Shodan MCP Server is an MCP server that connects AI assistants to the Shodan search engine and CVE vulnerability databases. Developed by Cyreslab.ai, it enables security engineers, penetration testers, and threat intelligence analysts to investigate internet-facing assets and security exposures directly through natural language queries. The server interfaces with Shodan's REST API to gather detailed host profiles, open ports, running protocols, and SSL certificates across specific IP addresses or broader CIDR blocks. Beyond basic network reconnaissance, it queries DNS records, tracks historical domain entries, and identifies specific categories of connected IoT equipment. It also bridges vulnerability research tools, allowing users to query Common Vulnerabilities and Exposures, filter by Exploit Prediction Scoring System metrics, verify CISA Known Exploited Vulnerabilities status, and inspect Common Platform Enumeration specifications. By wrapping these capabilities in Model Context Protocol tools and resources, security analysts can automate incident triage, evaluate third-party network exposure, and assess external attack surfaces without leaving their conversational agent interface.
Category: Security & Compliance
Tags: cve, cybersecurity, network-scanning, shodan, vulnerability
bash git clone https://github.com/Cyreslab-AI/shodan-mcp-server.git cd shodan-mcp-server 2. Install the necessary dependencies: bash npm install 3. Build the server: bash npm run build 4. Configure your MCP client settings (e.g., Claude Desktop) by adding the server configuration: json { "mcpServers": { "shodan": { "command": "node", "args": ["/path/to/shodan-mcp-server/build/index.js"], "env": { "SHODAN_API_KEY": "your-api-key-here" } } } } 5. Restart your client application to load the newly added tools.Part of MCP Servers
You install it by cloning its repository from GitHub, running npm install to fetch dependencies, and compiling it with npm run build. Then add the server to your MCP client configuration file by pointing to the built index.js script and supplying your Shodan API key as an environment variable.
It provides tools to search Shodan for hosts, scan network CIDR ranges, identify IoT hardware, inspect SSL certificates, and run forward or reverse DNS lookups. Additionally, it queries the CVE database, sorts vulnerabilities by EPSS exploit prediction scores, and retrieves CISA Known Exploited Vulnerabilities.
A paid Shodan API membership is required for general search queries, CIDR range scanning, SSL certificate lookups, IoT device identification, and domain information queries. However, all CVE database functionality, such as looking up vulnerability details, searching CVEs, and checking EPSS scores, is completely free and works without a paid plan.
Yes, Shodan MCP Server is open-source software released under the MIT license, developed by Cyreslab.ai and hosted on GitHub.
It works with any client compatible with the Model Context Protocol, including Claude Desktop and custom MCP agent frameworks capable of running a local Node.js process with environment variables.