
Hacktricks Mcp
io.github.zebbernv0.1.5Updated Oct 1, 2026
Offline full-text search over the HackTricks security wiki, synced every 3 days.
Overview
Lets an assistant search and read the HackTricks offensive-security wiki offline through a bundled full-text index.
- What it does
- Provides three read-only tools over a pre-built SQLite FTS5 index of the HackTricks wiki: ranked full-text search with snippets, category filters and abbreviation handling; page or section retrieval including code blocks; and a table of contents of the wiki category tree. The index ships inside the package, so queries need no network access, and a GitHub Action re-syncs it with upstream every three days.
- When to use it
- Useful when an assistant needs quick reference lookups of offensive-security techniques, such as privilege escalation, web exploitation or attack commands, without leaving the local machine. It suits pentesting and security research workflows where offline, read-only wiki search is preferred over web browsing.
- Requirements
- Runs locally as a stdio process via npx from the npm package @zebbern/hacktricks-mcp. Requires Node.js 22.13 or newer, which provides the built-in node:sqlite module. No accounts, API keys, environment variables or headers are declared, and no network access is needed at query time. Desktop clients only.
Installation
In SourceWeft
- Open Hacktricks Mcp in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
hacktricks-mcp
MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.
Unlike grep-based alternatives, this server ships with a pre-built SQLite FTS5 search index (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream every 3 days and commits it back to this repo.
Quick start
Requirements: Node.js 22.13 or newer (uses the built-in node:sqlite, zero native dependencies).
Claude Code:
Codex CLI:
Any MCP client (Claude Desktop, Cursor, Kimi, etc.), config JSON:
As a plugin (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (.claude-plugin/), Codex (.codex-plugin/) and Kimi (kimi-plugin/). Add it from your client's plugin marketplace flow pointing at zebbern/hacktricks-mcp, or for Kimi Work use this plugin link.
Then ask things like:
- "Search HackTricks for kerberoast and give me the attack commands"
- "How do I escalate privileges from the lxd group?"
- "Show me the SSRF section of the pentesting-web pages"
Tools at a glance
All tools are strictly read-only. Full reference: docs/tools.md.
Documentation
- docs/tools.md: complete tool reference with parameters and examples
- docs/architecture.md: how the index and the 3-day sync work
- docs/development.md: local setup, tests, releasing
- docs/agents.md: agent skill, MCP registry and plugin packaging
Security and legal
- The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
- HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
- Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).
Credits
- HackTricks by Carlos Polop and contributors
- Model Context Protocol SDK
Source: README.md at commit 35978b6
Tools
0Version history
1- v0.1.5LatestOct 1, 2026

