Skip to main content
Glama

packmate-mcp

MCP server that exposes Packmate — a CTF network traffic analyzer — to LLM tooling like Claude Desktop or Claude Code.

Features

  • 16 tools across services, patterns, streams, packets, and pcap-file lifecycle.

  • Packet content formatting tuned for LLM consumption: transcript (auto text/hex with client→server markers), text, hex, python_bytes, base64.

  • Three-layer trimming (per-packet, total budget, packet count) to keep responses inside the LLM context window.

  • Pure async httpx client over Packmate's HTTP API + Basic Auth.

  • stdio transport — drop into Claude Desktop or Claude Code as a subprocess.

Related MCP server: TShark2MCP

Install

uvx packmate-mcp        # ephemeral, recommended
# or
pip install packmate-mcp

Configure

All settings are env vars with the PACKMATE_MCP_ prefix:

Env var

Default

Description

PACKMATE_MCP_BASE_URL

http://localhost:65000

Packmate base URL

PACKMATE_MCP_LOGIN

(required)

Basic auth login

PACKMATE_MCP_PASSWORD

(required)

Basic auth password

PACKMATE_MCP_TIMEOUT_SECONDS

30

HTTP request timeout

PACKMATE_MCP_LOG_LEVEL

INFO

DEBUG/INFO/WARNING/ERROR/CRITICAL

See .env.example for a starter template.

Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %AppData%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "packmate": {
      "command": "uvx",
      "args": ["packmate-mcp"],
      "env": {
        "PACKMATE_MCP_BASE_URL": "http://localhost:65000",
        "PACKMATE_MCP_LOGIN": "BinaryBears",
        "PACKMATE_MCP_PASSWORD": "..."
      }
    }
  }
}

Restart Claude Desktop fully (Cmd+Q / tray → Quit), then look for the connector under the + menu.

Claude Code

claude mcp add packmate uvx packmate-mcp \
  --env PACKMATE_MCP_LOGIN=BinaryBears \
  --env PACKMATE_MCP_PASSWORD=...

Tools

See the design spec for the full list. Highlights:

  • get_stream(stream_id, content_format='transcript') — fetch a stream with packets pre-rendered. Most common entrypoint.

  • create_pattern + pattern_lookback + list_streams(pattern_id=…) — the native Packmate workflow for content search.

  • set_stream_favorite(stream_id, favorite=True/False) — pin interesting streams.

  • pcap_status / pcap_start — kick off pcap-file processing in FILE mode.

Development

git clone https://github.com/umbra2728/packmate-mcp
cd packmate-mcp
uv sync --dev
uv run pytest
uv run ruff check src tests
uv run mypy src

Manual smoke test against a real Packmate instance:

# in the Packmate repo
docker compose up -d
# back here
PACKMATE_MCP_LOGIN=BinaryBears PACKMATE_MCP_PASSWORD=123456 \
  uv run mcp dev src/packmate_mcp/server.py

This opens the MCP Inspector and lets you exercise each tool.

Releasing

This package ships to PyPI via Trusted Publishing. The workflow runs on any v*.*.* tag.

  1. Bump version in pyproject.toml.

  2. Add a ## [X.Y.Z] - YYYY-MM-DD section to CHANGELOG.md.

  3. Commit, tag, push:

git commit -am "Release vX.Y.Z"
git tag vX.Y.Z
git push --tags

One-time setup (not in repo state):

  • On PyPI → Account settings → Add a pending publisher with repo umbra2728/packmate-mcp, workflow release.yml, environment pypi.

  • On GitHub → repo → Settings → Environments → create pypi.

  • firegex-mcp — sibling MCP server for Firegex (PCRE2 regex / proxy WAF).

  • ad-ctf-toolkit — Claude Code plugin that combines packmate-mcp and firegex-mcp with skills and sub-agents for Attack/Defense CTF rounds.

Contact

Questions, suggestions, bug reports, or anything else — reach out:

License

MIT — see LICENSE.

Install Server
A
license - permissive license
B
quality
A
maintenance

Maintenance

Maintainers
Response time
0dRelease cycle
2Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    B
    quality
    F
    maintenance
    A Model Context Protocol server that provides LLMs with real-time network traffic analysis capabilities, enabling tasks like threat hunting, network diagnostics, and anomaly detection through Wireshark's tshark.
    Last updated
    7
    558
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    An MCP server that enables AI-assisted network packet analysis using Wireshark's TShark tool. It provides tools for pcap file overview, session extraction, protocol filtering, and statistical analysis through a standardized interface.
    Last updated
    1
    MIT
  • A
    license
    B
    quality
    B
    maintenance
    An MCP server that enables LLMs to analyze pcap files by providing tools for packet dissection, stream following, and data extraction via tshark. It supports protocol hierarchy analysis, credential scanning, and threat intelligence checks on captured network traffic.
    Last updated
    51
    183
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.

  • MCP server for AI dialogue using various LLM models via AceDataCloud

  • MCP server providing access to the Scorecard API to evaluate and optimize LLM systems.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/umbra2728/packmate-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server