
Hacktricks Mcp
io.github.zebbernv0.1.5更新于 Oct 1, 2026
Offline full-text search over the HackTricks security wiki, synced every 3 days.
概览
让助手通过内置全文索引离线搜索和阅读 HackTricks 攻防安全维基。
- 功能
- 基于预构建的 HackTricks 维基 SQLite FTS5 索引提供三个只读工具:带片段、分类过滤和缩写处理的相关性全文搜索;读取页面、单个章节或仅代码块;以及展示维基分类树的目录。索引随包分发,查询时无需网络访问,GitHub Action 每三天与上游重新同步一次。
- 适用场景
- 适合助手需要快速查阅攻防安全技术资料的场景,例如权限提升、Web 漏洞利用或攻击命令,且无需离开本机。适用于渗透测试和安全研究工作流,尤其是偏好离线只读维基搜索而非浏览网页的情况。
- 运行要求
- 通过 npx 从 npm 包 @zebbern/hacktricks-mcp 以 stdio 方式在本地运行。需要 Node.js 22.13 或更高版本,以使用内置的 node:sqlite 模块。未声明账户、API 密钥、环境变量或请求头,查询时无需网络访问。仅支持桌面客户端。
安装
在 SourceWeft 中
- 打开 控制台中的 Hacktricks Mcp,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
hacktricks-mcp
MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.
Unlike grep-based alternatives, this server ships with a pre-built SQLite FTS5 search index (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream every 3 days and commits it back to this repo.
Quick start
Requirements: Node.js 22.13 or newer (uses the built-in node:sqlite, zero native dependencies).
Claude Code:
Codex CLI:
Any MCP client (Claude Desktop, Cursor, Kimi, etc.), config JSON:
As a plugin (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (.claude-plugin/), Codex (.codex-plugin/) and Kimi (kimi-plugin/). Add it from your client's plugin marketplace flow pointing at zebbern/hacktricks-mcp, or for Kimi Work use this plugin link.
Then ask things like:
- "Search HackTricks for kerberoast and give me the attack commands"
- "How do I escalate privileges from the lxd group?"
- "Show me the SSRF section of the pentesting-web pages"
Tools at a glance
All tools are strictly read-only. Full reference: docs/tools.md.
Documentation
- docs/tools.md: complete tool reference with parameters and examples
- docs/architecture.md: how the index and the 3-day sync work
- docs/development.md: local setup, tests, releasing
- docs/agents.md: agent skill, MCP registry and plugin packaging
Security and legal
- The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
- HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
- Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).
Credits
- HackTricks by Carlos Polop and contributors
- Model Context Protocol SDK
来源:README.md,提交 35978b6
工具
0版本历史
1- v0.1.5最新Oct 1, 2026

