HashcatSAFE
MCP wrapper for Hashcat – automate hash cracking with natural language
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A powerful Model Context Protocol (MCP) server that provides intelligent hashcat integration for Claude Desktop. Crack hashes, analyze passwords, and perform security assessments directly from your Claude conversations.
✨ Features
- Smart Hash Identification - Automatically detect hash types with confidence scoring
- Multiple Attack Modes - Dictionary, brute-force, hybrid, and rule-based attacks
- Batch Processing - Crack multiple hashes simultaneously
- Session Management - Track and monitor cracking progress
- GPU Monitoring - Real-time hardware performance metrics
- Password Analysis - Analyze cracked passwords for security insights
- Auto Attack Strategies - Intelligent attack sequence selection
- Security Hardened - Input validation and injection protection
🎬 Demo
Watch the Hashcat MCP Server in action - from hash identification to successful cracking!
🛡️ RootSec Community
Join our cybersecurity community for the latest in offensive security, AI integration, and advanced penetration testing techniques:
🔗 [t.me/root_sec](https://t.me/root_sec)
RootSec is a community of security professionals, researchers, and enthusiasts sharing knowledge about:
- Advanced penetration testing techniques
- AI-powered security tools
- Red team methodologies
- Security research and development
- Industry insights and discussions
🚀 Quick
5d392ea2ec26OBSERVED · 2026-10-09Exposed tools (23)
17 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_cracked_passwords | read | Analyze patterns in cracked passwords |
auto_attack_strategy | write | Automatically choose and execute best attack strategy |
benchmark_hashcat | write | Run hashcat benchmark for specified hash types or all types |
crack_hash | read | Crack a hash using hashcat with various attack modes |
crack_multiple_hashes | read | Crack multiple hashes efficiently with auto-detection |
create_session | write | Create a new hashcat session for tracking |
create_wordlist_rules | write | Generate wordlist variations using hashcat rules |
estimate_crack_time | read | Estimate time to crack based on current hardware performance |
estimate_keyspace | read | Estimate keyspace size for an attack |
generate_mask_attack | destructive | Generate mask attack patterns for brute force |
generate_smart_masks | read | Generate intelligent mask patterns based on common password patterns |
get_backend_info | read | Get system/environment/backend API info |
get_gpu_status | read | Get real-time GPU status and performance metrics |
get_hash_categories | read | Get all available hash categories |
get_hash_info | read | Get information about hash types |
get_session_status | read | Get real-time status of hashcat session |
identify_hash | read | Identify hash type using hashcat |
load_attack_preset | read | Load saved attack preset |
save_attack_preset | write | Save attack configuration as preset |
search_hash_types | read | Search hash types by name or category |
show_cracked_hashes | read | Show previously cracked hashes from potfile |
smart_identify_hash | read | Enhanced hash identification with pattern matching and confidence scoring |
validate_hash_format | read | Validate hash format and detect potential issues |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
generate_mask_attack
fastmcp, python-dotenv
demo.gif
Gates applied: no_behavioural_pass, no_license.
5d392ea2ec26full audit observations/trust-audit/mcp-server/mordavid__hashcat.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 5d392ea2ec26 | SAFE | B | 89 | first audit |
Questions
What is the Hashcat MCP server?
MCP wrapper for Hashcat – automate hash cracking with natural language
What tools does Hashcat expose?
23 in total: 17 read-only, 5 that write, and 1 that can delete or overwrite (generate_mask_attack). Every one is listed on this page with its risk.
Is Hashcat safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Hashcat need?
No credential environment variables were found in its source, so it appears to need none.
How does Hashcat run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (5d392ea2ec26), read on 2026-10-09. The repository is watched and re-audited when it changes.