Kali GoSAFE
MCP runtime for AI-assisted security testing with Kali tools, explicit target controls, bounded scanning, structured evidence, and persistent Docker deployment.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Concurrent, policy-aware MCP runtime for authorized security testing with Kali tooling. It connects AI clients to a provisioned security environment while keeping target selection, scan limits, execution evidence, and tool safety explicit.
[](https://go.dev/) [](https://goreportcard.com/report/github.com/found-cake/kali-mcp-go) [](https://github.com/found-cake/kali-mcp-go/releases/latest)
Contents
- Highlights · Architecture
- Prerequisites · Installation
- Usage: Launch mode · Client registration · First assessment
- Configuration
- Available tools
- Detailed reference
- Project structure · Security notice
Highlights
33b2624877caOBSERVED · 2026-10-09Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
scan_job_cancel | read | Request cancellation of a running asynchronous tool job. |
scan_job_result | read | Read the existing ToolResult from an asynchronous tool job; after process exit, terminal results remain available for the requested execution timeout plus a three-minute grace period. |
scan_job_status | read | Inspect pending progress or terminal status for an asynchronous tool job. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (8)
{name: "SQLMap DNS exfiltration", build: func() error {{name: "sqlmap context DNS exfiltration", build: func() error {{name: "sqlmap receipt DNS exfiltration", build: func() error {--server http://127.0.0.1:5000 \
docker exec kali-mcp curl -fsS http://127.0.0.1:5000/health
--server http://127.0.0.1:5000 \
--server http://127.0.0.1:5000 --timeout 3600
"--server", "http://127.0.0.1:5000",
Gates applied: no_behavioural_pass.
33b2624877cafull audit observations/trust-audit/mcp-server/found-cake__kali-go.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 33b2624877ca | SAFE | B | 89 | first audit |
Questions
What is the Kali Go MCP server?
MCP runtime for AI-assisted security testing with Kali tools, explicit target controls, bounded scanning, structured evidence, and persistent Docker deployment.
What tools does Kali Go expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Kali Go safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Kali Go need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (33b2624877ca), read on 2026-10-09. The repository is watched and re-audited when it changes.