Mcpcap

An MCP server for analyzing PCAP files.

LLM Mart 0 views 1 listing impressions
Transport
Not stated
Package
—
Registry id
ai.mcpcap/mcpcap

No install snippet on purpose. A working MCP config is a command, its arguments and an environment block — the last two are where API keys live, so this catalogue never stores them and cannot publish them. Follow the link above for the authors' own instructions.

mcp

A modular Python MCP (Model Context Protocol) server for analyzing PCAP files. mcpcap exposes protocol-specific analysis tools that accept a local file path or remote HTTP URL at call time, so the server stays stateless and works cleanly with MCP clients.

Overview

mcpcap uses a modular architecture to analyze different network protocols found in PCAP files. Each module provides specialized analysis tools that can be called independently with any PCAP file, making it perfect for integration with Claude Desktop and other MCP clients.

Key Features

  • Stateless MCP Tools: Each analysis call supplies its own PCAP path or URL
  • Modular Architecture: DNS, DHCP, ICMP, TCP, SIP, and CapInfos modules with easy extensibility for new protocols
  • Advanced TCP Analysis: Connection lifecycle, traffic patterns, retransmissions, and flow inspection
  • Local & Remote PCAP Support: Analyze files from local storage or HTTP URLs
  • Scapy Integration: Leverages scapy's comprehensive packet parsing capabilities
  • Specialized Analysis Prompts: Security, networking, and forensic analysis guidance
  • JSON Responses: Structured data format optimized for LLM consumption

Installation

mcpcap requires Python 3.10 or greater.

Using pip

pip install mcpcap

Using uv

uv add mcpcap

Using uvx (for one-time usage)

uvx mcpcap

Using Docker

Build the image from the repository root:

docker build -t mcpcap .

Run it over HTTP for MCP clients that connect to a network endpoint:

docker run --rm \
  -p 127.0.0.1:8080:8080 \
  -v "$(pwd)/examples:/pcaps:ro" \
  mcpcap --transport http --host 0.0.0.0 --port 8080 --allow-unauthenticated-http

Run it over stdio for clients that can spawn docker run directly:

docker run --rm -i \
  -v "$(pwd)/examples:/pcaps:ro" \
  mcpcap

When you mount local captures into the container, use the container path in tool calls:

analyze_dns_packets("/pcaps/dns.pcap")

Remote http:// and https:// PCAP URLs work without a volume mount because mcpcap downloads them inside the container at call time.

Using Docker Compose

For the default HTTP workflow, start the bundled Compose service:

docker compose up

This pulls ghcr.io/mcpcap/mcpcap:latest, publishes http://127.0.0.1:8080/mcp only on host loopback, and mounts ./examples into the container as /pcaps.

analyze_dns_packets("/pcaps/dns.pcap")

To analyze your own captures, change the volume in docker-compose.yml from ./examples:/pcaps:ro to your local capture directory.

For local development against the checked-out source instead of GHCR:

docker compose -f docker-compose.yml -f docker-compose.dev.yml up --build

Quick Start

1. Start the MCP Server

Start mcpcap as a stateless MCP server:

# Default stdio transport for Claude Desktop and similar clients
mcpcap

# Start with specific modules only
mcpcap --modules dns,tcp

# With packet analysis limits
mcpcap --max-packets 1000

# Start an HTTP transport server for remote MCP clients
mcpcap --transport http --host 127.0.0.1 --port 8080

2. Connect Your MCP Client

Use stdio transport for local MCP clients like Claude Desktop:

{
  "mcpServers": {
    "mcpcap": {
      "command": "mcpcap",
      "args": []
    }
  }
}

Use HTTP transport when your MCP client expects a network endpoint:

mcpcap --transport http --host 127.0.0.1 --port 8080

Point your HTTP-capable MCP client at:

http://127.0.0.1:8080/mcp

Docker users can publish the same endpoint with:

docker run --rm \
  -p 127.0.0.1:8080:8080 \
  -v "/path/to/captures:/pcaps:ro" \
  mcpcap --transport http --host 0.0.0.0 --port 8080 --allow-unauthenticated-http

Or with Compose:

docker compose up

From the project's README.

Related servers

MCP server for Geargrafx PC Engine / TurboGrafx-16 emulator

15 views

Read-only discovery for NeuralNg Angular components, APIs, packages, icons and theme recipes.

14 views

Umami v3 MCP for Cloud or self-hosted analytics, with read-only, privacy-conscious defaults.

12 views

Read and write RAGE Package Format archives

12 views