█

AI/TLDR

HexStrike AI

Give an AI agent one interface to 150+ security tools

Security AgentsOpen source
Language
Python
License
MIT
$git clone https://github.com/0x4m4/hexstrike-ai.git

Overview

HexStrike AI is an MCP server that sits between an AI client and the security tools already installed on your machine. Instead of teaching an agent to shell out to each scanner with its own flags, you point the agent at HexStrike and it gets one protocol-level interface covering more than 150 tools across reconnaissance, web testing, password attacks, binary analysis, cloud and container auditing, forensics and OSINT.

The project ships in two halves: `hexstrike_server.py`, a long-running server that owns the tool executions, and `hexstrike_mcp.py`, the MCP adapter an client such as Claude Desktop, Cursor, VS Code Copilot or Roo Code launches and talks to. The server does not bundle the tools themselves — Nmap, Gobuster, Ghidra and the rest are installed separately, and HexStrike wraps whatever it finds.

This is offensive-security tooling: it is built for penetration testing, bug-bounty work and security research on systems you are authorised to test. Treat the agent as you would any operator holding the same tools, and scope it accordingly.

What it does

  • One MCP surface over 150+ existing security tools, so an agent does not need a bespoke wrapper per scanner
  • Network reconnaissance via Nmap, Rustscan, Masscan, Amass and Subfinder
  • Web application testing via Gobuster, SQLMap, WPScan, Nuclei and Nikto
  • Binary analysis and reverse engineering via Ghidra, Radare2, GDB and Binwalk
  • Cloud and container auditing via Prowler, Trivy and Kube-Hunter
  • Authentication testing (Hydra, Hashcat, John the Ripper) plus CTF, forensics and OSINT tooling
  • Client-agnostic: works with any MCP-compatible assistant, including Claude, Cursor, VS Code Copilot and Roo Code

Getting started

HexStrike runs as a local server that your MCP client connects to. The underlying security tools must already be installed and on your PATH — HexStrike orchestrates them, it does not ship them.

Clone the repository and create a virtualenv

The README uses a project-local environment named hexstrike-env.

bashbash
git clone https://github.com/0x4m4/hexstrike-ai.git
cd hexstrike-ai
python3 -m venv hexstrike-env
source hexstrike-env/bin/activate

Install the Python dependencies

bashbash
pip3 install -r requirements.txt

Start the server

Runs in the foreground and owns every tool execution. Add --debug for verbose logs or --port to move it off the default.

bashbash
python3 hexstrike_server.py
# or: python3 hexstrike_server.py --port 8888 --debug

Point your MCP client at it

For Claude Desktop, add the MCP adapter to claude_desktop_config.json and restart the app. The adapter connects out to the server you started above.

jsonjson
{
  "mcpServers": {
    "hexstrike-ai": {
      "command": "python3",
      "args": [
        "/path/to/hexstrike-ai/hexstrike_mcp.py",
        "--server",
        "http://localhost:8888"
      ]
    }
  }
}

Commands and code are distilled from the project's own documentation — always check the official repo for the latest.

When to use it

  • Reach for it when you want an assistant to run an authorised penetration test end to end, chaining recon into scanning into exploitation attempts
  • Reach for it for bug-bounty reconnaissance, where the value is breadth of tooling rather than one scanner
  • Reach for it during CTFs, where the forensics, OSINT and binary-analysis wrappers cover most challenge categories
  • Reach for it when you already have a hardened tool install and want an agent to use it, rather than a hosted scanner that sees your targets

How HexStrike AI compares

HexStrike AI alongside other open-source security agents tools AI/TLDR tracks, ranked by GitHub stars.

ToolStarsWhat it does
PentAGI★ 25.2kPentAGI is a self-hosted AI security platform that plans and runs penetration tests autonomously using a team of agents and 20+ built-in pentesting tools.
PentestGPT★ 15.7kAn open-source agent that uses large language models to run penetration tests and solve security challenges, either fully autonomously or with a human in the loop.
IDA Pro MCP★ 12.4kAn MCP server and IDA Pro plugin that exposes decompilation, cross-references, renaming and type editing to an LLM client, letting an agent read and annotate a binary inside your IDA database.
HexStrike AI★ 12.3kGive an AI agent one interface to 150+ security tools
CAI★ 9.8kCAI (Cybersecurity AI) is an open-source Python framework for building AI agents that automate offensive and defensive security tasks like recon, vulnerability discovery, and exploitation.
AI-Infra-Guard★ 6.7kTencent Zhuque Lab's AI red teaming platform: scans agents, Agent Skills and MCP servers, checks AI infra against a CVE library, fingerprints API relays and runs jailbreak evaluations.
T3MP3ST★ 6.3kA multi-agent offensive-security harness for authorised testing that drives an already-installed coding agent, or a local OpenAI-compatible model, through recon, exploitation and reporting from a localhost War Room or the CLI.
RedAmon★ 2.9kA Docker-deployed offensive-security platform for authorised testing that chains parallel recon, exploitation and post-exploitation into a Neo4j attack graph, then triages the findings and opens remediation pull requests on your repository.