hacktricks-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| hacktricks_searchA | Full-text search over the HackTricks offensive-security wiki (pentesting techniques, privilege escalation, web vulns, AD attacks, cloud, forensics). Returns ranked pages with snippets. Use specific technical terms (e.g. 'kerberoast', 'SUID', 'JWT algorithm confusion') for best results. Follow up with hacktricks_get_page on a result's path to read the content. |
| hacktricks_get_pageA | Retrieve content of a HackTricks page found via hacktricks_search. By default returns the page outline plus content (truncated if very long). Use section= to read one section by heading name, or codeOnly=true to get just the commands/payloads. This is the token-efficient way to consume long pages. |
| hacktricks_get_tocA | Get the HackTricks wiki structure: categories and page tree. Call without arguments for the top-level overview, or pass a category to see its pages. Useful to understand where a topic lives before searching. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
Each tool has a clearly distinct purpose: full-text search for finding pages, page retrieval for consuming content, and TOC for structural overview. There is no overlap in action or resource that would cause misselection.
All tool names follow a consistent snake_case pattern with the same 'hacktricks_' prefix and action-oriented verbs (search, get_page, get_toc). The convention is predictable and readable.
Three tools is exactly right for a read-only wiki access server: search, retrieve, and navigate structure. Each tool earns its place without redundancy or bloat.
The surface fully covers the domain of consuming the HackTricks wiki: searching, retrieving pages with section/code filtering, and browsing the table of contents. No obvious gaps for a read-only access layer.