Best Metasploit MCP Servers
Metasploit is a penetration testing framework that makes discovering, exploiting, and sharing vulnerabilities quick and relatively painless. It's maintained by the security company Rapid7 and widely used by security professionals for security testing.
Why this server?
Enables execution of Metasploit modules for exploitation tasks via the 'metasploit_exec' tool.
AlicenseAqualityDmaintenanceEnables AI assistants to execute security testing tools on a Kali Linux machine over SSH, including reconnaissance, web app scanning, and static/dynamic analysis.116 npmMITWhy this server?
Allows the use of the Metasploit Framework for security assessments and exploit development.
AlicenseAqualityDmaintenanceProvides an MCP interface to a full Kali Linux environment running in Docker, enabling AI assistants to execute security tools like nmap, sqlmap, and metasploit. It allows users to start/stop the container, run shell commands, and transfer files for security testing and educational purposes.76 npm5MITWhy this server?
Provides tools for interacting with the Metasploit Framework, including running msfconsole commands, generating payloads with msfvenom, searching and viewing module info, and executing resource scripts.
AlicenseAqualityBmaintenanceEnables AI applications to invoke 58 popular Kali Linux security tools for network scanning, web exploitation, password attacks, reconnaissance, Metasploit, evasion, forensics, post-exploitation, and miscellaneous tasks through the Model Context Protocol.593MITWhy this server?
Provides tools for interacting with Metasploit Framework, including searching exploits and auxiliary modules, retrieving exploit details and payloads, managing database workspaces, viewing hosts and services, and running nmap scans with automatic result import.
AlicenseBqualityDmaintenanceEnables interaction with Metasploit Framework for authorized security testing, including exploit searches, payload management, network scanning with nmap, and database operations for penetration testing workflows.9MITWhy this server?
Allows interaction with the Metasploit exploitation framework via structured handoff, enabling AI agents to pass C2 state (listeners, beacons, sessions) between systems for coordinated adversary emulation operations.
AlicenseBqualityCmaintenanceA Model Context Protocol server for the Sliver C2 framework that exposes operator tools like listeners, implant generation, sessions, command execution, and file operations for LLM-driven adversary emulation.371MITWhy this server?
Enables searching and counting exploits from Shodan's exploit database, which includes Metasploit modules, for vulnerability research.
AlicenseBqualityFmaintenanceProvides access to Shodan's IoT search engine API for device search, host intelligence, exploit database, network scanning, and security analysis through natural language.32MITWhy this server?
Checks for available exploits in the Metasploit framework as part of the exploit availability assessment tool.
AlicenseAqualityDmaintenanceA Model Context Protocol server providing security vulnerability intelligence tools including CVE lookup, EPSS scoring, CVSS calculation, exploit detection, and Python package vulnerability checking.89MITWhy this server?
Provides packaged Metasploit modules for CVEs, including reliability rank and run strings, to support exploitation testing and defensive triage.
AlicenseAqualityBmaintenanceEnables LLMs to access realtime CVE intelligence aggregated from NVD, CISA KEV, EPSS, GitHub advisories, PoC discovery, and Metasploit/Nuclei tooling, providing vulnerability details, exploitation signals, and prioritized triage verdicts.12MITWhy this server?
Provides access to Metasploit exploit modules, including details on usage, targets, and source URLs. Allows querying exploits specifically from the Metasploit framework.
AlicenseAqualityAmaintenanceGives AI assistants access to the Exploit Intelligence Platform for vulnerability and exploit intelligence. Supports searching CVEs, exploits, and generating pentest findings.1792 PyPIMIT