Vibe Coding Discover

MCP

blitzstrike

View on GitHub

⚡ Blitz Strike — a universal MCP penetration-testing toolbelt. Structured methodology: reconnaissance & attack-surface mapping, source-to-sink analysis, and live validation. 57 escalation chains, 130-tool catalog, intelligence data layer. One server, every agent.

★ 5294 forksTypeScriptMITshinthink

Blitz Strike is a TypeScript/Bun MCP server packaging a 3-tier pentest methodology: BLITZ recon, EAGLE-EYE source-to-sink taint analysis, and STRIKE live verification, with a 57-chain escalation graph and 130-tool catalog. Any MCP client can run full engagements via run_engagement.

Use Cases

Source-code security audit with file:line refsLive HTTP vulnerability verification with marker + negative controlAttack-surface and unauthenticated entry-point enumerationSource-to-sink taint and data-flow tracing (PHP/JS/TS/Python/Java)Automated pentest engagement orchestration via run_engagementCVE lookup and CWE/CVSS scoringWAF and technology fingerprinting with vuln correlationBug-bounty reconnaissance with FOFA asset searchNuclei template and exploit payload lookupScope enforcement and no-DoS guardrails before active testingFinding deduplication and reproducible report generationDetection rate / false-positive benchmarking on labelled corpora

Built With

Language
TypeScript
Frameworks
@modelcontextprotocol/sdk · Bun · Node.js · playwright-core · @babel/parser · php-parser · java-parser · @lezer/python

Tags

mcp · mcp-server · pentest · security · red-team · bug-bounty · vulnerability-scanning · reconnaissance · static-analysis · taint-analysis · attack-surface · exploit · cve · nuclei · payloads · waf-detection