last 7 days

User Management

List all system users
Create a new administrator user

Advanced Search

Search templates containing "urgent" in the subject
Find groups containing "marketing" in the name

๐Ÿ”’ Security

  • โš ๏ธ Server disables SSL verification by default for local development
  • โœ… Make sure to use HTTPS in production
  • ๐Ÿ”‘ Keep your API key secure and don't share it
  • ๐Ÿ›ก๏ธ All write operations require valid authentication

๐Ÿงช Testing

Run Tests

# Run all tests
python test.py all

# Run read-only tests
python test.py readonly

# Run verbose demo
python test.py demo

# Run comprehensive tests
python test.py comprehensive

Testing Requirements

  • โœ… GoPhish server running
  • โœ… Valid credentials in .env
  • โœ… Dependencies installed: pip install -e .

See tests/README.md for more details about testing.

๐Ÿ› ๏ธ Utilities

Utility Scripts

# List campaigns
python utils/list_campaigns.py

๐Ÿ—๏ธ Development

For local development:

# Install in development mode
pip install -e .

# Run server directly
python server.py

# Run tests
python test.py all

๐Ÿ“š Additional Resources


Made with โค๏ธ for the GoPhish community

โญ Star this repo if you find it useful!

License

This project is licensed under the MIT License. See the LICENSE file for details.

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured