HexStrike AI
BLOCKgrade D · trust 69/100HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capa
0x4m4aiai agentsai cybersecurityai hackingai penetration testingai security toolartificial intelligenceOverview
From the repository's own README, as read at the audited commit.
<div align="center"><img src="assets/hexstrike-logo.png" alt="HexStrike AI Logo" width="220" style="margin-bottom: 20px;"/># HexStrike AI MCP Agents v6.0### AI-Powered MCP Cybersecurity Automation Platform[](https://www.python.org/)[](LICENSE)[](https://github.com/0x4m4/hexstrike-ai)[](https://github.com/0x4m4/hexstrike-ai)[](https://github.com/0x4m4/hexstrike-ai/releases)[](https://github.com/0x4m4/hexstrike-ai)[](https://github.com/0x4m4/hexstrike-ai)[](https://github.com/0x4m4/hexstrike-ai)**Advanced AI-powered penetration testing MCP framework with 150+ security tools and 12+ autonomous AI agents****Owned & developed by [OTT Cybersecurity LLC](https://overthetop.ae/)**[📋 What's New](#whats-new-in-v60) • [🏗️ Architecture](#architecture-overview) • [🚀 Installation](#installation) • [🛠️ Features](#features) • [🤖 AI Agents](#ai-agents) • [📡 API Reference](#api-reference)</div>---<div align="center">## Follow Our Social Accounts<p align="center"> <a href="https://discord.gg/BWnmrrSHbA"> <img src="https://img.shields.io/badge/Discord-Join-7289DA?logo=discord&logoColor=white&style=for-the-badge" alt="Join our Discord" /> </a> <a href="https://www.linkedin.com/company/hexstrike-ai"> <img src="https://img.shields.io/badge/LinkedIn-Follow%20us-0A66C2?logo=linkedin&logoColor=white&style=for-the-badge" alt="Follow us on LinkedIn" /> </a></p></div>---## Architecture OverviewHexStrike AI MCP v6.0 features a m
Exposed tools (150) 134 read · 13 write · 3 destructive
Blast radius: 3 tools can delete or overwrite. An agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
advanced_payload_generation | read | |
ai_generate_attack_suite | read | |
ai_generate_payload | read | |
ai_reconnaissance_workflow | read | |
ai_test_payload | read | |
ai_vulnerability_assessment | read | |
amass_scan | read | |
analyze_target_intelligence | read | |
anew_data_processing | read | |
angr_symbolic_execution | read | |
api_fuzzer | read | |
api_schema_analyzer | read | |
arjun_parameter_discovery | read | |
arjun_scan | read | |
arp_scan_discovery | read | |
autorecon_comprehensive | read | |
autorecon_scan | read | |
binwalk_analyze | read | |
browser_agent_inspect | read | |
bugbounty_authentication_bypass_testing | read | |
bugbounty_business_logic_testing | read | |
bugbounty_comprehensive_assessment | read | |
bugbounty_file_upload_testing | write | |
bugbounty_osint_gathering | read | |
bugbounty_reconnaissance_workflow | read | |
bugbounty_vulnerability_hunting | read | |
burpsuite_alternative_scan | read | |
burpsuite_scan | read | |
checkov_iac_scan | read | |
checksec_analyze | read | |
clair_vulnerability_scan | read | |
clear_cache | destructive | |
cloudmapper_analysis | read | |
comprehensive_api_audit | read | |
correlate_threat_intelligence | read | |
create_attack_chain_ai | write | |
create_file | write | |
create_scan_summary | write | |
create_vulnerability_report | write | |
dalfox_xss_scan | read | |
delete_file | destructive | |
detect_technologies_ai | read | |
dirb_scan | read | |
dirsearch_scan | read | |
discover_attack_chains | read | |
display_system_metrics | read | |
dnsenum_scan | read | |
docker_bench_security_scan | read | |
dotdotpwn_scan | read | |
enum4linux_ng_advanced | read | |
enum4linux_scan | read | |
error_handling_statistics | read | |
execute_command | write | |
execute_python_script | write | |
exiftool_extract | read | |
falco_runtime_monitoring | read | |
feroxbuster_scan | read | |
ffuf_scan | read | |
fierce_scan | read | |
foremost_carving | read | |
format_tool_output_visual | read | |
gau_discovery | read | |
gdb_analyze | read | |
gdb_peda_debug | read | |
generate_exploit_from_cve | read | |
generate_payload | read | |
get_cache_stats | read | |
get_live_dashboard | read | |
get_process_dashboard | read | |
get_process_status | read | |
get_telemetry | read | |
ghidra_analysis | read | |
gobuster_scan | read | |
graphql_scanner | read | |
hakrawler_crawl | read | |
hashcat_crack | read | |
hashpump_attack | read | |
http_framework_test | read | |
http_intruder | read | Simple Intruder (sniper) fuzzing. Iterates payloads over each param individually. |
http_repeater | write | Send a crafted request (Burp Repeater equivalent). request_spec keys: url, method, headers, cookies, data. |
http_set_rules | write | Set match/replace rules used to rewrite parts of URL/query/headers/body before sending. |
http_set_scope | write | Define in-scope host (and optionally subdomains) so out-of-scope requests are skipped. |
httpx_probe | read | |
hydra_attack | read | |
install_python_package | write | |
intelligent_smart_scan | read | |
jaeles_vulnerability_scan | read | |
john_crack | read | |
jwt_analyzer | read | |
katana_crawl | read | |
kube_bench_cis | read | |
kube_hunter_scan | read | |
libc_database_lookup | read | |
list_active_processes | read | |
list_files | read | |
masscan_high_speed | read | |
metasploit_run | write | |
modify_file | write | |
monitor_cve_feeds | read | |
msfvenom_generate | read | |
nbtscan_netbios | read | |
netexec_scan | read | |
nikto_scan | read | |
nmap_advanced_scan | read | |
nmap_scan | read | |
nuclei_scan | read | |
objdump_analyze | read | |
one_gadget_search | read | |
optimize_tool_parameters_ai | read | |
pacu_exploitation | read | |
paramspider_discovery | read | |
paramspider_mining | read | |
pause_process | read | |
prowler_scan | read | |
pwninit_setup | read | |
pwntools_exploit | read | |
qsreplace_parameter_replacement | read | |
radare2_analyze | read | |
research_zero_day_opportunities | read | |
responder_credential_harvest | read | |
resume_process | read | |
ropgadget_search | read | |
ropper_gadget_search | read | |
rpcclient_enumeration | read | |
rustscan_fast_scan | read | |
scout_suite_assessment | read | |
select_optimal_tools_ai | read | |
server_health | read | |
smbmap_scan | read | |
sqlmap_scan | read | |
steghide_analysis | read | |
strings_extract | read | |
subfinder_scan | read | |
terminate_process | destructive | |
terrascan_iac_scan | read | |
test_error_recovery | read | |
threat_hunting_assistant | read | |
trivy_scan | read | |
uro_url_filtering | read | |
volatility3_analyze | read | |
volatility_analyze | read | |
vulnerability_intelligence_dashboard | read | |
wafw00f_scan | read | |
waybackurls_discovery | read | |
wfuzz_scan | read | |
wpscan_analyze | read | |
x8_parameter_discovery | read | |
xsser_scan | read | |
xxd_hexdump | read | |
zap_scan | read |
Details
- Source
- 0x4m4/hexstrike-ai
- License
- MIT
- Stars
- 11,850 · pushed 40d ago
Trust audit
Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (12 observation(s))
- Network
- declared (19 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
b64decode( ... exec(
{"name": "Cloud Metadata", "payloads": ["http://169.254.169.254/latest/meta-data/"]},resp = requests.get(page_info.get('url',''), timeout=10, verify=False)r = requests.get(test_url, timeout=8, verify=False)
shutil.rmtree(file_path)
os.remove(command_file)
os.remove(resource_file)
os.remove("/tmp/gdb_commands.txt")os.remove("/tmp/r2_commands.txt")valid_attack_types = ["rce", "privilege_escalation", "persistence", "exfiltration", "xss", "sqli", "lfi", "ssrf"]
"Data exfiltration indicators"
"Data staging and exfiltration"
{"name": "DNS Exfiltration", "payloads": ["http://burpcollaborator.net"]}DEFAULT_HEXSTRIKE_SERVER = "http://127.0.0.1:8888" # Default HexStrike server URL
{"name": "Internal Network", "payloads": ["http://127.0.0.1:80", "http://localhost:22"]},{"name": "Cloud Metadata", "payloads": ["http://169.254.169.254/latest/meta-data/"]},'http': f'http://127.0.0.1:{proxy_port}','https': f'http://127.0.0.1:{proxy_port}'clear_cache, delete_file, terminate_process
return hashlib.md5(key_data.encode()).hexdigest()
"basic": ["../../../etc/passwd", "..\\..\\..\\windows\\system32\\drivers\\etc\\hosts"],
header = json.loads(base64.b64decode(header_b64))
payload = json.loads(base64.b64decode(payload_b64))
flask, requests, psutil, fastmcp, beautifulsoup4, selenium, webdriver-manager, aiohttp
assets/leaksapi-logo.png
Gates applied: critical_finding, no_behavioural_pass.
Audited 2026-09-13 · audit v0.4.0 · source sha 876657bfe240 · full audit: observations/trust-audit/mcp-server/0x4m4__hexstrike-ai.json · Report an issue or request a re-scan
Audit history
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-13 | 876657bfe240 | BLOCK | D | 69 | first audit |
Alternatives
Other servers in the same categories, safer ones first.
Questions
What is the HexStrike AI MCP server?
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capa
What tools does HexStrike AI expose?
150 in total: 134 read-only, 13 that write, and 3 that can delete or overwrite (clear_cache, delete_file, terminate_process). Every one is listed on this page with its risk.
Is HexStrike AI safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does HexStrike AI need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (876657bfe240), read on 2026-09-13. The repository is watched and re-audited when it changes.
Provenance: OBSERVED · read 2026-09-13 · job trust-audit-2026-09-13