mrkeyoor.com_
Mon 05 Oct 06:27 UTC
Dev Toolsevaluationupdated 05 Oct 2026

blitzstrike review

Blitz Strike is an MCP server that gives an AI coding agent tools for source review, reconnaissance, vulnerability checks, and evidence-backed security reports. It combines scanners, attack-chain guidance, live verification, and a catalog of external security programs behind one agent-facing interface.

Verdict

Our Blitz Strike run installed 130 packages in 22 seconds and passed its 5-second build and 16-second test step, but npm audit still found 2 moderate vulnerabilities. Use it as a supervised console for authorized assessments when its MCP workflow saves analysts from stitching tools together. Do not give it an open-ended target or treat an LLM verdict as permission to skip manual reproduction.

We ran it

Lab card: what happened when we ran blitzstrikeScreenshot of blitzstrike (github.com/shinthink/blitzstrike)
Install✓ · 22s130 packages · 83 MB
Build✓ · 5s
Tests✓ · 16sran, no count parsed
Known vulns20 critical · 0 high · 2 moderate · 0 low (npm audit)
Repo13103 files~29,448 lines of source · 49.3 MB · 2 CI workflows · tests dir

Answers from our run

Does blitzstrike build from source?

Dependencies installed in 22 seconds (130 packages), and the build succeeded in 5 seconds. We cloned commit 68acb6c into a clean Debian container with 3 CPUs and no project-specific setup.

Do blitzstrike's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does blitzstrike have known vulnerabilities in its dependencies?

npm audit flagged 2 known advisories in the dependency tree at the time of our run.

Who should not use blitzstrike?

Unsupervised use against public targets: the server can perform live reconnaissance and verification, and its security policy requires explicit permission from the owner.

What are the alternatives to blitzstrike?

Semgrep, Nuclei, OWASP ZAP. Our Blitz Strike run installed 130 packages in 22 seconds and passed its 5-second build and 16-second test step, but npm audit still found 2 moderate vulnerabilities.

Setup4/5Fast local setup, but useful engagements need tools, data, and scope
Docs4/5Detailed tool tables and setup, with some version drift
Community3/5498 stars and an October push, but no issue history to inspect
Maturity3/5Tests pass, though the project is young and audit has 2 moderates

Who it’s for

Security engineers who want an MCP client to coordinate source review and authorized live checks.
Bug-bounty or internal assessment teams willing to verify every agent-generated finding.
Developers who need repeatable evidence, negative controls, deduplication, and report output around security tests.
Bun or Node users prepared to install and govern the external tools behind the catalog.

Who it’s NOT for

Unsupervised use against public targets: the server can perform live reconnaissance and verification, and its security policy requires explicit permission from the owner.
Teams that need Go or Ruby taint analysis today: the roadmap says those languages are not covered, while the Java adapter is currently regex-oriented.
Organizations requiring a shared remote MCP service: the current setup uses local stdio, and HTTP transport appears only as a medium-term aspiration.
Release gates that require a clean dependency audit: our install reported 2 moderate vulnerabilities.
Operators who do not want an agent able to install security programs: the exposed ensure_tool action can auto-install a missing catalog entry.

Setup reality

Our sandbox installed commit 68acb6c in 22 seconds, adding 130 packages and using 83 MB. The build passed in 5 seconds, and the test command passed in 16 seconds. Npm audit found 2 moderate vulnerabilities, with 0 critical and 0 high.

Running the MCP server needs Bun 1.4 or Node 20 plus a compatible client. FOFA search needs FOFA_EMAIL and FOFA_KEY; other core actions do not require credentials. Full engagements may call locally installed security tools and fetch payload or template data.

The checkout was 49.3 MB across 13,103 files and about 29,448 source lines. Automatic registration writes merged entries into detected agent configs, so use install --dry-run first. Live tests require a written scope and network access to the authorized target.

One MCP server exposes an unusually wide security surface

Blitz Strike puts source scanning, data-flow tracing, live HTTP verification, CVE lookups, Web3 checks, reporting, and a catalog of security programs behind an MCP server. An AI client can call individual actions or start a full engagement. Findings move through reconnaissance, analysis, and verification, with negative controls intended to reject simple pattern matches before a report is written.

The breadth is real in the interface. The repository documents 130 catalog entries, 17 engagement playbooks, 3 main analysis tiers, and data for WAF, technology, port, payload, and template lookups. Some catalog entries are guidance for external programs rather than built-in scanners. ensure_tool can check for a program and auto-install it. That makes the server a coordinator as much as an analyzer.

The agent drives tools that can touch a live target

Blitz Strike describes the LLM as the planner and judge, while the server supplies actions and guardrails. The live path can fingerprint a site, crawl, enumerate parameters and subdomains, scan ports, and send marker-based verification requests. Its scope checker adds exclusions and a no-DoS mode, but the operator still chooses the target, grants tool access, and accepts the consequences of an active request.

The project's security policy requires explicit written permission for any system you do not own. That condition belongs in the deployment design, not just a disclaimer. Give the MCP server a network boundary, run it under a limited account, record the approved hosts, and review each proposed active step. An agent prompt is not a signed scope document, and a scope string is not a substitute for egress controls.

What happened when we ran it

Our measurement setup cloned commit 68acb6c into an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets. Bun installed 130 packages in 22 seconds and used 83 MB on disk. The build finished successfully in 5 seconds. The supplied test command also passed in 16 seconds.

Npm audit reported 2 known vulnerabilities, both moderate, with 0 critical, 0 high, and 0 low. The measurement block does not identify the affected packages or reachable code paths, so claiming exploitability would go beyond the evidence. A team should inspect the audit report before deployment and decide whether the vulnerable dependencies are loaded by the MCP server actions it plans to expose.

The checkout was much larger than its source count suggests: 13,103 files, about 29,448 lines of source, and 49.3 MB. It contained 2 CI workflows and a tests directory, but no Dockerfile. Our run established that install, build, and test commands complete. It did not run an assessment against a target or measure vulnerability-detection accuracy.

Local stdio is ready, while remote HTTP is still an aspiration

The normal transport is MCP over local stdio. blitzstrike install detects supported clients and merges a server entry into their config files. The documentation lists 10 client locations, including Claude Code, Cursor, Codex, Gemini, and Copilot. A dry-run option previews the edit, which is the right first move when those files already contain other MCP servers.

A shared remote endpoint is not part of the current promise. The roadmap lists HTTP transport under medium-term work, alongside a wizard installer. Teams wanting one centrally governed service will need their own wrapper or a different product today. The repository also has no Dockerfile, so process isolation, filesystem mounts, outbound networking, and persistence for its JSONL memory remain your deployment choices.

Language coverage has explicit gaps

The universal taint tools cover PHP, JavaScript, TypeScript, Python, and Java according to the README. The roadmap is more precise about the weak spots: Java analysis is currently regex-oriented, and Go and Ruby are not covered. XML processing and archive extraction also remain uncovered sink classes. These statements are useful because they prevent a broad tool list from sounding like universal code understanding.

Web3 support follows a separate Solidity path, including source checks and Foundry proof generation. Live logic-bug actions cover differential authorization tests and IDOR-style cases. Those features still need fixtures from your stack. Before adoption, feed the server known vulnerable and known safe samples from the languages you use, then verify that negative controls fail for the right reason.

Source version 2.4.139 is ahead of the v1.0.0 GitHub release

GitHub's latest release is v1.0.0 from September 12, 2026, while the current package.json declares version 2.4.139. The repository was pushed on October 4 and showed 498 stars with 0 open issues or pull requests on October 5. The later source activity argues against reading the old GitHub tag as abandonment, but the version split makes provenance harder to follow.

Pin the exact package or commit you evaluate and keep the bundled data under change control. Blitz Strike is most useful when an experienced analyst wants one MCP surface for many authorized checks. Our passing build and test step make it worth a controlled trial. The 2 moderate audit findings, active-tool installation, and LLM-directed network actions rule out casual, unsupervised deployment.

Alternatives

ProjectWhat it isPick it when
SemgrepA rule-based static analyzer designed for repeatable local and CI scans.pick this instead when deterministic source rules and CI enforcement matter more than MCP orchestration.
Nuclei gh↗A template-driven scanner for known conditions across authorized network targets.pick this instead when you need a focused, scriptable scanner without an LLM directing the workflow.
OWASP ZAPA web application testing proxy with passive and active scan modes.pick this instead when browser and HTTP proxy inspection are central to the assessment.

What people are saying

  1. [velocity-scout] shinthink/blitzstrike

Sources

  1. Blitz Strike repository
  2. Blitz Strike README
  3. Blitz Strike installation guide
  4. Blitz Strike roadmap
  5. Blitz Strike v1.0.0 release

More dev tools reviews

learning-python · github-launch-checklist · AirCard · github-ranking-audit · gpt_sub_analysis · PythonRobotics · the whole board →