
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@pentatrail/mcp-server
Advanced tools
PentaTrail MCP Server for accessing CTEM (Continuous Threat Exposure Management) data via Model Context Protocol.
This package is a thin stdio wrapper over the PentaTrail Customer API. It works with Claude Code, Claude Desktop, and any MCP-compatible client.
The simplest way to use the server is with npx:
npx @pentatrail/mcp-server
Release the package from this directory:
cd packages/pentatrail-mcp
npm login --registry=https://registry.npmjs.org/
npm run build
npm pack --dry-run --cache /tmp/npm-cache
npm publish --access public
Notes:
--access public for a public npm release.npm login can be skipped.npm version patch --no-git-tag-version.Add to your MCP client config (e.g. ~/.claude/settings.json or claude_desktop_config.json):
{
"mcpServers": {
"pentatrail": {
"command": "npx",
"args": ["@pentatrail/mcp-server"],
"env": {
"PENTATRAIL_API_KEY": "ptk_your_api_key_here",
"PENTATRAIL_API_URL": "https://api.pentatrail.co"
}
}
}
}
| Variable | Required | Description |
|---|---|---|
PENTATRAIL_API_KEY | Yes | Your API key (ptk_...). Generate from PentaTrail Dashboard > Settings. |
PENTATRAIL_API_URL | Yes | https://api.pentatrail.co (production) |
| Tool | Description |
|---|---|
ctem_list_domains | List all monitored domains for your contract |
ctem_list_hosts | List hosts with enrichment (port/tech/finding counts, sortable) |
ctem_list_findings | List vulnerabilities sorted by Threat Discovery Level (TDL) |
ctem_get_asset_counts | Get asset type counts (hosts, IPs, ports, tech, buckets, URLs) |
ctem_get_tdl_counts | Get open finding counts grouped by TDL (tdl5=most critical) |
ctem_get_scores | Get live domain scores (asset counts + findings breakdown) |
ctem_get_score_trend | Get security score trend over time (7-365 days) |
| Tool | Description |
|---|---|
ctem_add_exclusion | Exclude an asset from monitoring |
ctem_remove_exclusion | Remove an exclusion you created via API |
ctem_update_finding | Update finding status, assignee, or due date |
Once configured, ask your AI assistant:
ctem:read, ctem:exclusions:write, ctem:prioritization:write)End-to-end tests against dev Supabase. See INTEGRATION_TESTS.md for setup, local execution, and failure triage.
UNLICENSED - Proprietary software. All rights reserved.
FAQs
PentaTrail MCP Server — access your CTEM / ASM (attack surface management) data from an AI agent via the Model Context Protocol
The npm package @pentatrail/mcp-server receives a total of 542 weekly downloads. As such, @pentatrail/mcp-server popularity was classified as not popular.
We found that @pentatrail/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.