Atlas / MCP servers / mordavid / Hashcat

HashcatSAFE

mcp/mordavid/hashcat

MCP wrapper for Hashcat – automate hash cracking with natural language

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
23 17r · 5w · 1d
Transport
stdio
License
—
Stars
26
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful Model Context Protocol (MCP) server that provides intelligent hashcat integration for Claude Desktop. Crack hashes, analyze passwords, and perform security assessments directly from your Claude conversations.

✨ Features

  • Smart Hash Identification - Automatically detect hash types with confidence scoring
  • Multiple Attack Modes - Dictionary, brute-force, hybrid, and rule-based attacks
  • Batch Processing - Crack multiple hashes simultaneously
  • Session Management - Track and monitor cracking progress
  • GPU Monitoring - Real-time hardware performance metrics
  • Password Analysis - Analyze cracked passwords for security insights
  • Auto Attack Strategies - Intelligent attack sequence selection
  • Security Hardened - Input validation and injection protection

🎬 Demo

Watch the Hashcat MCP Server in action - from hash identification to successful cracking!

🛡️ RootSec Community

Join our cybersecurity community for the latest in offensive security, AI integration, and advanced penetration testing techniques:

🔗 [t.me/root_sec](https://t.me/root_sec)

RootSec is a community of security professionals, researchers, and enthusiasts sharing knowledge about:

  • Advanced penetration testing techniques
  • AI-powered security tools
  • Red team methodologies
  • Security research and development
  • Industry insights and discussions

🚀 Quick

Read from source at commit 5d392ea2ec26OBSERVED · 2026-10-09
02

Exposed tools (23)

17 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_cracked_passwordsreadAnalyze patterns in cracked passwords
auto_attack_strategywriteAutomatically choose and execute best attack strategy
benchmark_hashcatwriteRun hashcat benchmark for specified hash types or all types
crack_hashreadCrack a hash using hashcat with various attack modes
crack_multiple_hashesreadCrack multiple hashes efficiently with auto-detection
create_sessionwriteCreate a new hashcat session for tracking
create_wordlist_ruleswriteGenerate wordlist variations using hashcat rules
estimate_crack_timereadEstimate time to crack based on current hardware performance
estimate_keyspacereadEstimate keyspace size for an attack
generate_mask_attackdestructiveGenerate mask attack patterns for brute force
generate_smart_masksreadGenerate intelligent mask patterns based on common password patterns
get_backend_inforeadGet system/environment/backend API info
get_gpu_statusreadGet real-time GPU status and performance metrics
get_hash_categoriesreadGet all available hash categories
get_hash_inforeadGet information about hash types
get_session_statusreadGet real-time status of hashcat session
identify_hashreadIdentify hash type using hashcat
load_attack_presetreadLoad saved attack preset
save_attack_presetwriteSave attack configuration as preset
search_hash_typesreadSearch hash types by name or category
show_cracked_hashesreadShow previously cracked hashes from potfile
smart_identify_hashreadEnhanced hash identification with pattern matching and confidence scoring
validate_hash_formatreadValidate hash format and detect potential issues
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
generate_mask_attack
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastmcp, python-dotenv
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
demo.gif
demo.gif
Why it matters. 2422560 bytes not read

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-09 · audit v0.4.1 · source sha 5d392ea2ec26full audit observations/trust-audit/mcp-server/mordavid__hashcat.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-095d392ea2ec26SAFEB89first audit
05

Questions

What is the Hashcat MCP server?

MCP wrapper for Hashcat – automate hash cracking with natural language

What tools does Hashcat expose?

23 in total: 17 read-only, 5 that write, and 1 that can delete or overwrite (generate_mask_attack). Every one is listed on this page with its risk.

Is Hashcat safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Hashcat need?

No credential environment variables were found in its source, so it appears to need none.

How does Hashcat run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (5d392ea2ec26), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement