Bring HackTricks pentesting knowledge into Claude Desktop. Search 1000+ security techniques, exploits, and payloads without leaving your AI assistant. MCP-powered, npx-ready.
SaferSkills independently audited Hacktricks Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP (Model Context Protocol) server for searching and querying HackTricks pentesting documentation directly from Claude.
npm install -g hacktricks-mcp-serverThe postinstall script automatically clones the HackTricks repository (~2 minutes on first install).
Add to your Claude settings (~/.claude/settings.json):
{
"mcpServers": {
"hacktricks": {
"command": "npx",
"args": ["hacktricks-mcp-server"]
}
}
}Restart Claude Desktop and try: "Search HackTricks for SQL injection"
git clone https://github.com/Xplo8E/hacktricks-mcp-server.git
cd hacktricks-mcp-server
git submodule update --init --recursive
npm install
npm run buildConfiguration for source install:
{
"mcpServers": {
"hacktricks": {
"command": "node",
"args": ["/absolute/path/to/hacktricks-mcp-server/dist/index.js"]
}
}
}Once configured in Claude Desktop, you can ask:
The server provides 7 specialized tools for efficient HackTricks searching.
hacktricks_quick_lookup⚡ One-shot exploitation lookup. Searches, finds best page, and returns exploitation sections + code blocks in one call.
Parameters:
topic (string, required): Attack/technique to look up (e.g., 'SUID', 'sqli', 'xss', 'docker escape')category (string, optional): Category filter for faster resultsSupported aliases: sqli, xss, rce, lfi, rfi, ssrf, csrf, xxe, ssti, idor, jwt, suid, privesc
Example:
hacktricks_quick_lookup("SSRF", category="pentesting-web")Benefits: Reduces 3+ tool calls to 1 for "how do I exploit X" questions.
search_hacktricksSearch through HackTricks documentation. Returns results GROUPED BY FILE with match count, page title, and relevant section headers.
Parameters:
query (string, required): Search term or regex patterncategory (string, optional): Filter to specific category (e.g., 'pentesting-web')limit (number, optional): Max grouped results (default: 20)Example output:
Found matches in 5 files for: "SUID"
────────────────────────────────────────────────────────────
📄 **Linux Privilege Escalation**
Path: src/linux-hardening/privilege-escalation/README.md
Matches: 12
Sections: SUID Binaries | Finding SUID | GTFOBins
Preview:
L45: Find files with SUID bit set...
L78: Common SUID exploitation techniques...
────────────────────────────────────────────────────────────get_hacktricks_outlineGet the table of contents of a page (all section headers). Use this BEFORE reading full pages to understand structure.
Parameters:
path (string): Relative path to markdown fileExample output:
# Linux Privilege Escalation
## Enumeration
### System Information
### Network
## SUID Binaries
### Finding SUID Files
### Exploiting SUID
## CapabilitiesBenefits: See page structure in ~20 lines vs reading 500+ lines.
get_hacktricks_sectionExtract a specific section from a page by header name. Much more efficient than reading the full page.
Parameters:
path (string): Relative path to markdown filesection (string): Section header to extract (partial match, case-insensitive)Example:
get_hacktricks_section("src/linux-hardening/privilege-escalation/README.md", "SUID")Benefits: Read just "SUID Binaries" section (~200 tokens) instead of entire page (~3000 tokens).
get_hacktricks_cheatsheetExtract only code blocks from a page. Perfect when you just need commands, payloads, or examples.
Parameters:
path (string): Relative path to markdown fileExample output:
find / -perm -4000 2>/dev/null./vulnerable_suid -pBenefits: Skip explanatory text when you just need "give me the command".
get_hacktricks_pageGet full content of a HackTricks page.
Parameters:
path (string): Relative path to markdown fileWarning: Pages can be very long (3000+ tokens). Consider using get_hacktricks_outline + get_hacktricks_section instead.
list_hacktricks_categoriesList categories and their contents.
Parameters:
category (string, optional): Category to expandWithout category: Lists top-level categories With category: Shows full directory tree with file paths
For optimal token usage, Claude should:
Before (inefficient):
search_hacktricks("SUID") → 50 raw lines
get_page(file1) → 3000 tokens
get_page(file2) → 2500 tokens
Total: ~5500 tokens, 3 callsAfter (efficient):
search_hacktricks("SUID", category="linux-hardening") → Grouped results
get_outline(best_match) → 20 lines
get_section(best_match, "SUID") → 200 tokens
Total: ~400 tokens, 3 callsrg) - usually pre-installed on macOS/LinuxWatch mode:
bun run devTest locally:
bun run startContributions are welcome! If you'd like to improve the server:
git checkout -b feature/improvement)Please ensure your PR includes tests for new features and maintains the existing code style.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.