numasec for
<h2>Terminal AI agent for security workflows and evidence capture</h2>
- Free
- 4
- V v1.2.1
<h2>Terminal AI agent for security workflows and evidence capture</h2>
numasec, created by FrancescoStabile, is an open-source AI security agent that runs inside the terminal to connect language models with local testing tools. It functions as a Model Context Protocol (MCP) server to preserve operation state while automating checklist-driven tasks and assembling findings. The app records terminal outputs and files into an evidence store and produces structured reports. It is designed for CLI-first security workflows used by AppSec engineers and penetration testers.
What tasks can you actually use it for?
The tool acts as a terminal-native coordinator between a language model and existing command-line scanners, enabling concrete outcomes: automated execution of scripted procedures, collection of proof artifacts, and report assembly. Example integrations include direct orchestration of nmap, ffuf, and user scripts, while predefined runbooks map steps to checklists. Users get an auditable record of commands and captured outputs for later review:
- CLI tool orchestration
- Runbook-driven testing
- Evidence capture for findings
How reliable are its outputs in a real engagement?
Operation memory keeps context persistent across a testing session, which reduces repeated manual tracking of findings. The tool records terminal output, screenshots, and logs locally, and compiles those items into structured reports. Generated guidance depends on the connected language model, so any model-suggested findings or remediation steps require independent verification by the tester before they are used in an official assessment.
What inputs and environment does it require?
Deployment requires a Node.js runtime and an MCP-compatible client such as Claude Desktop to let models execute commands. The server runs on any modern terminal environment across Linux, macOS, and Windows. Evidence and operation memory are stored locally by default, and users decide what to send to the connected model; sensitive inputs therefore need local LLM configuration or careful handling to limit external exposure.
Does it fit into existing security workflows without heavy retraining?
The tool is built to integrate with CLI-first workflows and supports custom runbooks so teams can codify existing procedures. Being open-source, the codebase can be audited and extended to match internal scripting practices. Adoption requires setup of MCP client connections and some configuration of runbooks and evidence paths, so teams should expect an initial configuration phase before it is used in routine assessments.
A practical option for CLI-focused security teams with verification needs
The tool is a practical option for AppSec engineers who need terminal-native orchestration and auditable evidence trails. Model-generated guidance requires independent verification and, for sensitive data, a local LLM provider is recommended. Use it when you want a scriptable agent that records findings locally and integrates with existing CLI scanners; expect a configuration step for MCP clients before routine use.
Pros
- Maintains persistent operation memory across testing sessions
- Captures terminal output, screenshots, and logs as evidence
- Acts as an MCP server to connect models with local tools
- Open-source code allows auditing and custom extensions
Cons
- Requires Node.js and an MCP-compatible client for deployment
- Connected language models typically need internet unless local
- Designed for CLI-first professionals, less suited for GUI users
- Local evidence storage requires deliberate data hygiene practices
numasec for
- Free
- 4
- V v1.2.1
Top downloads
passwd-page
passwd-page: zero-knowledge secret sharing for AI agents
tinybrain
Secure MCP sandbox for local execution of model-generated code
mcp-wallfacer
mcp-wallfacer: an MCP server to monitor and block prompt attacks
pyobfus
pyobfus: MCP-native Python obfuscation for AI-assisted workflows
mcp-aguara
Protocol-native security gateway for MCP agents and LLMs
Discover more programs
mcp-server-wazuh
- 4.9
- Free
mcp-proxy-firewall
- 4.9
- Free
mcp-proxy-firewall enforces strict agent controls for MCP environments
void-stack
- 4.8
- Free
Local MCP server for AI-driven development and codebase maintenance
agent-bom
- 4.7
- Free
agent-bom: Open-source BOM scanner for MCP AI infrastructures
AK47
- 4.7
- Free
AK47: Modular security assessment and exploitation framework for professionals
iam-policy-autopilot
- 4.5
- Free
Streamline IAM Policy Creation with IAM Policy Autopilot
ENScan_GO
- 4.1
- Free
Comprehensive AI Security Tool for Data Collection
mcpproxy-go
- 4.9
- Free
MCPProxy: Enhanced AI Tool Management
apktool-mcp-server
- 4.7
- Free
secretgenerator
- 4.5
- Free
Secretgenerator: MCP server for high-entropy credentials
code-pathfinder
- 4.9
- Free
Hol Guard
- 4.4
- Free
Hol Guard: MCP-native gatekeeper for AI-driven developer actions