hacktricks-mcp
MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.
Install / Use
npx skills add zebbern/hacktricks-mcpInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of hacktricks-mcp
hacktricks-mcp scores 74/100 on our quality scale, 1046th of 1,121 Security skills we index.
Its SKILL.md is 2.9 KB long, split into 6 sections with 3 code examples: a solid amount of guidance for an agent.
It has 2 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated yesterday, so hacktricks-mcp is actively maintained.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hacktricks-mcp compared with similar skills
All 4 of these similar skills score higher than hacktricks-mcp; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hacktricks-mcp (this skill)by zebbern | 74 | 2 | 1d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 93.9k | today | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.7k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 86.3k | today | MCP Server |
Frequently asked questions
- How do I install hacktricks-mcp?
- Run
npx skills add zebbern/hacktricks-mcp. The install tabs above show the steps for each supported agent. - Which AI agents does hacktricks-mcp work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hacktricks-mcp safe to use?
- It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hacktricks-mcp still maintained?
- The repository was last updated yesterday, so hacktricks-mcp is actively maintained.
Skill content
View source on GitHubhacktricks-mcp
MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.
Unlike grep-based alternatives, this server ships with a pre-built SQLite FTS5 search index (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream every 3 days and commits it back to this repo.
Quick start
Requirements: Node.js 22.13 or newer (uses the built-in node:sqlite, zero native dependencies).
Claude Code:
claude mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp
Codex CLI:
codex mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp
Any MCP client (Claude Desktop, Cursor, Kimi, etc.), config JSON:
{
"mcpServers": {
"hacktricks": {
"command": "npx",
"args": ["-y", "@zebbern/hacktricks-mcp"]
}
}
}
As a plugin (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (.claude-plugin/), Codex (.codex-plugin/) and Kimi (kimi-plugin/). Add it from your client's plugin marketplace flow pointing at zebbern/hacktricks-mcp, or for Kimi Work use this plugin link.
Then ask things like:
- "Search HackTricks for kerberoast and give me the attack commands"
- "How do I escalate privileges from the lxd group?"
- "Show me the SSRF section of the pentesting-web pages"
Tools at a glance
| Tool | What it does |
|---|---|
| hacktricks_search | Ranked full-text search with snippets, category filter and abbreviation handling (privesc, sqli, rce, ...) |
| hacktricks_get_page | Read a page, a single section, or just its code blocks |
| hacktricks_get_toc | The wiki category tree, so agents can see where topics live |
All tools are strictly read-only. Full reference: docs/tools.md.
Documentation
- docs/tools.md: complete tool reference with parameters and examples
- docs/architecture.md: how the index and the 3-day sync work
- docs/development.md: local setup, tests, releasing
- docs/agents.md: agent skill, MCP registry and plugin packaging
Security and legal
- The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
- HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
- Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).
Credits
- HackTricks by Carlos Polop and contributors
- Model Context Protocol SDK
Related Skills
Agent-Reach
93.9kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.7kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
86.3k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
