Hercules MCP
Related Servers
Alternatives to Hercules MCP
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to invoke 100+ pre-installed penetration testing tools (e.g., nmap, nuclei, sqlmap) inside a Dockerized Kali Linux environment via MCP, supporting single-turn execution for reconnaissance, scanning, exploitation, and security assessment.1,243 npmMIT
- FlicenseNot gradedqualityDmaintenanceEnables LLMs to execute Kali Linux security tools like nmap, sqlmap, and hydra in a secure, sandboxed environment. Provides both MCP and HTTP API interfaces for penetration testing and security assessment tasks.-
- AlicenseNot gradedqualityDmaintenanceProvides a containerized Kali Linux environment that gives AI assistants access to a comprehensive suite of security and penetration testing tools. It enables automated vulnerability scanning, network reconnaissance, and secure command execution through the Model Context Protocol.25MIT
- FlicenseNot gradedqualityBmaintenanceProduction-grade MCP server that exposes Kali Linux penetration testing tools to AI agents, enabling automated reconnaissance, web application testing, vulnerability assessment, and more.-
- AlicenseNot gradedqualityCmaintenanceEnables LLM-driven security assessments by exposing Kali tools like nmap, httpx, sqlmap, and ffuf as MCP tools, with explicit planning, parallel tool calls, tiered memory, MITRE ATT&CK mapping, and human approval gates for intrusive operations.2MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to orchestrate 100+ security tools over MCP for authorized penetration testing, including recon, scanning, exploitation, attack-chain planning, and knowledge-base retrieval.5Apache 2.0
TDQS
Scored across 45 tools
Most tools are clearly distinguishable by their domain prefixes (system_, nmap_, metasploit_, browser_) and specific action verbs. The only potential confusion is between web_scan and web_vuln_scan, but the descriptions clarify that one is for fingerprinting and the other for vulnerability scanning, so an agent can reliably separate them.
All tool names follow a consistent lowercase snake_case convention with a <domain>_<action> pattern, such as nmap_scan, metasploit_search, shell_kill_job, and browser_open. There are no mixed naming styles or deviations, making the naming highly predictable.
With 45 tools, this server is well above the typical 3-15 tool range and qualifies as 'too many' per the calibration. While each tool has a distinct purpose, the large number (especially 10 browser_* tools and 4 shell_* job tools) creates a heavy surface that could overwhelm agents and increases selection complexity.
The server covers the core penetration testing lifecycle comprehensively: recon, scanning, exploitation, post-exploitation, web app testing, and browser automation. Minor gaps exist, such as no workspace_list_files or workspace_delete_file, and no dedicated packet capture tool, but shell_exec provides a viable workaround for these missing operations.