Hacktricks Mcp

io.github.zebbernv0.1.5更新于 Oct 1, 2026

Offline full-text search over the HackTricks security wiki, synced every 3 days.

概览

AI 生成的概览

让助手通过内置全文索引离线搜索和阅读 HackTricks 攻防安全维基。

功能
基于预构建的 HackTricks 维基 SQLite FTS5 索引提供三个只读工具:带片段、分类过滤和缩写处理的相关性全文搜索;读取页面、单个章节或仅代码块;以及展示维基分类树的目录。索引随包分发,查询时无需网络访问,GitHub Action 每三天与上游重新同步一次。
适用场景
适合助手需要快速查阅攻防安全技术资料的场景,例如权限提升、Web 漏洞利用或攻击命令,且无需离开本机。适用于渗透测试和安全研究工作流,尤其是偏好离线只读维基搜索而非浏览网页的情况。
运行要求
通过 npx 从 npm 包 @zebbern/hacktricks-mcp 以 stdio 方式在本地运行。需要 Node.js 22.13 或更高版本,以使用内置的 node:sqlite 模块。未声明账户、API 密钥、环境变量或请求头,查询时无需网络访问。仅支持桌面客户端。
安装前请注意
维基内容属于攻防安全参考资料,仅可用于你已获授权测试的系统。工具严格只读,不执行维基中的任何内容,查询使用参数化并对用户输入进行转义。内容归 HackTricks 及其贡献者所有;该包包含派生索引数据和原创服务器代码。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Hacktricks Mcp,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

hacktricks-mcp

MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.

Unlike grep-based alternatives, this server ships with a pre-built SQLite FTS5 search index (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream every 3 days and commits it back to this repo.

Quick start

Requirements: Node.js 22.13 or newer (uses the built-in node:sqlite, zero native dependencies).

Claude Code:

bash
claude mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Codex CLI:

bash
codex mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Any MCP client (Claude Desktop, Cursor, Kimi, etc.), config JSON:

json
{  "mcpServers": {    "hacktricks": {      "command": "npx",      "args": ["-y", "@zebbern/hacktricks-mcp"]    }  }}

As a plugin (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (.claude-plugin/), Codex (.codex-plugin/) and Kimi (kimi-plugin/). Add it from your client's plugin marketplace flow pointing at zebbern/hacktricks-mcp, or for Kimi Work use this plugin link.

Then ask things like:

  • "Search HackTricks for kerberoast and give me the attack commands"
  • "How do I escalate privileges from the lxd group?"
  • "Show me the SSRF section of the pentesting-web pages"

Tools at a glance

ToolWhat it does
hacktricks_searchRanked full-text search with snippets, category filter and abbreviation handling (privesc, sqli, rce, ...)
hacktricks_get_pageRead a page, a single section, or just its code blocks
hacktricks_get_tocThe wiki category tree, so agents can see where topics live

All tools are strictly read-only. Full reference: docs/tools.md.

Documentation

Security and legal

  • The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
  • HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
  • Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).

Credits

来源:README.md,提交 35978b6

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.5最新Oct 1, 2026