Blitzstrike
Blitz Strike — a universal MCP security-audit toolbelt. Reconnaissance at speed. Analysis in depth. Validation before report.
- Transport
- Not stated
- Package
- —
- Registry id
- —
No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.
Reconnaissance at speed. Analysis in depth. Validation before report.
Blitz Strike is a structured penetration-testing methodology — reconnaissance,
source analysis, and validation — delivered as a universal MCP server. It
enumerates the attack surface (BLITZ), traces source-to-sink reachability
(EAGLE-EYE), and verifies each finding live before it is reported (STRIKE).
One server, every agent: scope enforcement to submission-ready findings in a
single run_engagement call, with the relevant exploit-tool manual attached to
every result.
A scan hit is a hypothesis. A live test is the verdict.
Blitz Strike exists to eliminate the two most common failure modes in automated security assessment: false positives from surface-level pattern matching, and unverified findings reported without live confirmation.
What it does
Blitz Strike is a Model Context Protocol (MCP) server (TypeScript / Bun) that
packages a 3-tier security-audit methodology as callable tools — and runs the
whole engagement server-side, so a single run_engagement call works from
Claude Code, Cursor, Hermes, OpenCode, Claude Desktop, Gemini, or any MCP client.
The three tiers
Blitz Strike maps a structured penetration-testing methodology — reconnaissance, source analysis, and validation — into three tool tiers executed server-side.
| Tier | Name | Phase | What it does |
|---|---|---|---|
| 1 | BLITZ | Reconnaissance & attack-surface mapping | Enumerates the exposed attack surface at scale: unauthenticated entry points, dangerous sinks, and authentication boundaries. |
| 2 | EAGLE-EYE | Static analysis & data-flow tracing | Traces source-to-sink reachability and enriches findings against the escalation-chain graph. Confirms a sink is reachable, unauthenticated, and exploitable — not merely present. |
| 3 | STRIKE | Validation & exploitation | Performs live verification (marker reflection + negative control), scope enforcement, and orchestration so a finding is confirmed before it is ever reported. |
Reconnaissance → analysis → validation. Nothing is reported until STRIKE confirms it.
Beyond the three tiers, Blitz Strike also ships Web3 audit (deterministic Solidity + executable Foundry proof), a live logic-bug prober (sibling enumeration + differential IDOR), hunting intel (CWE/CVE watchlist + DNS sinkhole detection), and out-of-band proof — so IDOR/auth logic bugs, blind injection, and smart-contract findings are all caught and proven, not just pattern-matched.
Autonomous, LLM-driven
Blitz Strike is driven by the LLM — Claude, Hermes, OpenCode, Codex, or any MCP client. The LLM is the brain (plans, routes, delegates, judges); Blitz Strike is the deterministic hands + knowledge + guardrails.
A full engagement is one call, or a granular agent-orchestrated cycle:
npx blitzstrike serve --mcp # connect your agent, then ask it to
# "audit ./src" (source) or "audit https://example.com" (live)
The LLM classifies the target automatically (URL → live pipeline, filesystem
path → source pipeline), then drives recon → analyze → verify → review →
report — guided by the bundled doctrine (instructions + skills + per-step
next_steps) and fanned out across the platform's native sub-agents.
→ Autonomy & doctrine — how the LLM is steered.
Why TypeScript / Bun
- Single static binary via
bun build --compile— ship one executable per platform. - Zero-install distribution via
bunx blitzstrike/npx blitzstrike. - MCP TypeScript SDK first-class (
@modelcontextprotocol/sdk). - One toolchain for dev + test + build + compile.
Quickstart (30 seconds)
# Zero-install — works from any MCP client, no clone, no build
npx -y blitzstrike doctor # verify the environment
npx -y blitzstrike install # auto-register with every detected agent CLI
From the project's README.