MCP Kali Server

A bridge between an MCP client and a Kali Linux terminal so the agent can run nmap, sqlmap, hydra and other tools for authorized pentesting and CTF

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Runs arbitrary commands in a Kali terminal
  • Built for offensive security; use only on your own systems and with authorization
  • A server exposed on an external interface grants remote shell access
All reasons and checks

wh0am123/mcp-kali-server

Install

Manual install

sudo apt install mcp-kali-server
kali-server-mcp

On the Kali box: install via the OS package and start the API server.

This is third-party code. Review the repository files before installing.

What it does

The project pairs an API server that runs on the Kali box with an MCP client that connects an AI agent to it. The server exposes controlled terminal access and a set of tools: dirb, enum4linux, gobuster, hydra, john, metasploit, nikto, nmap, sqlmap, wpscan, plus arbitrary commands. The agent proposes and runs commands, reads the output and continues recon or exploitation. By default the server binds to localhost only, and the authors recommend an SSH tunnel for remote use.

Who it is for. For offensive security specialists and CTF players who test their own infrastructure.

Good fit when

  • You want the agent to handle recon and routine pentest steps on your own lab
  • You solve CTF and want the agent to pick commands itself
  • You need Kali terminal access from an MCP client

Not a fit when

  • You have no written permission to test the target
  • The target belongs to a third party without authorization
  • You cannot expose the server on an external interface without protection

Example request

Scan my lab host at 127.0.0.1 with nmap and suggest the next step

Limitations

The server runs commands in a Kali terminal, so it must not be opened to an untrusted network: binding to 0.0.0.0 without a tunnel is dangerous. It needs the Kali tools installed and a configured MCP client. Model API keys for OpenAI, Anthropic and similar are configured separately in the client.

How to disable. Stop the server.py and client.py processes and remove the MCP entry from the client config. The OS package is removed with the standard package manager.

MCP

Transport
stdio
Authentication
not required

Security check

  • Runs arbitrary commands in a Kali terminal
  • Built for offensive security; use only on your own systems and with authorization
  • A server exposed on an external interface grants remote shell access

README in short

The README covers install via an OS package and from source, server run options (address, port, debug mode) and client setup locally or over an SSH tunnel. It gives examples for Claude Desktop and 5ire and walkthroughs for web CTF and HTB machines. It also notes forensics options through Volatility and SleuthKit. It ends with a disclaimer: legal and ethical testing only.

FAQ

Is it safe to expose on the network?

No. By default the server listens on localhost. The authors advise against binding to 0.0.0.0; use an SSH tunnel for remote work.

Which clients work with it?

MCP clients such as Claude Desktop and 5ire; the repository ships an example configuration.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIMCP Kali Server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.