Skip to content
dsh.fish
Bundle

xby-bbot

BBOT MCP服务器是一个用于管理和执行BBOT安全扫描的工具,提供模块管理、预设配置、实时监控等功能。

Source
xby-skill
License
MIT
Updated
Updated 2 days ago

Readme

# xby-bbot

DeepSeek Harness (DSH) 的插件:BBOT安全扫描服务

BBOT MCP服务器是一个用于管理和执行BBOT安全扫描的工具,提供模块管理、预设配置、实时监控等功能。

## 功能

- **set_xby_apikey** — 在聊天中设置 API 密钥(自动持久化,重启有效)
- **list_bbot_modules** — List all available bbot modules
- **list_bbot_presets** — List all available bbot presets
- **start_bbot_scan** — 
Start a new bbot scan

Args:
    targets: Comma-separated list of targets (domains, IPs, URLs)
    modules: Comma-separated list of modules to use (optional)
    presets: Comma-separated list of presets to use (optional)
    flags: Comma-separated list of flags to use (optional)
    no_deps: Disable dependency installation to prevent sudo prompts (default: True)

- **get_scan_status** — Get the status of a specific scan
- **get_scan_results** — 
Get results from a specific scan

Args:
    scan_id: The ID of the scan
    limit: Maximum number of results to return (default: 100)

- **list_active_scans** — List all active scans
- **wait_for_scan_completion** — 
Wait for a scan to complete with timeout and progress reporting

Args:
    scan_id: The ID of the scan to wait for
    timeout: Maximum time to wait in seconds (default: 300 = 5 minutes)
    poll_interval: How often to check scan status in seconds (default: 5)
    include_progress: Whether to include progress updates in the response (default: True)

- **get_dependency_info** — Get information about dependency management in bbot scans

## 安装

### 方式一:从 GitHub 直接安装(推荐)

```bash
# 格式: dsh plugin --profile <profile> add github:<owner>/<repo>
dsh plugin --profile web add github:xby_skill/xby-bbot
```

### 方式二:从本地目录安装(开发模式)

```bash
# 仅用于本地开发调试
dsh plugin --profile web add /absolute/path/to/xby-bbot
```

### 方式三:通过 cordis.patch.yml 开发调试

```bash
dsh web --profile web --patch /absolute/path/to/dsh-ocr-plugin/cordis.patch.yml
```



## 配置

### 获取 API 密钥

前往 [小笨羊官网](https://xiaobenyang.com) 注册并获取 API 密钥。

Install

dsh plugin --profile web add github:xby-skill/xby-bbot

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source