Skip to main content
Glama
README.md
# hacktricks-mcp

MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the [HackTricks](https://github.com/HackTricks-wiki/hacktricks) offensive-security wiki.

Unlike grep-based alternatives, this server ships with a **pre-built SQLite FTS5 search index** (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream **every 3 days** and commits it back to this repo.

## Quick start

Requirements: Node.js 22.13 or newer (uses the built-in `node:sqlite`, zero native dependencies).

**Claude Code:**

```bash
claude mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp
```

**Codex CLI:**

```bash
codex mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp
```

**Any MCP client** (Claude Desktop, Cursor, Kimi, etc.), config JSON:

```json
{
  "mcpServers": {
    "hacktricks": {
      "command": "npx",
      "args": ["-y", "@zebbern/hacktricks-mcp"]
    }
  }
}
```

**As a plugin** (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (`.claude-plugin/`), Codex (`.codex-plugin/`) and Kimi (`kimi-plugin/`). Add it from your client's plugin marketplace flow pointing at `zebbern/hacktricks-mcp`, or for Kimi Work use [this plugin link](kimi-work://plugin?id=hacktricks).

Then ask things like:

- *"Search HackTricks for kerberoast and give me the attack commands"*
- *"How do I escalate privileges from the lxd group?"*
- *"Show me the SSRF section of the pentesting-web pages"*

## Tools at a glance

| Tool | What it does |
|---|---|
| `hacktricks_search` | Ranked full-text search with snippets, category filter and abbreviation handling (`privesc`, `sqli`, `rce`, ...) |
| `hacktricks_get_page` | Read a page, a single section, or just its code blocks |
| `hacktricks_get_toc` | The wiki category tree, so agents can see where topics live |

All tools are strictly read-only. Full reference: [docs/tools.md](docs/tools.md).

## Documentation

- [docs/tools.md](docs/tools.md): complete tool reference with parameters and examples
- [docs/architecture.md](docs/architecture.md): how the index and the 3-day sync work
- [docs/development.md](docs/development.md): local setup, tests, releasing
- [docs/agents.md](docs/agents.md): agent skill, MCP registry and plugin packaging

## Security and legal

- The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
- HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
- Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).

## Credits

- [HackTricks](https://github.com/HackTricks-wiki/hacktricks) by Carlos Polop and contributors
- [Model Context Protocol SDK](https://github.com/modelcontextprotocol/typescript-sdk)

TDQS

A4.3/5.0

Scored across 3 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: full-text search for finding pages, page retrieval for consuming content, and TOC for structural overview. There is no overlap in action or resource that would cause misselection.

Naming Consistency5/5

All tool names follow a consistent snake_case pattern with the same 'hacktricks_' prefix and action-oriented verbs (search, get_page, get_toc). The convention is predictable and readable.

Tool Count5/5

Three tools is exactly right for a read-only wiki access server: search, retrieve, and navigate structure. Each tool earns its place without redundancy or bloat.

Completeness5/5

The surface fully covers the domain of consuming the HackTricks wiki: searching, retrieving pages with section/code filtering, and browsing the table of contents. No obvious gaps for a read-only access layer.

Maintenance

ActivityMaintained
ResponsivenessNo issues