One MCP server exposes an unusually wide security surface
Blitz Strike puts source scanning, data-flow tracing, live HTTP verification, CVE lookups, Web3 checks, reporting, and a catalog of security programs behind an MCP server. An AI client can call individual actions or start a full engagement. Findings move through reconnaissance, analysis, and verification, with negative controls intended to reject simple pattern matches before a report is written.
The breadth is real in the interface. The repository documents 130 catalog entries, 17 engagement playbooks, 3 main analysis tiers, and data for WAF, technology, port, payload, and template lookups. Some catalog entries are guidance for external programs rather than built-in scanners. ensure_tool can check for a program and auto-install it. That makes the server a coordinator as much as an analyzer.
The agent drives tools that can touch a live target
Blitz Strike describes the LLM as the planner and judge, while the server supplies actions and guardrails. The live path can fingerprint a site, crawl, enumerate parameters and subdomains, scan ports, and send marker-based verification requests. Its scope checker adds exclusions and a no-DoS mode, but the operator still chooses the target, grants tool access, and accepts the consequences of an active request.
The project's security policy requires explicit written permission for any system you do not own. That condition belongs in the deployment design, not just a disclaimer. Give the MCP server a network boundary, run it under a limited account, record the approved hosts, and review each proposed active step. An agent prompt is not a signed scope document, and a scope string is not a substitute for egress controls.
What happened when we ran it
Our measurement setup cloned commit 68acb6c into an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets. Bun installed 130 packages in 22 seconds and used 83 MB on disk. The build finished successfully in 5 seconds. The supplied test command also passed in 16 seconds.
Npm audit reported 2 known vulnerabilities, both moderate, with 0 critical, 0 high, and 0 low. The measurement block does not identify the affected packages or reachable code paths, so claiming exploitability would go beyond the evidence. A team should inspect the audit report before deployment and decide whether the vulnerable dependencies are loaded by the MCP server actions it plans to expose.
The checkout was much larger than its source count suggests: 13,103 files, about 29,448 lines of source, and 49.3 MB. It contained 2 CI workflows and a tests directory, but no Dockerfile. Our run established that install, build, and test commands complete. It did not run an assessment against a target or measure vulnerability-detection accuracy.
Local stdio is ready, while remote HTTP is still an aspiration
The normal transport is MCP over local stdio. blitzstrike install detects supported clients and merges a server entry into their config files. The documentation lists 10 client locations, including Claude Code, Cursor, Codex, Gemini, and Copilot. A dry-run option previews the edit, which is the right first move when those files already contain other MCP servers.
A shared remote endpoint is not part of the current promise. The roadmap lists HTTP transport under medium-term work, alongside a wizard installer. Teams wanting one centrally governed service will need their own wrapper or a different product today. The repository also has no Dockerfile, so process isolation, filesystem mounts, outbound networking, and persistence for its JSONL memory remain your deployment choices.
Language coverage has explicit gaps
The universal taint tools cover PHP, JavaScript, TypeScript, Python, and Java according to the README. The roadmap is more precise about the weak spots: Java analysis is currently regex-oriented, and Go and Ruby are not covered. XML processing and archive extraction also remain uncovered sink classes. These statements are useful because they prevent a broad tool list from sounding like universal code understanding.
Web3 support follows a separate Solidity path, including source checks and Foundry proof generation. Live logic-bug actions cover differential authorization tests and IDOR-style cases. Those features still need fixtures from your stack. Before adoption, feed the server known vulnerable and known safe samples from the languages you use, then verify that negative controls fail for the right reason.
Source version 2.4.139 is ahead of the v1.0.0 GitHub release
GitHub's latest release is v1.0.0 from September 12, 2026, while the current package.json declares version 2.4.139. The repository was pushed on October 4 and showed 498 stars with 0 open issues or pull requests on October 5. The later source activity argues against reading the old GitHub tag as abandonment, but the version split makes provenance harder to follow.
Pin the exact package or commit you evaluate and keep the bundled data under change control. Blitz Strike is most useful when an experienced analyst wants one MCP surface for many authorized checks. Our passing build and test step make it worth a controlled trial. The 2 moderate audit findings, active-tool installation, and LLM-directed network actions rule out casual, unsupervised deployment.

