Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

MCP server mode (subenum mcp): safe, budgeted subdomain enumeration for AI agents

Offen
#131 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Anfängerfreundlichkeit
35/100
Issue-Typ
Feature
Klarheit
Größtenteils klar
Aktivitätsstatus
Aktiv
Tech-Stack
go
Bereich
cli, security

Rechercherichtung

Read the related leak-fix issue and inspect pkg/subenum.Run before planning the MCP integration. The issue specifies stdio tools, operator-configured allow-listing, mandatory server-side caps, and documentation and registry listings, but does not name implementation or test files. Done means an MCP client can run lab_scan and an allow-listed scan, while non-allow-listed scans are refused and caps remain enforced.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

feature priority: low

Value / who it's for

AI security agents and assistants increasingly run recon through MCP tools. subenum is unusually well suited: it has hard budgets (-max-queries, -rate), scope control, an offline lab mode, and a run-quality verdict that tells an agent when not to trust its own result. Listing in MCP registries is a new distribution channel.

Suggested approach

  • subenum mcp (stdio) built on pkg/subenum.Run (after the leak fix in the related issue). Tools:
    • lab_scan (simulate-zone only; the default and always safe);
    • scan, requiring an operator-configured domain allow-list and mandatory caps;
    • explain_stats, which interprets a -stats file.
  • Refuse live scans unless the operator config allows the domain. Never let the model choose resolvers or lift caps.
  • Docs page plus registry listings.

Done when

An MCP client can run lab_scan and an allow-listed scan, a non-allow-listed domain is refused, and caps are enforced server-side.

Vorherrschende Sprache
Go
Sterne
1
Forks
1
Ø Merge
5 T. 2 Std.
Gemergte PRs (30 T.)
3

Entwicklungsumgebung

In Codespaces öffnen

Startet den Dev-Container des Projekts im Browser, mit Ihrem eigenen GitHub-Konto.

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus TMHSDigital/subenum

Alle Issues in TMHSDigital/subenum

Ähnliche Issues

Weitere Issues zu Go

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.