phantom-mcp

phantom-mcp

Exposes all PHANTOM security testing capabilities as MCP tools, enabling reconnaissance, vulnerability scanning, red teaming, and report generation through natural language interactions.

Category
Visit Server

README

phantom-mcp

MCP Server for PHANTOM — exposes all PHANTOM capabilities as MCP tools for Claude Desktop, Cursor, and any MCP client.


Tools available

Tool Description
phantom_scan Quick recon + vuln scan
phantom_quick_recon Passive subdomain discovery only
phantom_red Full red team pipeline (authorised use only)
phantom_orchestrate Natural language → autonomous execution
phantom_grey Bug bounty / OSCP-style (no blind exploits)
phantom_blue_analyze_log Analyse a log file for IOCs and attacks
phantom_hardening_checklist AI-powered hardening checklist
phantom_ir_playbook Incident response playbook from findings
phantom_siem_queries Splunk SPL / Elastic KQL from findings
phantom_identity_gen Generate a fake persona + disposable email
phantom_inbox Check disposable email inbox
phantom_wait_email_otp Wait for OTP in email
phantom_sms_otp Poll for SMS OTP
phantom_report Generate HackerOne / Bugcrowd / generic report
phantom_sessions_list List all sessions
phantom_findings Get session findings (with severity filter)
phantom_session_summary Full session summary
phantom_chat General-purpose AI chat (any topic)
phantom_analyze_findings Ask AI to analyze your findings

Install

# 1. Install PHANTOM first
git clone https://github.com/grsanudeep42-cmd/phantom
cd phantom && pip install -e .

# 2. Install phantom-mcp (bundled in phantom/phantom-mcp)
pip install mcp  # only extra dependency

Connect to Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or
%APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "phantom": {
      "command": "python",
      "args": ["-m", "phantom_mcp.server.main"],
      "cwd": "/absolute/path/to/phantom",
      "env": {
        "PYTHONPATH": "/absolute/path/to/phantom",
        "ANTHROPIC_API_KEY": "sk-ant-..."
      }
    }
  }
}

Then restart Claude Desktop. You'll see all PHANTOM tools available.


LLM Provider

Every tool accepts optional provider and model arguments:

phantom_chat(message="explain XSS", provider="ollama", model="llama3.1")
phantom_scan(target="example.com", provider="openai", model="gpt-4o")

Supported: anthropic, openai, ollama, openrouter, custom


Example usage in Claude Desktop

Use phantom_scan to scan example.com

Use phantom_grey to test example.com for bug bounty vulnerabilities

Use phantom_sessions_list to show my recent scans

Use phantom_findings with session_id="abc123" and severity="critical"

Use phantom_report with session_id="abc123" and format="hackerone"

Use phantom_chat to explain the CVE-2024-1234 vulnerability

License

MIT © Anudeep | Part of the PHANTOM project

Recommended Servers

playwright-mcp

playwright-mcp

A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.

Official
Featured
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.

Official
Featured
Local
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.

Official
Featured
Local
TypeScript
VeyraX MCP

VeyraX MCP

Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.

Official
Featured
Local
graphlit-mcp-server

graphlit-mcp-server

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.

Official
Featured
TypeScript
Kagi MCP Server

Kagi MCP Server

An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.

Official
Featured
Python
E2B

E2B

Using MCP to run code via e2b.

Official
Featured
Neon Database

Neon Database

MCP server for interacting with Neon Management API and databases

Official
Featured
Exa Search

Exa Search

A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.

Official
Featured
Qdrant Server

Qdrant Server

This repository is an example of how to create a MCP server for Qdrant, a vector search engine.

Official
Featured