Back to Browse

Hacktricks MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Offline full-text search over the HackTricks security wiki, synced every 3 days.

About

Offline full-text search over the HackTricks security wiki, synced every 3 days.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (3 strong, 3 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

10 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-zebbern-hacktricks-mcp": {
      "args": [
        "-y",
        "@zebbern/hacktricks-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

hacktricks-mcp

MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.

Unlike grep-based alternatives, this server ships with a pre-built SQLite FTS5 search index (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream every 3 days and commits it back to this repo.

Quick start

Requirements: Node.js 22.13 or newer (uses the built-in node:sqlite, zero native dependencies).

Claude Code:

claude mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Codex CLI:

codex mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Any MCP client (Claude Desktop, Cursor, Kimi, etc.), config JSON:

{
  "mcpServers": {
    "hacktricks": {
      "command": "npx",
      "args": ["-y", "@zebbern/hacktricks-mcp"]
    }
  }
}

As a plugin (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (.claude-plugin/), Codex (.codex-plugin/) and Kimi (kimi-plugin/). Add it from your client's plugin marketplace flow pointing at zebbern/hacktricks-mcp, or for Kimi Work use this plugin link.

Then ask things like:

  • "Search HackTricks for kerberoast and give me the attack commands"
  • "How do I escalate privileges from the lxd group?"
  • "Show me the SSRF section of the pentesting-web pages"

Tools at a glance

ToolWhat it does
hacktricks_searchRanked full-text search with snippets, category filter and abbreviation handling (privesc, sqli, rce, ...)
hacktricks_get_pageRead a page, a single section, or just its code blocks
hacktricks_get_tocThe wiki category tree, so agents can see where topics live

All tools are strictly read-only. Full reference: docs/tools.md.

Documentation

Security and legal

  • The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
  • HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
  • Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).

Credits

Reviews

No reviews yet

Be the first to review this server!