MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki.
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
- !Licence file present but not machine-readable
claude mcp add hacktricks-mcp -- npx -y @zebbern/hacktricks-mcp{
"mcpServers": {
"hacktricks-mcp": {
"command": "npx",
"args": ["-y", "@zebbern/hacktricks-mcp"]
}
}
}MCP Servers overview
# hacktricks-mcp
MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the [HackTricks](https://github.com/HackTricks-wiki/hacktricks) offensive-security wiki.
Unlike grep-based alternatives, this server ships with a **pre-built SQLite FTS5 search index** (1,000+ pages) inside the package. No install-time clone, no ripgrep dependency, no network access at query time. A GitHub Action re-syncs the index with upstream **every 3 days** and commits it back to this repo.
## Quick start
Requirements: Node.js 22.13 or newer (uses the built-in `node:sqlite`, zero native dependencies).
**Claude Code:**
```bash
claude mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp
```
**Codex CLI:**
```bash
codex mcp add hacktricks -- npx -y @zebbern/hacktricks-mcp
```
**Any MCP client** (Claude Desktop, Cursor, Kimi, etc.), config JSON:
```json
{
"mcpServers": {
"hacktricks": {
"command": "npx",
"args": ["-y", "@zebbern/hacktricks-mcp"]
}
}
}
```
**As a plugin** (bundles the agent skill that teaches efficient usage): this repo is a valid plugin for Claude Code (`.claude-plugin/`), Codex (`.codex-plugin/`) and Kimi (`kimi-plugin/`). Add it from your client's plugin marketplace flow pointing at `zebbern/hacktricks-mcp`, or for Kimi Work use [this plugin link](kimi-work://plugin?id=hacktricks).
Then ask things like:
- *"Search HackTricks for kerberoast and give me the attack commands"*
- *"How do I escalate privileges from the lxd group?"*
- *"Show me the SSRF section of the pentesting-web pages"*
## Tools at a glance
| Tool | What it does |
|---|---|
| `hacktricks_search` | Ranked full-text search with snippets, category filter and abbreviation handling (`privesc`, `sqli`, `rce`, ...) |
| `hacktricks_get_page` | Read a page, a single section, or just its code blocks |
| `hacktricks_get_toc` | The wiki category tree, so agents can see where topics live |
All tools are strictly read-only. Full reference: [docs/tools.md](docs/tools.md).
## Documentation
- [docs/tools.md](docs/tools.md): complete tool reference with parameters and examples
- [docs/architecture.md](docs/architecture.md): how the index and the 3-day sync work
- [docs/development.md](docs/development.md): local setup, tests, releasing
- [docs/agents.md](docs/agents.md): agent skill, MCP registry and plugin packaging
## Security and legal
- The server executes nothing from the wiki; it is a read-only search interface. All queries are parameterized, and user input is escaped before query construction.
- HackTricks content is offensive-security reference material. Use it only on systems you are authorized to test.
- Content belongs to HackTricks / Carlos Polop and contributors; this repo contains derived index data plus original server code (MIT).
## Credits
- [HackTricks](https://github.com/HackTricks-wiki/hacktricks) by Carlos Polop and contributors
- [Model Context Protocol SDK](https://github.com/modelcontextprotocol/typescript-sdk)
What people ask about hacktricks-mcp
What is zebbern/hacktricks-mcp?
+
zebbern/hacktricks-mcp is mcp servers for the Claude AI ecosystem. MCP server that gives AI agents fast, offline full-text search and section-level retrieval over the HackTricks offensive-security wiki. It has 0 GitHub stars and its last recorded update is dated 2026-10-01.
How do I install hacktricks-mcp?
+
You can install hacktricks-mcp by cloning the repository (https://github.com/zebbern/hacktricks-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is zebbern/hacktricks-mcp safe to use?
+
Our security agent has analyzed zebbern/hacktricks-mcp and assigned a Trust Score of 80/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains zebbern/hacktricks-mcp?
+
zebbern/hacktricks-mcp is maintained by zebbern. The last recorded GitHub activity is dated 2026-10-01, with 0 open issues.
Are there alternatives to hacktricks-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy hacktricks-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/zebbern-hacktricks-mcp)<a href="https://claudewave.com/repo/zebbern-hacktricks-mcp"><img src="https://claudewave.com/api/badge/zebbern-hacktricks-mcp" alt="Featured on ClaudeWave: zebbern/hacktricks-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.