SkillAgentSearch skills...

hacktricks-mcp

MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.

Install / Use

npx skills add zebbern/hacktricks-mcp

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

74/100

Category

Security

Supported Platforms

Universal

Our assessment of hacktricks-mcp

hacktricks-mcp scores 74/100 on our quality scale, 1046th of 1,121 Security skills we index.

Its SKILL.md is 2.9 KB long, split into 6 sections with 3 code examples: a solid amount of guidance for an agent.

It has 2 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
26/30
Structure
16/20
Description
15/15
Adoption
2/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated yesterday, so hacktricks-mcp is actively maintained.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

hacktricks-mcp compared with similar skills

All 4 of these similar skills score higher than hacktricks-mcp; compare them before choosing.

SkillScoreStarsUpdatedFormat
hacktricks-mcp (this skill)by zebbern7421d agoSKILL.md
Agent-Reachby Panniantong10093.9ktodayCLAUDE.md
headroomby headroomlabs-ai10074.7ktodayCLAUDE.md
CowAgentby zhayujie10047.3ktodayCLAUDE.md
Scraplingby D4Vinci10086.3ktodayMCP Server

Frequently asked questions

How do I install hacktricks-mcp?
Run npx skills add zebbern/hacktricks-mcp. The install tabs above show the steps for each supported agent.
Which AI agents does hacktricks-mcp work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is hacktricks-mcp safe to use?
It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is hacktricks-mcp still maintained?
The repository was last updated yesterday, so hacktricks-mcp is actively maintained.

hacktricks-mcp

MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.

Unlike grep-based alternatives, this server ships with a pre-built SQLite FTS5 search index (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream every 3 days and commits it back to this repo.

Quick start

Requirements: Node.js 22.13 or newer (uses the built-in node:sqlite, zero native dependencies).

Claude Code:

claude mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Codex CLI:

codex mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Any MCP client (Claude Desktop, Cursor, Kimi, etc.), config JSON:

{
  "mcpServers": {
    "hacktricks": {
      "command": "npx",
      "args": ["-y", "@zebbern/hacktricks-mcp"]
    }
  }
}

As a plugin (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (.claude-plugin/), Codex (.codex-plugin/) and Kimi (kimi-plugin/). Add it from your client's plugin marketplace flow pointing at zebbern/hacktricks-mcp, or for Kimi Work use this plugin link.

Then ask things like:

  • "Search HackTricks for kerberoast and give me the attack commands"
  • "How do I escalate privileges from the lxd group?"
  • "Show me the SSRF section of the pentesting-web pages"

Tools at a glance

| Tool | What it does | |---|---| | hacktricks_search | Ranked full-text search with snippets, category filter and abbreviation handling (privesc, sqli, rce, ...) | | hacktricks_get_page | Read a page, a single section, or just its code blocks | | hacktricks_get_toc | The wiki category tree, so agents can see where topics live |

All tools are strictly read-only. Full reference: docs/tools.md.

Documentation

Security and legal

  • The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
  • HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
  • Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).

Credits

Related Skills

View on GitHub
GitHub Stars2
CategorySecurity
Updated1d ago
Forks0

Languages

TypeScript

Trust signals

80/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 medium1 low