Hacktricks Mcp

io.github.zebbernv0.1.5更新於 Oct 1, 2026

Offline full-text search over the HackTricks security wiki, synced every 3 days.

概覽

AI 產生的概覽

讓助理透過內建的全文索引離線搜尋與閱讀 HackTricks 攻防安全維基。

功能
以預先建置的 HackTricks 維基 SQLite FTS5 索引提供三個唯讀工具:附摘要片段、分類篩選與縮寫處理的相關性全文搜尋;讀取頁面、單一章節或僅程式碼區塊;以及顯示維基分類樹的目錄。索引隨套件一起提供,查詢時不需網路連線,GitHub Action 每三天與上游重新同步一次。
適用情境
適合助理需要快速查閱攻防安全技術資料的情境,例如權限提升、Web 漏洞利用或攻擊指令,且不必離開本機。適用於滲透測試與安全研究工作流程,特別是偏好離線唯讀維基搜尋而非瀏覽網頁的情況。
執行需求
透過 npx 從 npm 套件 @zebbern/hacktricks-mcp 以 stdio 方式在本機執行。需要 Node.js 22.13 或更新版本,以使用內建的 node:sqlite 模組。未宣告帳號、API 金鑰、環境變數或標頭,查詢時不需網路連線。僅支援桌面用戶端。
安裝前請注意
維基內容屬於攻防安全參考資料,僅可用於你已獲授權測試的系統。工具嚴格唯讀,不會執行維基中的任何內容,查詢採用參數化並對使用者輸入進行轉義。內容歸 HackTricks 及其貢獻者所有;此套件包含衍生的索引資料與原創伺服器程式碼。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Hacktricks Mcp,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

hacktricks-mcp

MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.

Unlike grep-based alternatives, this server ships with a pre-built SQLite FTS5 search index (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream every 3 days and commits it back to this repo.

Quick start

Requirements: Node.js 22.13 or newer (uses the built-in node:sqlite, zero native dependencies).

Claude Code:

bash
claude mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Codex CLI:

bash
codex mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp

Any MCP client (Claude Desktop, Cursor, Kimi, etc.), config JSON:

json
{  "mcpServers": {    "hacktricks": {      "command": "npx",      "args": ["-y", "@zebbern/hacktricks-mcp"]    }  }}

As a plugin (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (.claude-plugin/), Codex (.codex-plugin/) and Kimi (kimi-plugin/). Add it from your client's plugin marketplace flow pointing at zebbern/hacktricks-mcp, or for Kimi Work use this plugin link.

Then ask things like:

  • "Search HackTricks for kerberoast and give me the attack commands"
  • "How do I escalate privileges from the lxd group?"
  • "Show me the SSRF section of the pentesting-web pages"

Tools at a glance

ToolWhat it does
hacktricks_searchRanked full-text search with snippets, category filter and abbreviation handling (privesc, sqli, rce, ...)
hacktricks_get_pageRead a page, a single section, or just its code blocks
hacktricks_get_tocThe wiki category tree, so agents can see where topics live

All tools are strictly read-only. Full reference: docs/tools.md.

Documentation

Security and legal

  • The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
  • HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
  • Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).

Credits

來源:README.md,提交 35978b6

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.5最新Oct 1, 2026