A scope-aware bug-bounty & reconnaissance MCP server that works out of the box on the Python standard library and augments itself with your favourite CLI tools when they're present.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.MOONMCP_LOG_LEVELMOONMCP_AUDIT_LOG— audit_log Read the session audit trail — one record per scope decision (allow / deny / SSRF-block) and external command (also on audit://recent, persisted via ).MOONMCP_SHODAN_API_KEY— (none) Enables the full Shodan API (else free InternetDB).SHODAN_API_KEYMOONMCP_NVD_API_KEY— (none) Raises the NVD CVE-lookup rate limit.NVD_API_KEYMOONMCP_SCREENSHOT_DIR— (temp dir) Where the screenshot tool writes PNGs.MOONMCP_STATE_DIR— surface_diff / surface_snapshots Track how the attack surface changes over time — baseline a set (subdomains/endpoints/…) and surface only what's new since last run (persists via ).MOONMCP_OAST_DOMAINMOONMCP_OAST_POLL_URLMOONMCP_VAULT_DIRMOONMCP_CHROMIUM_PATHPLAYWRIGHT_BROWSERS_PATH[](https://m8ven.ai/mcp/moonwuk-moonmcp-upk0pd)