Vulnix MCP

Pentest your apps from the AI tools you already use

Start pentests, triage exploit-proven findings and check fixes in plain language, from Claude, ChatGPT, Cursor or any MCP client. Sign in once; nothing to install.

https://api.vulnix.dev/mcp
  • Claude
  • ChatGPT
  • Cursor

Engineers move faster while you keep control

Every AI app signs in as a real member of your workspace, gets only the permissions you allow, and can be cut off in one click.

Start a free trial
  • Decide what AI apps may do

    Turn AI apps on or off for the whole workspace, and set a ceiling on the permissions anyone can grant. Existing connections narrow at their next request.

  • Never more than the person behind it

    Each connection is an OAuth sign-in by one member. It can't exceed their role, follows it when it changes, and shows up in the console where you can revoke it.

  • Spend stays predictable

    Starting pentests and re-testing fixes are never granted by default, apps ask before running them, and every connection has its own rate limit.

  • Claude
  • ChatGPT
  • Cursor

Start a pentest

Kick off a pentest and follow it live

Ask for a pentest on any verified scope. The AI app confirms the credit cost, starts the run and reports back as it moves through recon, exploitation and reporting.

Triage findings

Work through findings in plain language

Ask which critical findings are still open on a domain, read the proof and reproduction steps for each, and update their status without opening the console.

Check a fix

Know a fix holds before you close the ticket

Have the agent replay the original exploit against your patch, then open a fix pull request on the connected repository when one is still needed.

Get started

Connect Vulnix in your AI app, then try one of these. Each opens a new chat with the prompt filled in; nothing runs until you send it.

Vulnix, which critical and high findings are still open, and what's the fastest one to fix?

Questions

What is the Vulnix MCP server?
A hosted Model Context Protocol server at https://api.vulnix.dev/mcp. Add it to an AI app as a custom connector and the app can start pentests, read findings, check fixes and manage domains, scopes and knowledge in your Vulnix workspace.
Which AI apps does it work with?
Any app that supports remote MCP servers with OAuth sign-in, including Claude, ChatGPT and Cursor. Tools that can't open a browser sign-in can use a scoped Vulnix API token instead.
Do I need to install anything or copy a token?
No. You paste the server URL, sign in with your Vulnix account, pick the workspace and choose what the app may do. The app gets its own connection, which you can see and disconnect in the console.
Can an AI app do more than I can?
No. A connection never exceeds the role of the person who connected it, and follows that role if it changes. Workspace owners and admins can also turn AI apps off or cap the permissions anyone can grant.
Does using it cost credits?
Reading pentests, findings and reports is free. Starting a pentest, re-testing a fix and opening a fix PR cost the same credits as in the console. Those permissions are never ticked for you, and your AI app asks before running them.
What can't it do?
Chat with the testing agent and webhook settings stay in the console. Installing the GitHub App also happens in the console, since it needs a browser sign-in with GitHub.