Skip to main content
Glama
rdriver001

mcp-kali-tools

by rdriver001
README.md
# mcp-kali-tools

A Docker image that runs a [Model Context Protocol](https://modelcontextprotocol.io) server
exposing common Kali Linux pentesting tools to an MCP client (e.g. Claude Desktop). Each tool
runs as its own MCP tool call, executed directly as `argv` (no shell), so arguments can't be
used to chain or inject arbitrary shell commands — but each tool still has the full power of
its underlying binary.

> **Authorized use only.** This bundles offensive security tooling (nmap, sqlmap, hydra,
> Metasploit, etc.). Only point it at systems and networks you're authorized to test.

## Tools included

`nmap`, `sqlmap`, `nikto`, `hydra`, `john`, `hashcat`, `msfconsole`, `gobuster`, `ffuf`,
`whatweb`, `wpscan`, `aircrack-ng`, `searchsploit`

`aircrack-ng` can crack existing capture files, but live wireless capture (monitor mode) needs
a physical adapter passed through to the container (`--device`, `--net=host`), which isn't set
up by default.

## Build

```
docker build -t mcp-kali-tools:latest .
```

## Run manually (for testing)

The server speaks MCP over stdio — it's not meant to be left running standalone. To smoke-test
it, pipe JSON-RPC requests in directly:

```
docker run -i --rm mcp-kali-tools:latest
```

## Configure in Claude Desktop

Create a host directory for wordlists/scan output to persist across runs, e.g.:

```
mkdir -p ~/mcp-data
```

Add this to `mcpServers` in your `claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "kali-tools": {
      "command": "docker",
      "args": [
        "run", "-i", "--rm",
        "--cap-add=NET_RAW", "--cap-add=NET_ADMIN",
        "-v", "/home/YOUR_USER/mcp-data:/data",
        "mcp-kali-tools:latest"
      ]
    }
  }
}
```

`--cap-add=NET_RAW --cap-add=NET_ADMIN` is required for full nmap functionality (e.g. SYN
scans). The `/data` mount is where wordlists (e.g. `rockyou.txt`) and scan output should live —
pass paths under `/data/...` in tool arguments to read/write there.

Restart Claude Desktop after editing the config. If Docker was installed or your user was just
added to the `docker` group, log out and back in first — group membership only applies to new
login sessions.

## Notes

- Each container run is ephemeral (`--rm`); nothing persists except what's written to `/data`.
- Output per tool call is capped at 20,000 characters and each call times out after 180s by
  default (override with the `timeout` argument on any tool call).

Maintenance

ActivityMaintained
ResponsivenessNo issues