Skip to main content
Glama
rifkyekayama

Kali Linux MCP Server

by rifkyekayama

search_exploits

Search Metasploit modules by keyword to quickly locate relevant exploits for penetration testing and vulnerability assessments.

Instructions

Search Metasploit modules by keyword.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
queryYes
exploit_typeNoexploit
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries full burden for behavioral disclosure. It fails to mention whether the tool requires an active Metasploit connection, any destructive potential, or rate limits. Since it searches for exploits, it likely triggers no destructive actions, but this is not confirmed.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence, concise and to the point. However, it would benefit from a second sentence clarifying the scope (e.g., 'Searches within Metasploit's module database').

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity (2 params) but lack of output schema and annotations, the description is incomplete. Agents would not know the response format (list of module names?), whether search is exact or fuzzy, or if it filters by exploit type automatically. The sibling tools list suggests Metasploit integration, which is not clarified.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

With 0% schema description coverage and 2 parameters, the description should add meaning but only names 'keyword' for the query parameter. It doesn't explain that 'exploit_type' has a default value or its possible values, leaving the agent to guess. The parameter 'query' is vague—what kind of keyword? Module name, CVE, or free text?

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states it searches Metasploit modules by keyword, which differentiates it from siblings that scan ports or enumerate directories. However, it doesn't clarify that it searches specifically for exploits/modules within Metasploit, which could be confused with the broader sibling 'scan_host_vulnerabilities'.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives like 'run_network_exploit' or 'connect_metasploit'. It doesn't state prerequisites (e.g., Metasploit must be accessible) or when not to use it, which is a significant gap given the specialized sibling tools.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/rifkyekayama/kali-linux-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server