Kali Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Kali Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Kali Linux MCP (Model Context Protocol) Server built with Node.js for seamless integration with LLMs such as Claude, or any MCP-compatible client. It offers powerful network security and penetration testing tools like Nmap, Whois, Dig, Ping, Nikto, Hydra, and SQLMap inside a Dockerized Kali Linux setup.
DISCLAIMER — IMPORTANT LEGAL NOTICE: This repository and the tools, code, scripts, configurations, documentation, and other materials contained herein (collectively, the “Materials”) are provided solely for lawful, educational, and authorized security-testing purposes. The author(s) and maintainers make no representations or warranties regarding the suitability, accuracy, completeness, or fitness of the Materials for any particular purpose.
nmap_scan: Network scanning & host discoverywhois_lookup: Domain registration info lookupdig_dns: DNS record queryingping_host: ICMP ping testnetcat_connect: TCP/UDP port testingnikto_scan: Web vulnerability scanningsqlmap_scan: SQL Injection testinghydra_bruteforce: Login brute force attacks (controlled environment)dns_enum: DNS enumerationsubdomain_enum: Subdomain discoveryssl_scan: SSL/TLS certificate inspectionmetasploit_search: Search exploits from Metasploit DBmetasploit_exploit_info: Get detailed exploit module infoset_info: Check if Social Engineering Toolkit is installedtraceroute: Network path tracinghost_discovery: Active host discoverykali-mcp-server/
├── Dockerfile
├── server.js
├── package.json
├── claude-config.json
├── .dockerignore
├── FEATURES.md
├── README.md
├── DISCLAIMER.md
├── LICENSE
└── screenshots/
├── scan_report.png
├── ssh_bruteforce.png
├── tools_list_1.png
├── tools_list_2.png
└── tools_menu.pngnode server.js
Dockergit clone https://github.com/rangta10/kali-mcp-server.git
cd kali-mcp-server
docker build -t kali-mcp-server .docker run -it kali-mcp-serverC:\Users\<YourUsername>\AppData\Roaming\Claudeclaude_desktop_config.json{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-filesystem",
"C:\\Users\\annan\\Desktop",
"C:\\Users\\annan\\Downloads"
]
},
"kali-mcp-server": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"--privileged",
"--cap-add=NET_ADMIN",
"--cap-add=NET_RAW",
"kali-mcp-server:latest",
"node",
"/app/server.js"
]
}
}
}# kali-mcp-server (by rangta)
FROM kalilinux/kali-rolling
RUN apt update && apt install -y \
nmap whois dnsutils netcat-traditional nikto sqlmap hydra dnsenum sslscan metasploit-framework set traceroute nodejs npm
WORKDIR /app
COPY . .
RUN npm install || true
CMD ["node", "server.js"](unchanged from the repository — contains your MCP tool definitions and handlers, with copyright signature rangta)
License
Copyright (c) 2025 rangta
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND.nmap scan nmap scan
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.