Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

MCP server mode (subenum mcp): safe, budgeted subdomain enumeration for AI agents

Aperta
#131 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
35/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
go
Ambito
cli, security

Direzione di ricerca

Read the related leak-fix issue and inspect pkg/subenum.Run before planning the MCP integration. The issue specifies stdio tools, operator-configured allow-listing, mandatory server-side caps, and documentation and registry listings, but does not name implementation or test files. Done means an MCP client can run lab_scan and an allow-listed scan, while non-allow-listed scans are refused and caps remain enforced.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

feature priority: low

Value / who it's for

AI security agents and assistants increasingly run recon through MCP tools. subenum is unusually well suited: it has hard budgets (-max-queries, -rate), scope control, an offline lab mode, and a run-quality verdict that tells an agent when not to trust its own result. Listing in MCP registries is a new distribution channel.

Suggested approach

  • subenum mcp (stdio) built on pkg/subenum.Run (after the leak fix in the related issue). Tools:
    • lab_scan (simulate-zone only; the default and always safe);
    • scan, requiring an operator-configured domain allow-list and mandatory caps;
    • explain_stats, which interprets a -stats file.
  • Refuse live scans unless the operator config allows the domain. Never let the model choose resolvers or lift caps.
  • Docs page plus registry listings.

Done when

An MCP client can run lab_scan and an allow-listed scan, a non-allow-listed domain is refused, and caps are enforced server-side.

Lingua principale
Go
Stelle
1
Fork
1
Merge medio
5g 2h
PR unite (30g)
3

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di TMHSDigital/subenum

Tutte le issue di TMHSDigital/subenum

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.