← MCP servers · 0x4m4

HexStrike AI

BLOCKgrade D · trust 69/100

HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capa

0x4m4aiai agentsai cybersecurityai hackingai penetration testingai security toolartificial intelligence

Overview

From the repository's own README, as read at the audited commit.

<div align="center"><img src="assets/hexstrike-logo.png" alt="HexStrike AI Logo" width="220" style="margin-bottom: 20px;"/># HexStrike AI MCP Agents v6.0### AI-Powered MCP Cybersecurity Automation Platform[![Python](https://img.shields.io/badge/Python-3.8%2B-blue.svg)](https://www.python.org/)[![License](https://img.shields.io/badge/License-MIT-green.svg)](LICENSE)[![Security](https://img.shields.io/badge/Security-Penetration%20Testing-red.svg)](https://github.com/0x4m4/hexstrike-ai)[![MCP](https://img.shields.io/badge/MCP-Compatible-purple.svg)](https://github.com/0x4m4/hexstrike-ai)[![Version](https://img.shields.io/badge/Version-6.0.0-orange.svg)](https://github.com/0x4m4/hexstrike-ai/releases)[![Tools](https://img.shields.io/badge/Security%20Tools-150%2B-brightgreen.svg)](https://github.com/0x4m4/hexstrike-ai)[![Agents](https://img.shields.io/badge/AI%20Agents-12%2B-purple.svg)](https://github.com/0x4m4/hexstrike-ai)[![Stars](https://img.shields.io/github/stars/0x4m4/hexstrike-ai?style=social)](https://github.com/0x4m4/hexstrike-ai)**Advanced AI-powered penetration testing MCP framework with 150+ security tools and 12+ autonomous AI agents****Owned & developed by [OTT Cybersecurity LLC](https://overthetop.ae/)**[📋 What's New](#whats-new-in-v60) • [🏗️ Architecture](#architecture-overview) • [🚀 Installation](#installation) • [🛠️ Features](#features) • [🤖 AI Agents](#ai-agents) • [📡 API Reference](#api-reference)</div>---<div align="center">## Follow Our Social Accounts<p align="center">  <a href="https://discord.gg/BWnmrrSHbA">    <img src="https://img.shields.io/badge/Discord-Join-7289DA?logo=discord&logoColor=white&style=for-the-badge" alt="Join our Discord" />  </a>  &nbsp;&nbsp;  <a href="https://www.linkedin.com/company/hexstrike-ai">    <img src="https://img.shields.io/badge/LinkedIn-Follow%20us-0A66C2?logo=linkedin&logoColor=white&style=for-the-badge" alt="Follow us on LinkedIn" />  </a></p></div>---## Architecture OverviewHexStrike AI MCP v6.0 features a m

Exposed tools (150) 134 read · 13 write · 3 destructive

Blast radius: 3 tools can delete or overwrite. An agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
advanced_payload_generationread
ai_generate_attack_suiteread
ai_generate_payloadread
ai_reconnaissance_workflowread
ai_test_payloadread
ai_vulnerability_assessmentread
amass_scanread
analyze_target_intelligenceread
anew_data_processingread
angr_symbolic_executionread
api_fuzzerread
api_schema_analyzerread
arjun_parameter_discoveryread
arjun_scanread
arp_scan_discoveryread
autorecon_comprehensiveread
autorecon_scanread
binwalk_analyzeread
browser_agent_inspectread
bugbounty_authentication_bypass_testingread
bugbounty_business_logic_testingread
bugbounty_comprehensive_assessmentread
bugbounty_file_upload_testingwrite
bugbounty_osint_gatheringread
bugbounty_reconnaissance_workflowread
bugbounty_vulnerability_huntingread
burpsuite_alternative_scanread
burpsuite_scanread
checkov_iac_scanread
checksec_analyzeread
clair_vulnerability_scanread
clear_cachedestructive
cloudmapper_analysisread
comprehensive_api_auditread
correlate_threat_intelligenceread
create_attack_chain_aiwrite
create_filewrite
create_scan_summarywrite
create_vulnerability_reportwrite
dalfox_xss_scanread
delete_filedestructive
detect_technologies_airead
dirb_scanread
dirsearch_scanread
discover_attack_chainsread
display_system_metricsread
dnsenum_scanread
docker_bench_security_scanread
dotdotpwn_scanread
enum4linux_ng_advancedread
enum4linux_scanread
error_handling_statisticsread
execute_commandwrite
execute_python_scriptwrite
exiftool_extractread
falco_runtime_monitoringread
feroxbuster_scanread
ffuf_scanread
fierce_scanread
foremost_carvingread
format_tool_output_visualread
gau_discoveryread
gdb_analyzeread
gdb_peda_debugread
generate_exploit_from_cveread
generate_payloadread
get_cache_statsread
get_live_dashboardread
get_process_dashboardread
get_process_statusread
get_telemetryread
ghidra_analysisread
gobuster_scanread
graphql_scannerread
hakrawler_crawlread
hashcat_crackread
hashpump_attackread
http_framework_testread
http_intruderreadSimple Intruder (sniper) fuzzing. Iterates payloads over each param individually.
http_repeaterwriteSend a crafted request (Burp Repeater equivalent). request_spec keys: url, method, headers, cookies, data.
http_set_ruleswriteSet match/replace rules used to rewrite parts of URL/query/headers/body before sending.
http_set_scopewriteDefine in-scope host (and optionally subdomains) so out-of-scope requests are skipped.
httpx_proberead
hydra_attackread
install_python_packagewrite
intelligent_smart_scanread
jaeles_vulnerability_scanread
john_crackread
jwt_analyzerread
katana_crawlread
kube_bench_cisread
kube_hunter_scanread
libc_database_lookupread
list_active_processesread
list_filesread
masscan_high_speedread
metasploit_runwrite
modify_filewrite
monitor_cve_feedsread
msfvenom_generateread
nbtscan_netbiosread
netexec_scanread
nikto_scanread
nmap_advanced_scanread
nmap_scanread
nuclei_scanread
objdump_analyzeread
one_gadget_searchread
optimize_tool_parameters_airead
pacu_exploitationread
paramspider_discoveryread
paramspider_miningread
pause_processread
prowler_scanread
pwninit_setupread
pwntools_exploitread
qsreplace_parameter_replacementread
radare2_analyzeread
research_zero_day_opportunitiesread
responder_credential_harvestread
resume_processread
ropgadget_searchread
ropper_gadget_searchread
rpcclient_enumerationread
rustscan_fast_scanread
scout_suite_assessmentread
select_optimal_tools_airead
server_healthread
smbmap_scanread
sqlmap_scanread
steghide_analysisread
strings_extractread
subfinder_scanread
terminate_processdestructive
terrascan_iac_scanread
test_error_recoveryread
threat_hunting_assistantread
trivy_scanread
uro_url_filteringread
volatility3_analyzeread
volatility_analyzeread
vulnerability_intelligence_dashboardread
wafw00f_scanread
waybackurls_discoveryread
wfuzz_scanread
wpscan_analyzeread
x8_parameter_discoveryread
xsser_scanread
xxd_hexdumpread
zap_scanread

Details

Source
0x4m4/hexstrike-ai
License
MIT
Stars
11,850 · pushed 40d ago

Trust audit

Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (12 observation(s))
Network
declared (19 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

CRITICALObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
hexstrike_server.py:7289
b64decode( ... exec(
Why it matters. decodes a payload and executes it
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
hexstrike_server.py:2597
{"name": "Cloud Metadata", "payloads": ["http://169.254.169.254/latest/meta-data/"]},
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
hexstrike_server.py:13766
resp = requests.get(page_info.get('url',''), timeout=10, verify=False)
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
hexstrike_server.py:13844
r = requests.get(test_url, timeout=8, verify=False)
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
hexstrike_server.py:8985
shutil.rmtree(file_path)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
hexstrike_server.py:10696
os.remove(command_file)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
hexstrike_server.py:11081
os.remove(resource_file)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
hexstrike_server.py:11997
os.remove("/tmp/gdb_commands.txt")
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
hexstrike_server.py:12040
os.remove("/tmp/r2_commands.txt")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
hexstrike_mcp.py:4216
valid_attack_types = ["rce", "privilege_escalation", "persistence", "exfiltration", "xss", "sqli", "lfi", "ssrf"]
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
hexstrike_mcp.py:4350
"Data exfiltration indicators"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
hexstrike_mcp.py:4359
"Data staging and exfiltration"
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
hexstrike_server.py:2598
{"name": "DNS Exfiltration", "payloads": ["http://burpcollaborator.net"]}
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
hexstrike_mcp.py:143
DEFAULT_HEXSTRIKE_SERVER = "http://127.0.0.1:8888"  # Default HexStrike server URL
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
hexstrike_server.py:2596
{"name": "Internal Network", "payloads": ["http://127.0.0.1:80", "http://localhost:22"]},
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
hexstrike_server.py:2597
{"name": "Cloud Metadata", "payloads": ["http://169.254.169.254/latest/meta-data/"]},
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
hexstrike_server.py:13298
'http': f'http://127.0.0.1:{proxy_port}',
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
hexstrike_server.py:13299
'https': f'http://127.0.0.1:{proxy_port}'
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_cache, delete_file, terminate_process
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
hexstrike_server.py:6680
return hashlib.md5(key_data.encode()).hexdigest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
hexstrike_server.py:14582
"basic": ["../../../etc/passwd", "..\\..\\..\\windows\\system32\\drivers\\etc\\hosts"],
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
hexstrike_server.py:15041
header = json.loads(base64.b64decode(header_b64))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
hexstrike_server.py:15042
payload = json.loads(base64.b64decode(payload_b64))
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
flask, requests, psutil, fastmcp, beautifulsoup4, selenium, webdriver-manager, aiohttp
Why it matters. 11 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
assets/leaksapi-logo.png
assets/leaksapi-logo.png
Why it matters. 1014134 bytes not read

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-09-13 · audit v0.4.0 · source sha 876657bfe240 · full audit: observations/trust-audit/mcp-server/0x4m4__hexstrike-ai.json · Report an issue or request a re-scan

Audit history

DateSourceVerdictGradeScoreChange
2026-09-13876657bfe240BLOCKD69first audit

Alternatives

Other servers in the same categories, safer ones first.

Questions

What is the HexStrike AI MCP server?

HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capa

What tools does HexStrike AI expose?

150 in total: 134 read-only, 13 that write, and 3 that can delete or overwrite (clear_cache, delete_file, terminate_process). Every one is listed on this page with its risk.

Is HexStrike AI safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does HexStrike AI need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (876657bfe240), read on 2026-09-13. The repository is watched and re-audited when it changes.

Provenance: OBSERVED · read 2026-09-13 · job trust-audit-2026-09-13