wondersuite

data-ai MCP Server

AI-Powered Offensive Security Research Engine - desktop-native security testing platform with native MCP integration. 90 tools, MITM proxy, stealth browser, autonomous AI agent. Built on Tauri + Rust + React.

Verified
data-aidata-ai
3 views35 stars4 forksv0.3.35MIT

Why This Matters

Discovered via github-topic:model-context-protocol and last synced 3mo ago.

Verified
Source
github-topic:model-context-protocol
Stars
35
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
25
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (25)

OSINT

`whois_lookup` · `asn_lookup` · `crtsh_search` · `wayback_lookup` · `hackertarget_lookup` · `ip_geolocation` · `tech_detect` · `favicon_hash` · `reverse_ip_lookup` · `graphql_introspect`

Category

Tools

Codec

`encode` · `decode` · `hash` · `smart_decode` · **`analyze_jwt`** (alg=none, kid SQLi/traversal, jku/x5u SSRF, HS/RS confusion)

Frontend

React 19, TypeScript, Vite, Zustand

Intruder

`fuzz_request` — Sniper · Battering Ram · Pitchfork · Cluster Bomb

Browser

Bundled Chrome-for-Testing 148.0.7778.97 (SHA-256-verified lazy download) + WonderSuite extension (MV3)

Component

Technology

Recon

`crawl_target` · `discover_content` · `discover_subdomains` (concurrent DNS) · `find_secrets` · `dns_resolve` (with CDN detection) · `js_link_finder`

HTTP

`send_request` · `send_to_repeater` · `send_to_intruder` (auto-categorises payloads per param name) · `h2_send_request` · `mtls_send_request`

Scanner

`active_scan` (SQLi · XSS · SSTI · LFI · Open Redirect · CRLF) with optional `with_oast:true` for **blind cmdi, blind SSRF, Log4Shell** via the bundled OAST listener · `passive_scan` (headers, cookies, CORS, info disclosure)

Session

`session_manage` · `session_from_browser` · `payload_manager`

MCP

Axum HTTP server (JSON-RPC 2.0), dedicated thread/runtime

Exploit

`race_request` · `raw_tcp_send` · `websocket_connect` · `analyze_cdn_waf` (with CDN bypass strategies)

Reporting

`generate_report` (markdown / JSON / summary) · `bambda_filter` · `payload_manager` · `get_traffic_log`

Backend

Rust 1.78+

Framework

Tauri 2.x

persists

Store["zustand portscanStore<br/><sub>survives module-unmount + pop-out</sub>"] classDef ui fill:#1f2937,stroke:#94a3b8,stroke-width:1.5px,color:#e2e8f0 classDef orch fill:#3b0764,stroke:#a855f7,stroke-width:2px,color:#f3e8ff classDef engine fill:#064e3b,stroke:#10b981,stroke-width:2px,color:#d1fae5 classDef store fill:#1e3a8a,stroke:#60a5fa,stroke-width:2px,color:#dbeafe classDef probe fill:#7c2d12,stroke:#fb923c,stroke-width:2px,color:#fed7aa class UI,Live ui class Orch orch class Connect,Syn,Udp,Probe engine class RTT,Calc,Sem orch class ProbeDb probe class Result,Emit,Store store ``` #### Privilege model

response

ProbeDb["<b>nmap-service-probes</b><br/><sub>include_str!() at build time<br/>187 probes · 11 971 matches<br/>compiled regex via Lazy&lt;ProbeDb&gt;</sub>"] ProbeDb -->

Connect

SYN

Linux

no admin

macOS

no admin

OAST

Embedded axum HTTP listener + tokio UDP DNS server + raw-TCP SMTP listener, shared `INTERACTIONS` log

Windows

no admin

Platform

Installer

Proxy

tokio, native-tls, rsa/x509-cert (dynamic CA)