Atlas / MCP servers / ccq1 / Awsome Kali

Awsome KaliSAFE

mcp/ccq1/awsome-kali

awsome kali MCPServers is a set of MCP servers tailored for Kali Linux

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
27 27r · 0w · 0d
Transport
stdio
License
Apache-2.0
Stars
106
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Overview

Welcome to awsome-kali-MCPServers! This repository is a collection of Model Context Protocol (MCP) servers designed specifically for Kali Linux environments. The goal is to enhance reverse engineering, security testing, and automation workflows by integrating powerful tools and flexible features. Whether you're a security researcher or a developer, this project aims to streamline your tasks with Kali Linux.

Quick Start

Follow these steps to quickly get started with kali-mcps:

  1. Build the Docker Image

First, build the Docker image, temporarily named kali-mcps. Run the following command in the project root directory:

docker build -t kali-mcps:latest .
  1. Launch an MCP Client

Ensure you have an MCP client installed, such as claude desktop, cline, goose, or roo code. Open your chosen MCP client.

  1. Configure the MCP Client

In your MCP client, create a configuration file (e.g., config.json) with the following content:

{
"mcpServers": {
"kali-docker": {
"command": "docker",
"args": ["run", "-i", "kali-mcps:latest"]
}
}
}
  • "kali-docker" is the server name, which you can customize.
  • "command": "docker" specifies that Docker will be used to run the container.
  • "args" defines the Docker run parameters: -i enables interactive mode, and kali-mcps:latest is the image you just built.
  1. Use Kali Tools

Once configured, connect to the kali-mcps container via the MCP client and start using the built-in Kali tools (e.g., Nmap, nm, objdump, strings, tshark) for your tasks. Examples include:

  • Run basic_scan for basic network scanning.
  • Run disassemble to disassemble a target file.
  • Run capture_live to capture real-time network traffic.

What to Expect

Network Analysis: Tools for sniffing and analyzing traffic.

Read from source at commit 9635549dbd28OBSERVED · 2026-10-07
02

Exposed tools (27)

27 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_pcapreadPerform an analysis of a pcap file using tshark.
basic_scanreadPerform a basic network scan using nmap.
basic_stringsreadPerform a basic string listing using strings.
basic_symbolsreadPerform a basic symbol listing using nm.
capture_livereadPerform a live capture of network traffic using tshark.
conversation_statisticsreadPerform a conversation statistics listing using tshark.
demangle_symbolsreadPerform a demangling of symbols using nm.
disassemblereadPerform a disassembly of the target file using objdump.
dynamic_symbolsreadPerform a dynamic symbol listing using nm.
encoding_stringsreadPerform an encoding string listing using strings.
expert_inforeadPerform an expert information listing using tshark.
extract_httpreadPerform an HTTP extraction from a pcap file using tshark.
file_headersreadPerform a file header listing using objdump.
full_contentsreadPerform a full contents listing using objdump.
intense_scanreadPerform an intense network scan using nmap.
min_length_stringsreadPerform a minimum length string listing using strings.
numeric_sortreadPerform a numeric sort of symbols using nm.
offset_stringsreadPerform an offset string listing using strings.
protocol_hierarchyreadPerform a protocol hierarchy listing using tshark.
quick_scanreadPerform a quick network scan using nmap.
section_headersreadPerform a section header listing using objdump.
size_sortreadPerform a size sort of symbols using nm.
stealth_scanreadPerform a stealth network scan using nmap.
symbol_tablereadPerform a symbol table listing using objdump.
tracerouteread
undefined_symbolsreadPerform an undefined symbol listing using nm.
vulnerability_scanreadPerform a vulnerability scan using nmap.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/kali_mcps/strings/actions.py:53
input_file = bytes.fromhex("68656c6c6f20776f726c64")

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 9635549dbd28full audit observations/trust-audit/mcp-server/ccq1__awsome-kali.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-079635549dbd28SAFEB89first audit
05

Questions

What is the Awsome Kali MCP server?

awsome kali MCPServers is a set of MCP servers tailored for Kali Linux

What tools does Awsome Kali expose?

27 in total: 27 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Awsome Kali safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Awsome Kali need?

No credential environment variables were found in its source, so it appears to need none.

How does Awsome Kali run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (9635549dbd28), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement