Shodan MCP Server

Shodan MCP Server is an MCP server that connects AI assistants to the Shodan search engine and CVE vulnerability databases. Developed by Cyreslab.ai, it enables security engineers, penetration testers, and threat intelligence analysts to investigate internet-facing assets and security exposures directly through natural language queries. The server interfaces with Shodan's REST API to gather detailed host profiles, open ports, running protocols, and SSL certificates across specific IP addresses or broader CIDR blocks. Beyond basic network reconnaissance, it queries DNS records, tracks historical domain entries, and identifies specific categories of connected IoT equipment. It also bridges vulnerability research tools, allowing users to query Common Vulnerabilities and Exposures, filter by Exploit Prediction Scoring System metrics, verify CISA Known Exploited Vulnerabilities status, and inspect Common Platform Enumeration specifications. By wrapping these capabilities in Model Context Protocol tools and resources, security analysts can automate incident triage, evaluate third-party network exposure, and assess external attack surfaces without leaving their conversational agent interface.

Category: Security & Compliance

Tags: cve, cybersecurity, network-scanning, shodan, vulnerability

Visit Shodan MCP Server

How to install and configure Shodan MCP Server

  1. Clone the repository: bash git clone https://github.com/Cyreslab-AI/shodan-mcp-server.git cd shodan-mcp-server 2. Install the necessary dependencies: bash npm install 3. Build the server: bash npm run build 4. Configure your MCP client settings (e.g., Claude Desktop) by adding the server configuration: json { "mcpServers": { "shodan": { "command": "node", "args": ["/path/to/shodan-mcp-server/build/index.js"], "env": { "SHODAN_API_KEY": "your-api-key-here" } } } } 5. Restart your client application to load the newly added tools.

What you can do with Shodan MCP Server

  • Querying specific IP addresses and network CIDR blocks to detect exposed ports, banners, and services during security assessments. - Searching Shodan for vulnerable internet-connected IoT devices such as webcams, industrial control systems, and routers across different geographic regions. - Triaging emerging threats by pulling CISA Known Exploited Vulnerabilities and ranking active CVEs using their EPSS exploit probability scores. - Inspecting SSL and TLS certificate properties and historical DNS configurations to map out external digital asset footprints for target domains.

Key facts

  • https://github.com/Cyreslab-AI/shodan-mcp-server
  • Security & Compliance, Web Search & Research
  • cve, cybersecurity, network-scanning, shodan, vulnerability

Part of MCP Servers

Related MCP servers

  • MCP NPX Fetch — MCP NPX Fetch is an MCP server that retrieves online resources and transforms web content into structured formats including HTML,…
  • MCP Naver News — MCP Naver News is an MCP server that connects AI assistants to the Naver News API, enabling automated search and…
  • MCP NIF.PT — MCP NIF.PT is an MCP server that connects LLM clients to the Portuguese NIF.PT public API to retrieve and analyze…
  • MCP Open Library — MCP Open Library is an MCP server that connects AI assistants to the Open Library catalogue API to retrieve book,…
  • MCP Omnisearch — MCP Omnisearch is an MCP server that consolidates multiple search engines, AI answer engines, and web scrapers into a unified…
  • MCP Personal Assistant Agent — MCP Personal Assistant Agent is an MCP server that connects AI clients to productivity services, external web information, and smart…

How do I install Shodan MCP Server?

You install it by cloning its repository from GitHub, running npm install to fetch dependencies, and compiling it with npm run build. Then add the server to your MCP client configuration file by pointing to the built index.js script and supplying your Shodan API key as an environment variable.

What can Shodan MCP Server do?

It provides tools to search Shodan for hosts, scan network CIDR ranges, identify IoT hardware, inspect SSL certificates, and run forward or reverse DNS lookups. Additionally, it queries the CVE database, sorts vulnerabilities by EPSS exploit prediction scores, and retrieves CISA Known Exploited Vulnerabilities.

Do I need a paid Shodan subscription to use this server?

A paid Shodan API membership is required for general search queries, CIDR range scanning, SSL certificate lookups, IoT device identification, and domain information queries. However, all CVE database functionality, such as looking up vulnerability details, searching CVEs, and checking EPSS scores, is completely free and works without a paid plan.

Is Shodan MCP Server open source?

Yes, Shodan MCP Server is open-source software released under the MIT license, developed by Cyreslab.ai and hosted on GitHub.

Which MCP clients work with Shodan MCP Server?

It works with any client compatible with the Model Context Protocol, including Claude Desktop and custom MCP agent frameworks capable of running a local Node.js process with environment variables.

  • AI Tools
  • Categories
  • Industries
  • CLI Coding Agents
  • MCP Servers
  • MCP Categories