Mmcp.market

Cyberchef MCP server

by doublegate·io.github.doublegate/cyberchef-mcp·v4.2.0

CyberChef's 504 data-transformation operations as MCP tools: encryption, encoding, forensics.

B77/100grade B
What users say
No reviews yet
Be the first
Safety scan
B77/100

full report

Adoption
Growing

19 stars474 downloads/wk

Reviews

Write one

Nobody has reviewed Cyberchef yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Cyberchef tools (13, 4 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • cyberchef_analysewrite action

    Run one of this server's analysis tools -- analyses a CyberChef operation

  • cyberchef_bakewrite action

    Execute a CyberChef recipe. Use this for complex chains of operations.

  • cyberchef_batchwrite action

    Execute multiple CyberChef operations in batch (parallel or sequential mode). Supports partial success.

  • cyberchef_cache_clear

    Clear the operation result cache.

  • cyberchef_cache_stats

    Get cache statistics including hits, misses, size, and items.

  • cyberchef_categories

    List CyberChef's operation categories with counts and examples.

  • cyberchef_describe_operation

    Full argument schema, defaults and types for one or more operations.

  • cyberchef_quota_info

    Get current resource quota information including concurrent operations and data sizes.

  • cyberchef_recipe_executewrite action

    Execute a saved recipe with input data.

  • cyberchef_recipe_export

    Export a recipe to various formats (json, yaml, url, cyberchef).

  • cyberchef_search

    Search for available CyberChef operations. Returns names and one-line summaries;

  • cyberchef_telemetry_export

    Export collected telemetry metrics. Returns anonymized usage statistics.

  • cyberchef_worker_stats

    Get worker thread pool statistics including thread count, utilization, and completed tasks. Only available when ENABLE_WORKERS=true.

Public scan report

scanner v0.1.8 · 2026-09-19 · same rubric, same numbers if you re-run it

2 medium
  • Code scan706 source files scanned15/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 6 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (2)

  • mediumnpm install lifecycle script presentinstall.script
  • mediumnpm install lifecycle script presentinstall.script
    package.json: … "lint:grammar": "cspell ./src", "postinstall": "node scripts/patch-dependencies.mjs", …
Overall 77/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Grade history

  • 2026-09-19restoreCBscore 77: npm install lifecycle script present; npm install lifecycle script present
  • 2026-09-19restoreFCscore 58: Base64 decoded then executed; npm install lifecycle script present; npm install lifecycle script present

Install directly

claude mcp add cyberchef-mcp -- docker run -i --rm ghcr.io/doublegate/cyberchef-mcp_v4:4.2.0
Add to Cursor

Cyberchef: common questions

Is Cyberchef MCP server safe?
Mostly: it is graded B (77/100). Read the Cyberchef safety report
How do I install Cyberchef?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does Cyberchef need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Cyberchef maintained?
The last commit was 7 days ago (2026-09-13). The latest release is v4.2.0.

More from doublegate