shinthink/blitzstrike
⚡ Blitz Strike — a universal MCP penetration-testing toolbelt. Structured methodology: reconnaissance & attack-surface mapping, source-to-sink analysis, and live validation. 57 escalation chains, 130-tool catalog, intelligence data layer. One server, every agent.
About the project
A TypeScript/Bun MCP server packaging a pentest methodology into three tiers: attack-surface reconnaissance, source-to-sink tracing, and live validation of findings before reporting.
Useful for
- Connect the server to Claude Code or Cursor and run a source audit via run_engagement
- Verify discovered sinks for reachability and missing authentication before reporting
- Run live validation against a URL target with scope enforcement and negative control
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 1 star so far today, about 42 expected by the end of the day.
- The spike has held for 2 days in a row — not a one-off blip.
- The repository is 6 days old and already has 635 stars.
- Top new repositories this week: #17.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 635
- Stars in a day
- 42
- Forks
- 1
- Issues and pull requests
- 0
- Watchers
- 0
- Language
- TypeScript
- License
- MIT
- Latest release
- v1.0.0 · September 12, 2026
- Created
- September 12, 2026
- Last push
- September 18, 2026
Star trust
Unusual star pattern. The magnitude is lowered, not zeroed:
- Very few forks: 1 for 635 stars. Active projects usually have 3–15 forks per 100 stars.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 18, 2026Top new repositories this week: #11
- September 17, 2026Top new repositories this week: #12
Similar projects
-
9.7
cloudflare/security-audit-skill
A coding-agent skill that turns the agent into a security auditor, running a multi-phase code audit with independently verified, machine-readable findings.
-
6.6
yynxxxxx/gpt_sub_analysis
A guide to analyzing the ChatGPT iOS subscription flow: it describes intercepting the buyProduct request via Reqable and SSL Kill Switch 3 and rewriting the offerName and salableAdamId fields to obtain the Pro 20x…
-
5.9
ctdal/cve-2026-41940-PoC
PoC exploit for CVE-2026-41940, a critical authentication bypass in cPanel & WHM (CVSS 10.0) that grants unauthenticated root-level WHM access by injecting CRLF sequences into server-side session files.
-
5.3
BennyThink/NFCX
Cross-platform GUI desktop app for NFC card work: reader discovery, MIFARE Classic reads, dumps, key management, and key recovery. For cards you own or are authorized to test.
-
5.0
NationalSecurityAgency/ghidra
A software reverse engineering framework from the NSA: disassembly, decompilation, graphing and scripting for analyzing compiled code on Windows, macOS and Linux.
-
4.6
bl4ckarch/go-responder
A Go port of Responder: poisons LLMNR, NBT-NS and mDNS, runs rogue servers (SMB, HTTP, LDAP, etc.) and captures NTLM hashes and cleartext credentials.