Security-focused MCP server for authorized assessment workflows
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"ghostmcp-server","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
<p align="center"> <img src="docs/images/banner.png" alt="GhostMCP banner" /> </p> # GhostMCP [](https://github.com/BlueDot-IT/GhostMCP/releases/latest) [](https://github.com/BlueDot-IT/GhostMCP/actions/workflows/ci.yml) [](https://github.com/BlueDot-IT/GhostMCP/actions/workflows/codeql.yml) [](https://securityscorecards.dev/viewer/?uri=github.com/BlueDot-IT/GhostMCP) [](LICENSE) [](SECURITY.md) GhostMCP is a security-focused MCP server for authorized assessment workflows. It combines policy-guarded native tools, curated external scanners, normalized workflows, a local dashboard, scheduling, credential backends, and auditable execution. GhostMCP is currently a beta release. It defaults to a restricted posture and should be deployed only in environments where the operator controls the target scope, credentials, network path, and installed security tools. ## Safety and authorization Use GhostMCP only against systems you own or are explicitly authorized to assess. The runtime provides scope controls and execution ceilings, but those controls do not replace written authorization, rules of engagement, or operator review. Secure defaults include: - Private-address targeting by default - Engagement context required by default - Maximum tool level set to `active` - Raw binary wrappers disabled by default - External plugins disabled by default - Credential storage disabled until a backend is selected - Remote transport without authentication blocked by default - Dashboard authe…
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.