Nyxstrike

221 tools. 187 can modify or destroy data without limits.

3 destructive tools with no built-in limits. Policy required.

Last updated:

187 can modify or destroy data
34 read-only
221 tools total

Community server · catalogue entry checked 07/07/2026

How to control Nyxstrike ↓

What Nyxstrike exposes to your agents

Read (34) Write / Execute (183) Destructive / Financial (3)
Critical Risk

The most dangerous Nyxstrike tools

187 of Nyxstrike's 221 tools can modify, destroy, or commit something on every call — and an agent calls them with no built-in limits.

How to control Nyxstrike

PolicyLayer is an MCP gateway — it sits between your AI agents and Nyxstrike, and nothing reaches the server without passing your rules. These are the rules we recommend:

Deny destructive operations
{
  "clear_cache": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Blocked by default. Requires approval."
      }
    ]
  }
}

Destructive tools should never be available to autonomous agents without human approval.

Rate limit write operations
{
  "bugbounty_osint_gathering": {
    "limits": [
      {
        "counter": "bugbounty_osint_gathering_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "analyze_target_intelligence": {
    "limits": [
      {
        "counter": "analyze_target_intelligence_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

  1. Create a free account and register Nyxstrike — nothing to install.
  2. Add these rules — paste them, or build them visually. Tune the limits to your setup.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
ENFORCE POLICY ON NYXSTRIKE →

Instant setup, no code required.

All 221 Nyxstrike tools

EXECUTE 175 tools
Execute advanced_payload_generation advanced_payload_generation Execute ai_generate_attack_suite Generate comprehensive attack suite with multiple payload types. Execute ai_generate_payload ai_generate_payload Execute ai_reconnaissance_workflow ai_reconnaissance_workflow Execute ai_test_payload ai_test_payload Execute ai_vulnerability_assessment ai_vulnerability_assessment Execute airbase_ng airbase_ng Execute aircrack_ng aircrack_ng Execute aircrack_ng_analysis aircrack_ng_analysis Execute airdecap_ng airdecap_ng Execute aireplay_ng aireplay_ng Execute airmon_ng airmon_ng Execute airodump_ng airodump_ng Execute amass_scan Execute Amass for subdomain enumeration with enhanced logging. Execute analyze_session analyze_session Execute anew_data_processing anew_data_processing Execute angr_symbolic_execution angr_symbolic_execution Execute api_fuzzer api_fuzzer Execute api_schema_analyzer api_schema_analyzer Execute arjun_parameter_discovery arjun_parameter_discovery Execute arjun_scan arjun_scan Execute arp_scan_discovery arp_scan_discovery Execute autopsy_analysis Launch the Autopsy digital forensics web server and provide access instructions. Execute autorecon_comprehensive autorecon_comprehensive Execute autorecon_scan autorecon_scan Execute bbot_scan bbot_scan Execute bettercap_wifi bettercap_wifi Execute binwalk_analyze binwalk_analyze Execute breachsql_scan breachsql_scan Execute browser_agent_inspect browser_agent_inspect Execute bugbounty_authentication_bypass_testing bugbounty_authentication_bypass_testing Execute bugbounty_business_logic_testing bugbounty_business_logic_testing Execute bugbounty_comprehensive_assessment bugbounty_comprehensive_assessment Execute bugbounty_file_upload_testing Create file upload vulnerability testing workflow with bypass techniques. Execute bugbounty_reconnaissance_workflow bugbounty_reconnaissance_workflow Execute bugbounty_vulnerability_hunting bugbounty_vulnerability_hunting Execute burpsuite_alternative_scan burpsuite_alternative_scan Execute burpsuite_scan burpsuite_scan Execute checkov_iac_scan checkov_iac_scan Execute clair_vulnerability_scan clair_vulnerability_scan Execute classify_task classify_task Execute cloudmapper_analysis cloudmapper_analysis Execute commix commix Execute comprehensive_api_audit comprehensive_api_audit Execute correlate_threat_intelligence correlate_threat_intelligence Execute create_attack_chain_ai create_attack_chain_ai Execute dalfox_xss_scan dalfox_xss_scan Execute dirb_scan Execute Dirb for directory brute forcing with enhanced logging. Execute dirsearch_scan dirsearch_scan Execute discover_attack_chains discover_attack_chains Execute dnsenum_scan dnsenum_scan Execute docker_bench_security_scan docker_bench_security_scan Execute dotdotpwn_scan dotdotpwn_scan Execute eaphammer eaphammer Execute enum4linux_ng_advanced enum4linux_ng_advanced Execute enum4linux_scan Execute Enum4linux for SMB enumeration with enhanced logging. Execute execute_command Execute an arbitrary command on the API server with enhanced logging. Execute execute_python_script execute_python_script Execute exploit_db exploit_db Execute falco_runtime_monitoring falco_runtime_monitoring Execute feroxbuster_scan feroxbuster_scan Execute ffuf_scan ffuf_scan Execute fierce_scan Execute fierce for DNS reconnaissance with enhanced logging. Execute follow_up_session follow_up_session Execute foremost_carving foremost_carving Execute gau_discovery gau_discovery Execute gdb_analyze gdb_analyze Execute gdb_peda_debug gdb_peda_debug Execute generate_exploit_from_cve generate_exploit_from_cve Execute generate_payload generate_payload Execute ghidra_analysis ghidra_analysis Execute gobuster_scan gobuster_scan Execute gospider_crawl gospider_crawl Execute graphql_scanner graphql_scanner Execute hakrawler_crawl hakrawler_crawl Execute handover_session handover_session Execute hashcat_crack hashcat_crack Execute hashpump_attack hashpump_attack Execute hcxdumptool hcxdumptool Execute hcxpcapngtool hcxpcapngtool Execute http_framework_test http_framework_test Execute http_intruder Simple Intruder (sniper) fuzzing. Iterates payloads over each param individually. Execute http_repeater Send a crafted request (Burp Repeater equivalent). request_spec keys: url, method, headers, cookies, data. Execute http_set_rules Set match/replace rules used to rewrite parts of URL/query/headers/body before sending. Execute httpx_probe httpx_probe Execute hurl_request hurl_request Execute hydra_attack hydra_attack Execute impacket_ad_enum impacket_ad_enum Execute impacket_get_spec impacket_get_spec Execute impacket_remote_exec impacket_remote_exec Execute impacket_run impacket_run Execute install_python_package Install a Python package in a virtual environment on the API server. Execute intelligent_smart_scan intelligent_smart_scan Execute interactsh_client interactsh_client Execute jaeles_vulnerability_scan jaeles_vulnerability_scan Execute john_crack john_crack Execute joomscan_analyze Execute Joomscan for Joomla vulnerability scanning with enhanced logging. Execute katana_crawl katana_crawl Execute kube_bench_cis kube_bench_cis Execute kube_hunter_scan kube_hunter_scan Execute masscan_high_speed masscan_high_speed Execute massdns_scan massdns_scan Execute mdk4 mdk4 Execute medusa_attack medusa_attack Execute metasploit_run metasploit_run Execute msfvenom_generate msfvenom_generate Execute mysql_query mysql_query Execute nbtscan_netbios nbtscan_netbios Execute netexec_scan netexec_scan Execute nikto_scan Execute Nikto web vulnerability scanner with enhanced logging. Execute nmap_advanced_scan nmap_advanced_scan Execute nmap_scan nmap_scan Execute nuclei_scan nuclei_scan Execute nyxstrike_h2csmuggler nyxstrike_h2csmuggler Execute nyxstrike_net_ping nyxstrike_net_ping Execute objdump_analyze objdump_analyze Execute one_gadget_search one_gadget_search Execute ophcrack_crack ophcrack_crack Execute optimize_tool_parameters_ai optimize_tool_parameters_ai Execute pacu_exploitation pacu_exploitation Execute paramspider_discovery paramspider_discovery Execute paramspider_mining paramspider_mining Execute parsero Execute Parsero for Robots.txt analysis with enhanced logging. Execute patator_attack patator_attack Execute pause_process Pause a specific running process. Execute phaseaccess_scan phaseaccess_scan Execute postgresql_query postgresql_query Execute preview_attack_chain_ai preview_attack_chain_ai Execute prowler_scan prowler_scan Execute pwninit_setup pwninit_setup Execute pwntools_exploit pwntools_exploit Execute qsreplace_parameter_replacement qsreplace_parameter_replacement Execute radare2_analyze radare2_analyze Execute research_zero_day_opportunities research_zero_day_opportunities Execute responder_credential_harvest responder_credential_harvest Execute resume_process Resume a paused process. Execute ropgadget_search ropgadget_search Execute ropper_gadget_search ropper_gadget_search Execute rpcclient_enumeration rpcclient_enumeration Execute run_tool run_tool Execute rustscan_fast_scan rustscan_fast_scan Execute schemathesis schemathesis Execute scout_suite_assessment scout_suite_assessment Execute select_optimal_tools_ai select_optimal_tools_ai Execute sherlock Execute Sherlock for username investigation across social networks. Execute shuffledns_scan shuffledns_scan Execute smbmap_scan smbmap_scan Execute spiderfoot Execute SpiderFoot for OSINT automation with enhanced logging. Execute sqlite_query sqlite_query Execute sqlmap_scan Execute SQLMap for SQL injection testing with enhanced logging. Execute ssh ssh Execute steghide_analysis steghide_analysis Execute stingxss_scan stingxss_scan Execute subfinder_scan subfinder_scan Execute telnet telnet Execute terrascan_iac_scan terrascan_iac_scan Execute test_error_recovery test_error_recovery Execute testssl_analyze testssl_analyze Execute theharvester_scan theharvester_scan Execute threat_hunting_assistant threat_hunting_assistant Execute trivy_scan trivy_scan Execute uro_url_filtering uro_url_filtering Execute vaultrip_sweep vaultrip_sweep Execute volatility_analyze volatility_analyze Execute volatility3_analyze volatility3_analyze Execute vulnx vulnx Execute wafw00f_scan Execute wafw00f to identify and fingerprint WAF products with enhanced logging. Execute wfuzz_scan wfuzz_scan Execute whatweb_analyze Execute WhatWeb for web technology fingerprinting with enhanced logging. Execute wifite2 wifite2 Execute wordlist_find_best wordlist_find_best Execute wpscan_analyze Execute WPScan for WordPress vulnerability scanning with enhanced logging. Execute x8_parameter_discovery x8_parameter_discovery Execute xsser_scan Execute XSSer for XSS vulnerability testing with enhanced logging. Execute zap_scan zap_scan
READ 34 tools
Read analyze_target_intelligence Analyze target using AI-powered intelligence to create comprehensive profile. Read assetfinder_scan assetfinder_scan Read check_http_headers check_http_headers Read checksec_analyze Check security features of a binary with enhanced logging. Read detect_technologies_ai Use AI to detect technologies and provide technology-specific testing recommendations. Read dig_dns dig_dns Read display_system_metrics Display current system metrics and performance indicators with visual formatting. Read error_handling_statistics Get intelligent error handling system statistics and recent error patterns. Read exiftool_extract exiftool_extract Read get_cache_stats Get cache statistics from the API server. Read get_live_dashboard Get a beautiful live dashboard showing all active processes with enhanced visual formatting. Read get_process_dashboard Get enhanced process dashboard with visual status indicators. Read get_process_status Get the status of a specific process. Read get_telemetry Get system telemetry from the API server. Read hashid hashid Read jwt_analyzer jwt_analyzer Read ldapdomaindump ldapdomaindump Read libc_database_lookup libc_database_lookup Read list_active_processes List all active processes on the API server. Read list_files List files in a directory on the API server. Read llm_agent_scan_result Retrieve the results of a completed LLM agent scan session. Read llm_status Check whether the LLM backend is available and report its configuration. Read monitor_cve_feeds monitor_cve_feeds Read server_health Check the health status of the API server. Read strings_extract Extract strings from a binary file with enhanced logging. Read sublist3r sublist3r Read vulnerability_intelligence_dashboard vulnerability_intelligence_dashboard Read waybackurls_discovery waybackurls_discovery Read waymore_discovery waymore_discovery Read whois_lookup Perform a WHOIS lookup for a domain or IP address. Read wordlist_get Retrieve a specific wordlist entry by its ID. Read wordlist_get_all Retrieve all wordlist entries. Read wordlist_get_path Retrieve the file path for a specific wordlist by its ID. Read xxd_hexdump xxd_hexdump

Related servers

Other MCP servers with similar tools — same risk classification, starter policies for each.

Questions about Nyxstrike

Can an AI agent delete data through the Nyxstrike MCP server? +

Yes. The Nyxstrike server exposes 3 destructive tools including clear_cache, delete_file, wordlist_delete. These permanently remove resources with no undo. PolicyLayer blocks destructive tools by default so they never reach the upstream server.

How do I prevent bulk modifications through Nyxstrike? +

The Nyxstrike server has 8 write tools including bugbounty_osint_gathering, create_file, create_scan_summary. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach Nyxstrike.

How many tools does the Nyxstrike MCP server expose? +

221 tools across 4 categories: Destructive, Execute, Read, Write. 34 are read-only. 187 can modify, create, or delete data.

How do I enforce a policy on Nyxstrike? +

Register the Nyxstrike MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Enforce policy on every Nyxstrike tool call.

Deterministic rules across all 221 Nyxstrike tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Instant setup, no code required.

221 Nyxstrike tools catalogued and risk-classified — across an index of 46,500+ MCP servers.

// WHERE THIS COMES FROM

These policies come from Nyxstrike's registry record.

The record behind this page: verified identity, auth posture, risk grade, every tool classified, recommended policy — re-checked continuously.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.