mcp-kali-tools
by rdriver001
README.md
# mcp-kali-tools
A Docker image that runs a [Model Context Protocol](https://modelcontextprotocol.io) server
exposing common Kali Linux pentesting tools to an MCP client (e.g. Claude Desktop). Each tool
runs as its own MCP tool call, executed directly as `argv` (no shell), so arguments can't be
used to chain or inject arbitrary shell commands — but each tool still has the full power of
its underlying binary.
> **Authorized use only.** This bundles offensive security tooling (nmap, sqlmap, hydra,
> Metasploit, etc.). Only point it at systems and networks you're authorized to test.
## Tools included
`nmap`, `sqlmap`, `nikto`, `hydra`, `john`, `hashcat`, `msfconsole`, `gobuster`, `ffuf`,
`whatweb`, `wpscan`, `aircrack-ng`, `searchsploit`
`aircrack-ng` can crack existing capture files, but live wireless capture (monitor mode) needs
a physical adapter passed through to the container (`--device`, `--net=host`), which isn't set
up by default.
## Build
```
docker build -t mcp-kali-tools:latest .
```
## Run manually (for testing)
The server speaks MCP over stdio — it's not meant to be left running standalone. To smoke-test
it, pipe JSON-RPC requests in directly:
```
docker run -i --rm mcp-kali-tools:latest
```
## Configure in Claude Desktop
Create a host directory for wordlists/scan output to persist across runs, e.g.:
```
mkdir -p ~/mcp-data
```
Add this to `mcpServers` in your `claude_desktop_config.json`:
```json
{
"mcpServers": {
"kali-tools": {
"command": "docker",
"args": [
"run", "-i", "--rm",
"--cap-add=NET_RAW", "--cap-add=NET_ADMIN",
"-v", "/home/YOUR_USER/mcp-data:/data",
"mcp-kali-tools:latest"
]
}
}
}
```
`--cap-add=NET_RAW --cap-add=NET_ADMIN` is required for full nmap functionality (e.g. SYN
scans). The `/data` mount is where wordlists (e.g. `rockyou.txt`) and scan output should live —
pass paths under `/data/...` in tool arguments to read/write there.
Restart Claude Desktop after editing the config. If Docker was installed or your user was just
added to the `docker` group, log out and back in first — group membership only applies to new
login sessions.
## Notes
- Each container run is ephemeral (`--rm`); nothing persists except what's written to `/data`.
- Output per tool call is capped at 20,000 characters and each call times out after 180s by
default (override with the `timeout` argument on any tool call).
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues