kali-mcp
kali-mcp is a comprehensive AI-driven penetration testing platform that exposes over 120 MCP tools wrapping 27+ Kali Linux security tools, enabling autonomous or guided offensive security engagements from reconnaissance through exploitation and reporting. Its capabilities include:
Network Scanning & Discovery: Nmap scans (host discovery, port/service/OS detection, vulnerability, aggressive), fast masscan+nmap combinations, netcat port checks, and banner grabbing.
Reconnaissance & OSINT: Subdomain enumeration (subfinder, Amass, gobuster DNS), OSINT gathering (theHarvester), WHOIS/DNS lookups (dig, zone transfers), and continuous recon sweeps with asset change detection.
Web Application Testing: Vulnerability scanning (Nikto, Nuclei, WPScan), directory/vhost/file brute-forcing (gobuster, ffuf), crawling, HTTP request crafting, form submission, link/text extraction, and visual screenshots (gowitness).
Exploitation & Post-Exploitation: SQL injection (sqlmap), password brute-forcing (Hydra), Metasploit integration (search, run, msfvenom payload generation), exploit searching (searchsploit, CVE-to-exploit mapping), automated scan-to-exploit chains, SSH command execution, privilege escalation enumeration, and SMB/Windows enumeration (enum4linux, smbclient).
Traffic Analysis: PCAP credential extraction, protocol hierarchy analysis, and tshark queries.
AI-Optimized Workflows: Parallel multi-tool scans (scan_host, scan_web), intelligent finding triage with attack path analysis, and correlation of findings into compound attack chains.
Engagement & Asset Management: Full engagement lifecycle, scoping with allow/deny targets, persistent asset inventory, and scan-to-scan asset diffing.
Credential Management: Encrypted vault for storing, listing, reusing, and deleting discovered credentials.
Reporting & Validation: Automated report generation (Markdown/HTML) with attack chains and remediation advice, structured finding extraction, and a validation workflow to confirm or dismiss findings.
Job & System Management: Asynchronous job handling (submit, status, output, cancel), server health checks, file artifact management, and runtime scope enforcement.
This platform fully automates the penetration testing lifecycle, transforming any MCP-capable AI into a powerful offensive security assistant.
Provides tools for running Kali Linux security tools, enabling AI agents to perform penetration testing, vulnerability scanning, and attack chain analysis on authorized targets.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@kali-mcpScan 10.10.10.5 and tell me what's worth attacking."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
๐ kali-mcp
Your AI, holding a full Kali Linux toolkit.
kali-mcp turns any MCP-compatible AI assistant into a hands-on penetration testing partner โ it drives 27+ real Kali security tools through 123 AI-callable actions, and hands the AI clean, verified, structured findings instead of raw terminal noise.
123 MCP tools ยท 27+ Kali binaries ยท autonomous hunt mode ยท verification oracles + interactsh OOB + IDOR/access-control + race & secrets scanners ยท 7 attack-chain templates ยท ~450 tests
Quick Start ยท Documentation ยท Tool Reference
You: "Scan 10.10.10.5 and tell me what's worth attacking."
AI: โ scan_host("10.10.10.5")
โ open ports 22, 80, 445 โ fans out nikto + gobuster + nuclei + enum4linux in parallel
โ 14 findings extracted, verified, and deduplicated
โ attack chain found: Exposed .git โ leaked creds โ Admin Panel
โ next moves suggested: hydra on SSH, sqlmap on the login formYou describe intent. The AI drives the tools. kali-mcp makes the results trustworthy.
โจ Why kali-mcp
๐ง Structured, not raw. Every scan result becomes a clean finding (
host,severity,confidence,evidence) โ never a wall of terminal text. โ The Finding Pipeline๐ฏ Low false positives. Findings are actively re-verified (soft-404 baselines, catch-all clustering,
.git/.envcontent proof), evidence-anchored, and cross-tool corroborated. The AI can't inflate what the tools didn't prove. โ False-Positive Reduction๐ Impact, not just bugs. Individual findings are correlated into named attack chains with ready-to-paste narratives. โ Attack Chains
๐ฐ๏ธ Change detection. Passive recon sweeps diff against previous runs and surface newly exposed assets โ where the bounties are. โ Continuous Recon
๐๏ธ Memory. A persistent asset inventory and full engagement lifecycle, from scope to client-ready report. โ Engagements
๐ Safety-first. stdio-only (no exposed network), scope allow/deny enforcement, argument-injection guards, an encrypted credential vault, and a full audit log. โ Security Model
Related MCP server: MCP Kali Server
๐ Quick Start
# 1. Clone & install
git clone https://github.com/Neeraj829784/kali-mcp.git
cd kali-mcp
python3 -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
# 2. Verify
python3 -c "from server import mcp; print('Ready')"Then point your AI client at it:
{
"mcpServers": {
"kali-mcp": {
"command": "/path/to/kali-mcp/.venv/bin/python",
"args": ["/path/to/kali-mcp/server.py"]
}
}
}Ask it to run server_health() to confirm the tools are installed, then
scan_host("<your-authorized-target>").
Full setup โ including the security tools kali-mcp drives โ is in the Installation guide.
๐ Documentation
Everything lives in docs/:
Start here | Concepts | Scope & assets | Reference |
โ๏ธ Responsible use
kali-mcp runs real offensive tooling. Only test systems you own or are explicitly authorized to test. Use programs to encode your authorization boundary and stay inside it. You are responsible for how you use this tool.
๐ License
MIT โ see LICENSE.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-quality-maintenanceEnables AI assistants to execute penetration testing commands and security tools on Kali Linux remotely. Supports automated reconnaissance, vulnerability scanning, and CTF solving through integration with 25+ offensive security tools like nmap, gobuster, and nuclei.16
- Flicense-qualityDmaintenanceConnects AI assistants to 55+ Kali Linux security tools for automated CTF solving, penetration testing, and security analysis across 7 categories including cryptography, forensics, web security, and binary exploitation.48
- Alicense-qualityDmaintenanceEnables AI assistants to perform penetration testing and security assessments by exposing 60+ Kali Linux security tools including network scanning, web security testing, password cracking, exploitation frameworks, and OSINT capabilities through an AI-friendly interface.2MIT
- FlicenseAqualityDmaintenanceEnables AI assistants to perform authorized penetration testing and security assessments by exposing 20+ Kali Linux security tools (nmap, sqlmap, gobuster, hydra, etc.) through a safe, validated interface with command allowlists, rate limiting, and input sanitization.191
Related MCP Connectors
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Operate your Linux servers from your LLM. Every action runs through an auditable allowlist.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Neeraj829784/kali-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server