kali-security-bridge
Related Servers
Alternatives to kali-security-bridge
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityCmaintenanceMCP server for security analysis, reverse engineering, and penetration testing, providing 70+ tools (nmap, sqlmap, hydra, frida, etc.) with configurable backends (Docker Kali, WSL, SSH).-
- AlicenseNot gradedqualityNot gradedmaintenanceA Kali Linux-based MCP server that exposes over 45 penetration testing tools for AI-assisted security auditing and vulnerability scanning. It features strict scope enforcement, structured output parsing, and persistent finding storage to automate the offensive security workflow.MIT
- FlicenseNot gradedqualityCmaintenanceA Docker-based MCP server exposing a curated set of Kali Linux security tools for authorized, hands-on network scanning on private ranges, with enforced trustworthiness and honest output.-
- AlicenseNot gradedqualityBmaintenanceMCP server providing Kali Linux security tools for authorized penetration testing, with tiered tool sets for network scanning, web testing, and more, run via Docker stdio.1MIT
- FlicenseNot gradedqualityDmaintenanceA Dockerized Kali Linux MCP server that enables LLMs to perform network security scans, penetration testing, and reconnaissance using tools like Nmap, Nikto, Hydra, and SQLMap.13 npm-
- FlicenseNot gradedqualityCmaintenanceA penetration testing MCP server that runs 20 hacking tools inside a Kali Linux Docker container, enabling AI assistants to execute security scans and attacks via natural language.2-
TDQS
Scored across 25 tools
Most tools are clearly differentiated by scanner/tool name (nmap, subfinder, nikto, sqlmap, etc.) and phase (recon, scanning, evidence). The main confusion points are scan_diretorios_gobuster vs scan_fuzzing_ffuf and scan_vulnerabilidades_nikto vs scan_nuclei, but descriptions state when each should be used.
All names use lowercase snake_case and generally follow an action_object_tool pattern (scan_portas_nmap, enum_subdominios_subfinder). The main inconsistency is the scan_ prefix appearing on some tools but not on other action-first names like brute_force_hydra, screenshot_gowitness, or fazer_requisicao_http.
25 tools is at the threshold where the set starts to feel heavy. While a pentest suite justifies many specialized scanners, several tools overlap in function (directory enumeration, generic web vulnerability scanning), so the count is not as lean as it could be.
The set covers the full lifecycle from authorization and recon through scanning, evidence collection, findings listing, and report generation, plus session resume. Minor gaps exist around triage/management of findings (no update/delete or false-positive marking), but core pentest workflows are well covered.