Overview
HexStrike AI is an MCP server that sits between an AI client and the security tools already installed on your machine. Instead of teaching an agent to shell out to each scanner with its own flags, you point the agent at HexStrike and it gets one protocol-level interface covering more than 150 tools across reconnaissance, web testing, password attacks, binary analysis, cloud and container auditing, forensics and OSINT.
The project ships in two halves: `hexstrike_server.py`, a long-running server that owns the tool executions, and `hexstrike_mcp.py`, the MCP adapter an client such as Claude Desktop, Cursor, VS Code Copilot or Roo Code launches and talks to. The server does not bundle the tools themselves — Nmap, Gobuster, Ghidra and the rest are installed separately, and HexStrike wraps whatever it finds.
This is offensive-security tooling: it is built for penetration testing, bug-bounty work and security research on systems you are authorised to test. Treat the agent as you would any operator holding the same tools, and scope it accordingly.
What it does
- One MCP surface over 150+ existing security tools, so an agent does not need a bespoke wrapper per scanner
- Network reconnaissance via Nmap, Rustscan, Masscan, Amass and Subfinder
- Web application testing via Gobuster, SQLMap, WPScan, Nuclei and Nikto
- Binary analysis and reverse engineering via Ghidra, Radare2, GDB and Binwalk
- Cloud and container auditing via Prowler, Trivy and Kube-Hunter
- Authentication testing (Hydra, Hashcat, John the Ripper) plus CTF, forensics and OSINT tooling
- Client-agnostic: works with any MCP-compatible assistant, including Claude, Cursor, VS Code Copilot and Roo Code
Getting started
HexStrike runs as a local server that your MCP client connects to. The underlying security tools must already be installed and on your PATH — HexStrike orchestrates them, it does not ship them.
Clone the repository and create a virtualenv
The README uses a project-local environment named hexstrike-env.
git clone https://github.com/0x4m4/hexstrike-ai.git
cd hexstrike-ai
python3 -m venv hexstrike-env
source hexstrike-env/bin/activateInstall the Python dependencies
pip3 install -r requirements.txtStart the server
Runs in the foreground and owns every tool execution. Add --debug for verbose logs or --port to move it off the default.
python3 hexstrike_server.py
# or: python3 hexstrike_server.py --port 8888 --debugPoint your MCP client at it
For Claude Desktop, add the MCP adapter to claude_desktop_config.json and restart the app. The adapter connects out to the server you started above.
{
"mcpServers": {
"hexstrike-ai": {
"command": "python3",
"args": [
"/path/to/hexstrike-ai/hexstrike_mcp.py",
"--server",
"http://localhost:8888"
]
}
}
}Commands and code are distilled from the project's own documentation — always check the official repo for the latest.
When to use it
- Reach for it when you want an assistant to run an authorised penetration test end to end, chaining recon into scanning into exploitation attempts
- Reach for it for bug-bounty reconnaissance, where the value is breadth of tooling rather than one scanner
- Reach for it during CTFs, where the forensics, OSINT and binary-analysis wrappers cover most challenge categories
- Reach for it when you already have a hardened tool install and want an agent to use it, rather than a hosted scanner that sees your targets
How HexStrike AI compares
HexStrike AI alongside other open-source security agents tools AI/TLDR tracks, ranked by GitHub stars.
| Tool | Stars | What it does |
|---|---|---|
| PentAGI | ★ 25.2k | PentAGI is a self-hosted AI security platform that plans and runs penetration tests autonomously using a team of agents and 20+ built-in pentesting tools. |
| PentestGPT | ★ 15.7k | An open-source agent that uses large language models to run penetration tests and solve security challenges, either fully autonomously or with a human in the loop. |
| IDA Pro MCP | ★ 12.4k | An MCP server and IDA Pro plugin that exposes decompilation, cross-references, renaming and type editing to an LLM client, letting an agent read and annotate a binary inside your IDA database. |
| HexStrike AI | ★ 12.3k | Give an AI agent one interface to 150+ security tools |
| CAI | ★ 9.8k | CAI (Cybersecurity AI) is an open-source Python framework for building AI agents that automate offensive and defensive security tasks like recon, vulnerability discovery, and exploitation. |
| AI-Infra-Guard | ★ 6.7k | Tencent Zhuque Lab's AI red teaming platform: scans agents, Agent Skills and MCP servers, checks AI infra against a CVE library, fingerprints API relays and runs jailbreak evaluations. |
| T3MP3ST | ★ 6.3k | A multi-agent offensive-security harness for authorised testing that drives an already-installed coding agent, or a local OpenAI-compatible model, through recon, exploitation and reporting from a localhost War Room or the CLI. |
| RedAmon | ★ 2.9k | A Docker-deployed offensive-security platform for authorised testing that chains parallel recon, exploitation and post-exploitation into a Neo4j attack graph, then triages the findings and opens remediation pull requests on your repository. |