38 个核心工具,31 个标记为 AI 可调用。配置见仓库 tools/ai-tool-registry.json 与 .mcp.json;完整 100+ 工具集由 mcp_smoke_check.py 验证。
system.curlAIsystem.dockerAIsystem.gitAIsystem.goAIsystem.javaAIsystem.nodeAIsystem.pythonAIsystem.rgAImisc.ai_contextAIRun at task start with the real task text and --save to recall tools/findings.
misc.ai_findingAImisc.ai_toolAImisc.ai_toolcheckAImisc.mitmproxy_captureAI抓包/改包/发包: capture(抓包保存JSON), modify(代理+addon实时改包), replay(重放已抓flow), craft(构造发包). CA证书在%USERPROFILE%/.mitmproxy/.
misc.proxy_pipelineAI代理管道: forward/chain/route/test. 串联多级代理或路由流量到代理池.
misc.proxy_poolAI代理池管理: fetch, validate, rotate, stats. 为扫描工具提供代理轮换.
misc.proxy_testAI单代理快速连通性/匿名性测试.
ctf.burp.jar手动GUI/proxy app. Automatic AI checks must not launch it; use only when user explicitly wants the GUI.
ctf.burp.wrapper手动No-popup wrapper probe. The MCP burp_status tool reports whether a Burp JAR is installed.
ctf.dirsearchAIctf.feroxbusterAIctf.ffufAIctf.gobusterAIctf.httpxAIctf.jwt_toolAIctf.katanaAIctf.nmapAIctf.nucleiAIctf.searchsploitAIctf.sqlmapAIctf.tplmapAIandroid.apktoolAIandroid.frida_server_x86_64手动Android target binary; push with scripts/android/install_frida_server.ps1.
android.jadxAICLI wrapper uses absolute classpath and does not launch GUI.
android.uber_apk_signerAIwindows.cutter手动GUI reverse engineering frontend; automatic AI checks only verify file exists.
windows.hxd手动Installer/GUI; automatic AI checks only verify file exists.
windows.pe_bear手动GUI. Do not launch in automatic checks.
windows.procmon手动GUI. Use Procmon configs/scripts only when explicitly needed.