BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Tengu (Pentesting MCP)

Connector Security Usable
Works inClaude Code Claude Cowork Claude Chat
Usable Scanned — metadata only

Comprehensive AI-assisted pentesting with proper guardrails. Human-in-control for destructive actions and full audit logging show mature security thinking.

MCP server turning Claude into a penetration testing copilot. Orchestrates 80 security tools (Nmap to Metasploit) with 20 resources, 35 guided prompts, human-in-control for destructive actions, and audit logging.

56 starsMIT (commercial OK)FreeNo code needed
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Comprehensive AI-assisted pentesting with proper guardrails. Human-in-control for destructive actions and full audit logging show mature security thinking.

Professional penetration testers with proper authorization. NOT for general developers. Requires local installation of security tools (Nmap, Metasploit, etc.).

Claude Code Claude Cowork Claude Chat

https://github.com/rfunix/tengu

By rfunix

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
git clone https://github.com/rfunix/tengu.git && cd tengu && make docker-build && make docker-up, then: claude mcp add --transport sse tengu http://localhost:8000/sse

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

Once it’s connected, paste this into Claude:

Help me orchestrate dozens of security testing tools from one interface
PrerequisitesDocker (the images bundle Nmap, Metasploit, SQLMap, Nuclei, and other tools by tier); an ANTHROPIC_API_KEY for autonomous mode; and an allowed-hosts list of systems you are authorized to test.CostFree

Trust Signals Auto-scanned

Stars56Contributors2Last updated2026-06-22LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-07-21 · scanner v1

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.

Community Pulse Growing

Discussed on Hacker News

1 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 52 GitHub stars; 2 contributors; last commit 15d ago; license MIT.

Things to check

  • Offensive security tool — only for authorized security professionals on systems they have permission to test. Requires extensive local tool installation. Misuse risk is inherent to the category.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
3/5
Security
4/5
Overall score3.15 / 5.00 UsableEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 52 GitHub stars; 2 contributors; last commit 15d ago; license MIT.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →