SecForge
Provides tools for executing security tools inside a self-built Kali Docker container and managing container/image lifecycle for security scanning and exploitation workflows.
Allows AI agents to invoke Metasploit payloads and msfconsole within the Kali container for exploitation and post-exploitation tasks.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@SecForgescan 192.168.10.1 with nmap and map findings to CVEs"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
SecForge
工具箱里的安全全家桶 —— 5000+ 工具索引 · 59000+ 漏洞库 · AI 编排 · 自建 Kali 镜像 · 原生 macOS 界面
把扫描 / 攻击 / 防御 / 漏洞研究要用的东西塞进一个盒子, 让 AI 帮你调用它们,界面是一个真正的原生 App(不是浏览器套壳)。
English TL;DR — SecForge is a self-hosted security toolkit: it indexes 5,000+ GitHub security tools, ships a 59,000-CVE local database (MSRC + CISA KEV + ExploitDB + NVD), builds its own Kali Docker image, exposes 21 MCP tools to any AI agent, and drives everything from a native macOS app (Swift/SwiftUI — no Electron, no browser). Bring your own LLM API key. Authorized targets only.
⚠️ 使用声明
仅限合法用途:你自己的资产,或你持有书面授权的目标。禁止用于任何未授权的攻击行为。
未经授权扫描、入侵、窃取数据,或对政府 / 教育 / 医疗 / 金融等关键信息基础设施做任何探测, 在中国大陆由《刑法》第 285 / 286 条、《网络安全法》第 27 条规制 —— 后果是刑事责任与民事赔偿。
护栏已写进代码(政府 / 教育 / 军方域名直接拒绝,换任何 AI 大脑都绕不过去), 但真正的边界在你自己的判断里。
📄 完整条款:USAGE-POLICY.md
Related MCP server: Hercules MCP
它解决什么问题
想认真学安全,你得先干这些事:装 Kali(或者 40 个工具各自装)、到处找工具、 翻十几个网站查漏洞、还得记住一堆参数。真开始干活了又是一堆手工步骤。
SecForge 把这些压成三层:
① 工具库 爬 GitHub 78 个安全 topic + 20 组关键词搜索 → 过滤噪音 → 本地 SQLite 索引
② 漏洞库 微软 MSRC + CISA KEV + ExploitDB + NVD 年度 feed → 统一到一张表
③ 执行层 自建 Kali 镜像(Dockerfile 由工具库自动生成)+ AI 编排 + 原生界面核心是第 ③ 层:你对着界面说「扫一下 192.168.10.1,把开放的服务和已知漏洞对应起来」, AI 自己决定调哪个工具、传什么参数、拿结果去查漏洞库、最后给你结论。你不用记参数。
实测数据(不是估算,是库里真实的)
数量 | 说明 | |
GitHub 安全工具 | 5,266 | 从 8,446 个仓库里过滤掉噪音/清单,15 个分类 |
参考清单 | 710 | awesome-list / cheat-sheet 类,单独归类 |
CVE 漏洞库 | 59,876 | 其中 56,967 条有 CVSS 评分 |
已被真实利用(CISA KEV) | 1,729 | 标记 🔥,优先看这些 |
有公开 PoC | 25,086 | 标记 💥,附 ExploitDB 编号 |
带补丁号(KB) | 9,070 | 直接告诉你打哪个补丁 |
受影响产品条目 | 253,921 | 按产品反查漏洞用 |
Windows 版本覆盖 | 27 个 | Win11 各代 / Win10 全分支 / Server / 8.1 / 7 SP1 |
Kali 镜像 | 2,091 个包 | 21.3GB,含 Metasploit 2604 个载荷 |
MCP 工具 | 21 个 | 任何支持 MCP 的 AI 都能直接用 |
原生 App | 1.2MB | Mach-O arm64 真二进制 |
Windows 版本能查到什么(真实输出):
Windows 7 SP1 → 2,078 个 CVE,头一个是 CVE-2019-0708 BlueKeep (CVSS 9.8)
Windows 8.1 → 2,360 个 CVE,含 CVE-2017-0143 永恒之蓝
Windows Server 2019 → 5,775 个 CVE,头一个是 CVE-2020-1472 Zerologon (CVSS 10.0)
Windows 10 22H2 → 3,072 个 CVE,706 个补丁 KB 号
Windows 11 24H2 → 2,412 个 CVE界面
两个前端,都真实可用:
位置 | 说明 | |
原生版 |
| Swift + SwiftUI 写的真 macOS 程序。没有 HTML、没有浏览器、没有 Python 后端:SQLite 由 Swift 直接读,docker 直接调。1.2MB |
网页版 |
| Python 标准库 HTTP 服务 + 单页 HTML,方便改 |
原生版页签:总览 / 工具库 / 漏洞库 / Windows 漏洞 / 扫描 / 问 AI(双大脑) / 容器与镜像。 深色 + 军绿 + 战术橙,全原生控件,跟随系统深浅色。
构建原生版:
cd native && ./build.sh # 编译 + 打包 + ad-hoc 签名 → /Applications/SecForge.app
file /Applications/SecForge.app/Contents/MacOS/SecForge
# → Mach-O 64-bit executable arm64 (不是 shell script,不是网页壳)启动用
open /Applications/SecForge.app。open -a /Applications/SecForge.app是不行的 ——-a后面要跟 App 名字不是路径。
接进 AI(自带 key)
本仓库不带任何模型密钥,也不会代替你调用任何模型 —— AI 部分你自己部署、自己配 key。 不配也能用,只是「问 AI」页签的 DeepSeek 大脑不可用,其余全部功能(工具库、漏洞库、 扫描、关联分析)都正常。
cp .env.example .env
# 打开 .env 填上你自己的 key(申请:https://platform.deepseek.com/api_keys)
DEEPSEEK_API_KEY=sk-你的keyui/deepseek_agent.py 里写的是 DeepSeek 的 OpenAI 兼容接口。换别家(本地
Ollama / vLLM、通义、Moonshot、OpenAI 官方……)只改文件顶部两个常量即可。
双大脑设计 —— 同一批工具,两个控制器:
大脑 | 怎么跑 | 权限 | 特点 |
DeepSeek 直连 | 直接调 API,自己跑工具循环 | 只能动容器 | 快;每次工具调用都显示给你看;不需要装别的 |
Hermes 真身(可选) | 调本机 Hermes Agent | 全权限 | 有跨会话记忆和技能库;危险命令会弹审批 |
两个大脑共用同一个 Kali 容器、同一份漏洞库、同一批工具,所以可以同时开着轮流使唤。 工具 schema 是从函数签名和 docstring 自动生成的 —— 加新工具不用改大脑那边的代码。
任何 MCP 客户端都能接(Claude Desktop / Cursor / 自己的 agent):
hermes config set mcp_servers.secforge.command /path/to/secforge/.venv/bin/python
hermes config set mcp_servers.secforge.args '["/path/to/secforge/mcp/server.py"]'☠️ 合法使用
这个工具只允许用于你自己拥有的设备、你自己搭的靶场、或者你拿到书面授权的目标。 完整条款见 USAGE-POLICY.md。
这不是免责声明里凑字数的一句 —— 它写在代码里:
# mcp/server.py
BLOCKED_TLDS = (".gov", ".gov.cn", ".edu", ".edu.cn", ".mil", ".ac.cn", ...)
def guard(target):
"""返回空串表示放行, 否则返回拒绝原因"""政府、教育、军方域名会被直接拒绝,换哪个 AI 大脑都绕不过去(护栏长在工具上,不在大脑上)。 腾讯等厂商的客户端反外挂条款、以及《刑法》第 285/286 条,都不是「我就试试」级别的后果。
护栏之外,AI 能调什么也被限死了。给 AI 的工具名要过三道关:
# mcp/server.py
① 名字形态 只允许字母开头的工具名 —— 塞不进"一整串命令"
② 不是通用执行器 sh/bash/python/curl/wget/nc/rm/... 一律拒绝
③ 容器里真存在 只允许调容器里实际装了的可执行文件所以 AI 只能调 nmap、nuclei、sqlmap 这些真工具,不能直接叫 bash 去干活。
要跑任意命令的通道只留给人:secforge sh 或 docker exec -it secforge bash。
(工具参数同样不过 shell:args 会被切成 argv 以 argv 形式交给工具。)
诚实的边界:这不等于「AI 绝不可能在容器里执行任意代码」——
nmap --script、sqlmap --os-shell、msfconsole -x本身就是命令执行引擎, 那是它们的设计功能,不是绕过。这道关挡住的是最省事的那条路。 真正的隔离靠的是容器本身够不着宿主机:没有 docker socket、没有挂宿主目录。
建议的练习靶场(全部合法):
靶场 | 怎么起 |
OWASP Juice Shop |
|
DVWA |
|
vulhub | vulhub.org —— 一堆现成漏洞环境 |
Metasploitable / HackTheBox / TryHackMe | 专门的「生来被打」的靶机 |
快速开始
需要:macOS(或 Linux)、Docker、Python 3.11+、约 30GB 磁盘。 Windows 用户请用 WSL2。
git clone https://github.com/kangyx-2024/secforge.git
cd secforge
python3 -m venv .venv && .venv/bin/pip install -r requirements.txt
cp .env.example .env # 可选:填 AI key第一步:拿数据(仓库里不含数据库,127MB 超过 GitHub 单文件上限)
scripts/fetch_data.sh # 优先从 Release 下载现成的库;没有就自己构建自己构建(需要 gh CLI 已登录,因为 GitHub 搜索 API 有速率限制):
# 工具库:爬 GitHub → 过滤噪音(约 30-60 分钟)
.venv/bin/python catalog/scrape_github.py --pages 2 --min-stars 30
.venv/bin/python catalog/refine_catalog.py
# 漏洞库:MSRC + KEV + ExploitDB(约 1-2 小时)
.venv/bin/python vulndb/build_vulndb.py --from 2016-Jan
# 补 CVSS 评分(下 NVD 年度 feed,约 20 分钟)
.venv/bin/python vulndb/fill_cvss_nvd.py第二步:建 Kali 镜像(Dockerfile 由工具库自动生成,约 20-40 分钟)
.venv/bin/python image/build_image.py # → secforge/kali:standard(21.3GB / 2091 包)
docker run -d --name secforge --cap-add NET_ADMIN --cap-add NET_RAW \
-v secforge_work:/work -v secforge_loot:/loot secforge/kali:standard镜像是你自己在本机从上游软件源构建的。本仓库只提供 Dockerfile 生成器, 不打包、不再分发任何第三方二进制 —— 各工具仍受其原始许可证约束。
第三步:开界面
cd native && ./build.sh # 原生 App(推荐)
# 或
ui/启动SecForge.command # 网页版第四步(可选):每天自动更新漏洞库
.venv/bin/python vulndb/update_daily.py # 增量拉 NVD modified feed + KEV + 当月 MSRC
# 加进 crontab 就是每天自动更新,实测一次能补 8000+ 条架构
secforge/
├── catalog/ GitHub 爬虫 + 目录精炼 → catalog.sqlite(工具库)
├── vulndb/ MSRC + KEV + ExploitDB + NVD → vulndb.sqlite(漏洞库)
│ ├── build_vulndb.py 全量构建
│ ├── fill_cvss_nvd.py 补 CVSS / severity / CWE
│ └── update_daily.py 每日增量
├── image/ Dockerfile 生成器 + 镜像构建 → secforge/kali:standard
├── mcp/ MCP 服务器(21 个工具,stdio) → 给任何 AI 用
├── ui/ 网页版界面 + DeepSeek 直连大脑
├── native/ 原生 macOS App(Swift + SwiftUI)
└── secforge.py 命令行入口关键设计:AI 大脑不直接碰工具,中间隔一层 MCP/函数调用。所以 (a)换大脑不用改工具,(b)护栏写在工具里,换大脑绕不过去。
常见问题
Q:为什么不直接把数据库放进仓库?
A:vulndb.sqlite 127MB,GitHub 单文件硬上限 100MB。用 scripts/fetch_data.sh 下载
Release 附件,或者按上面自己构建。
Q:能不能不装 AI 只用工具库和漏洞库? A:可以。工具库、漏洞库、Windows 版本查询、扫描执行都不依赖 AI。
Q:支持 Windows / Linux 吗? A:扫描和漏洞库是跨平台的(Python);原生 App 目前是 macOS。 Linux 用网页版界面,Windows 用 WSL2。
Q:为什么只支持 DeepSeek?
A:不限。ui/deepseek_agent.py 用的是 OpenAI 兼容格式,改成你本地 Ollama 或者
任何 OpenAI 兼容服务只改两个常量。默认给 DeepSeek 是因为它便宜、函数调用稳定。
Q:跟 PentAGI / Nuclei / 其他 AI 渗透工具什么关系? A:互补。SecForge 的定位是本地索引 + 编排层:它不重写任何扫描器,而是把已有的 几千个工具和 6 万条漏洞整理成 AI 能用的形式。你也可以只把它的 MCP 服务器接到 你自己的 agent 上。
数据来源与致谢
工具索引:GitHub Search API(78 个安全 topic + 20 组关键词)
漏洞数据:Microsoft MSRC CVRF、CISA KEV、ExploitDB、NIST NVD
所有实际工具:归各自上游项目所有(nmap / Metasploit / nuclei / sqlmap / hydra / ...)
SecForge 只做编排,不重造轮子。
License
MIT —— 见 LICENSE。 使用前请读 USAGE-POLICY.md(可接受使用政策)。 本软件仅限用于合法的网络安全工作:你自己的资产,或你持有书面授权的目标。
This server cannot be deployed
Maintenance
Related MCP Connectors
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Find, vet, and run MCP tools through a secure audited gateway with prompt-injection risk scoring
Related MCP Servers
- FlicenseAqualityDmaintenanceEnables AI assistants to perform authorized penetration testing and security assessments by exposing 20+ Kali Linux security tools (nmap, sqlmap, gobuster, hydra, etc.) through a safe, validated interface with command allowlists, rate limiting, and input sanitization.191-
- AlicenseAqualityBmaintenanceEnables AI agents to perform professional penetration testing through a containerized Kali Linux environment, exposing industry-standard offensive security tools as structured MCP tools.454MIT
- FlicenseNot gradedqualityDmaintenanceExposes a hardened Docker container with Kali Linux security tools (nmap, sqlmap, dig, whois, etc.) as MCP tools, enabling network reconnaissance, web analysis, and vulnerability scanning through natural language commands.-
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to invoke 100+ pre-installed penetration testing tools (e.g., nmap, nuclei, sqlmap) inside a Dockerized Kali Linux environment via MCP, supporting single-turn execution for reconnaissance, scanning, exploitation, and security assessment.1,031 npmMIT