Labsco
MCP SERVER · OFFICIAL PROJECT

Operant Security Testing

by operantlabs

Run web, network, and forensic security tests — injection, SSRF, PCAP and memory analysis, access-control and business-logic checks — against your own targets.

Vulnerability Scanning & Application SecurityOfficial source
Summary
A wide set of web and network attack techniques runs from the assistant, against systems the operator is cleared to test.

The 62 tools send live attack traffic and read forensic artifacts. Some are read-only file analysis (the pcap and CloudTrail tools); others depend on external binaries on the PATH, and the offensive tools are for authorised testing only.

What it is

An offensive-security testing server: its 62 tools cover SQL and NoSQL injection, XSS, command injection, SSRF, path traversal, PCAP and memory forensics, CloudTrail analysis, access-control and business-logic checks, and wrappers around scanners like nuclei and ffuf.

What you get
  • Probe injection classes: SQLi, NoSQLi, command injection, path traversal, SSRF (sqli_blind_boolean, cmdi_test, ssrf_test)
  • Analyse captured evidence: PCAP protocol and credential extraction, memory forensics, CloudTrail (pcap_overview, volatility_windows, cloudtrail_find_anomalies)
  • Test access control and business logic: IDOR, role escalation, price and coupon abuse (idor_test, role_escalation_test, price_manipulation_test)
  • Run race-condition and request-smuggling attacks (race_single_packet, raw_h2_smuggle, race_last_byte_sync)
  • Wrap external scanners and fuzzers (nuclei_scan, ffuf_fuzz, param_discover)
Requirements

Targets you are authorised to test; some tools need external binaries such as vol.py, vol3, or interactsh-client on the PATH.

Setup effort

One command — npx -y operant-mcp