Hacktricks Mcp

io.github.zebbernv0.1.5Updated Oct 1, 2026

Offline full-text search over the HackTricks security wiki, synced every 3 days.

Overview

AI-generated overview

Lets an assistant search and read the HackTricks offensive-security wiki offline through a bundled full-text index.

What it does
Provides three read-only tools over a pre-built SQLite FTS5 index of the HackTricks wiki: ranked full-text search with snippets, category filters and abbreviation handling; page or section retrieval including code blocks; and a table of contents of the wiki category tree. The index ships inside the package, so queries need no network access, and a GitHub Action re-syncs it with upstream every three days.
When to use it
Useful when an assistant needs quick reference lookups of offensive-security techniques, such as privilege escalation, web exploitation or attack commands, without leaving the local machine. It suits pentesting and security research workflows where offline, read-only wiki search is preferred over web browsing.
Requirements
Runs locally as a stdio process via npx from the npm package @zebbern/hacktricks-mcp. Requires Node.js 22.13 or newer, which provides the built-in node:sqlite module. No accounts, API keys, environment variables or headers are declared, and no network access is needed at query time. Desktop clients only.
Before you install
The wiki content is offensive-security reference material and should only be used against systems you are authorized to test. The tools are strictly read-only and execute nothing from the wiki, and queries are parameterized with user input escaped. Content belongs to HackTricks and its contributors; the package contains derived index data plus original server code.

Installation

In SourceWeft

  1. Open Hacktricks Mcp in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

hacktricks-mcp

MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.

Unlike grep-based alternatives, this server ships with a pre-built SQLite FTS5 search index (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream every 3 days and commits it back to this repo.

Quick start

Requirements: Node.js 22.13 or newer (uses the built-in node:sqlite, zero native dependencies).

Claude Code:

bash
claude mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Codex CLI:

bash
codex mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Any MCP client (Claude Desktop, Cursor, Kimi, etc.), config JSON:

json
{  "mcpServers": {    "hacktricks": {      "command": "npx",      "args": ["-y", "@zebbern/hacktricks-mcp"]    }  }}

As a plugin (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (.claude-plugin/), Codex (.codex-plugin/) and Kimi (kimi-plugin/). Add it from your client's plugin marketplace flow pointing at zebbern/hacktricks-mcp, or for Kimi Work use this plugin link.

Then ask things like:

  • "Search HackTricks for kerberoast and give me the attack commands"
  • "How do I escalate privileges from the lxd group?"
  • "Show me the SSRF section of the pentesting-web pages"

Tools at a glance

ToolWhat it does
hacktricks_searchRanked full-text search with snippets, category filter and abbreviation handling (privesc, sqli, rce, ...)
hacktricks_get_pageRead a page, a single section, or just its code blocks
hacktricks_get_tocThe wiki category tree, so agents can see where topics live

All tools are strictly read-only. Full reference: docs/tools.md.

Documentation

Security and legal

  • The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
  • HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
  • Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).

Credits

Source: README.md at commit 35978b6

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.5LatestOct 1, 2026