Skip to content
Back to skills

Tools Mcp Bridges

ASecurity

Expose CLI security tools to an AI agent through MCP servers — mcp-kali-server generic terminal bridge, MetasploitMCP, pentestMCP Docker bundle, mcp-security-hub, single-tool nmap/nuclei servers. Load when setting up agent-driven tooling on Kali or wiring a new tool into MCP. Signals: mcpServers config, kali-server-mcp, metasploitmcp, pentestmcp, "MCP server for nmap", stdio transport, port 5000/8080/8085.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentsgoshellbashsqldockergitapisecurity

Works with

  • terminal
  • cli
  • api
  • mcp

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add NoorQureshi/SploitAgent --skill tools-mcp-bridges --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Tools Mcp Bridges?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Tools Mcp Bridges
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-tools-mcp-bridges/badge)](https://www.skillsdirectory.com/skills/noorqureshi-tools-mcp-bridges)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: tools-mcp-bridges
description: >
  Expose CLI security tools to an AI agent through MCP servers — mcp-kali-server generic terminal
  bridge, MetasploitMCP, pentestMCP Docker bundle, mcp-security-hub, single-tool nmap/nuclei
  servers. Load when setting up agent-driven tooling on Kali or wiring a new tool into MCP.
  Signals: mcpServers config, kali-server-mcp, metasploitmcp, pentestmcp, "MCP server for nmap",
  stdio transport, port 5000/8080/8085.
domain: tools
type: arsenal
stability: learning
modes: [pentest, bugbounty]
severity: info
tools: [mcp-kali-server, metasploitmcp, pentestmcp, mcp-security-hub, hexstrike-ai]
schema_version: 1
---

# MCP bridges for security tools

## When it applies
You're setting up an agent-driven workflow and need CLI tools (nmap, nuclei, sqlmap, hashcat,
gobuster, Metasploit…) callable as MCP tools instead of raw shell. This is *infrastructure*, not
authorization: registering a tool over MCP never widens scope — `tradecraft-scope-roe` and
`scope.txt` still gate every call. For Burp specifically, see `tools-burp-suite`; for attacking MCP
servers themselves, `ai-mcp-security`.

## Why it works
MCP wraps a tool's CLI behind typed tool definitions, so the agent gets structured parameters and
output instead of scraping terminal text. A generic terminal bridge (mcp-kali-server) covers
everything but is unstructured; per-tool servers give safer, typed interfaces at the cost of setup.

## Options (pick one per need)

| Option | Install | Tools covered | Best for |
|--------|---------|---------------|----------|
| **mcp-kali-server** (Kali-official) | `apt install mcp-kali-server` | Any terminal command (nmap, nxc, curl, gobuster…) | General-purpose; CTF/labs |
| **MetasploitMCP** (Kali-official) | `apt install metasploitmcp` | MSF modules/payloads/sessions | MSF-heavy exploitation (`tools-metasploit`) |
| **pentestMCP** (Docker bundle) | `docker run -d -p 8080:8080 ramkansal/pentestmcp` | 20+: nmap, nuclei, ZAP, sqlmap, ffuf, nikto, gobuster, subfinder, httpx | One-container everything |
| **mcp-security-hub** (modular) | per-module pip installs | nmap, Ghidra, nuclei, sqlmap, hashcat | Enable only what you need |
| **hexstrike-ai** (Kali-official) | `apt install hexstrike-ai` | 150+ tools, multi-agent orchestration | Large-scale automation |
| **Single-tool servers** | npm/pip per project | one tool each (e.g. nmap-mcp-server, nuclei-mcp) | Minimal footprint |

## Method
1. **Generic terminal bridge (start here on Kali):**
   ```bash
   kali-server-mcp --port 5000        # API side; runs any terminal command
   mcp-server --server http://localhost:5000   # MCP client-facing side
   ```
2. **Metasploit:** `metasploitmcp --transport stdio` (preferred) or
   `--transport http --port 8085`. The invocation discipline in `tools-metasploit` still applies
   underneath (one-shot `-x`, `;exit`, port checks).
3. **Docker bundle:** `docker pull ramkansal/pentestmcp && docker run -d -p 8080:8080 ramkansal/pentestmcp`,
   then register `{"url": "http://localhost:8080/mcp"}` in the client's `mcpServers`.
4. **Register stdio servers** in the client config, e.g.:
   ```json
   {
     "mcpServers": {
       "kali-server": { "command": "kali-server-mcp", "args": ["--port", "5000"] },
       "metasploit-mcp": { "command": "metasploitmcp", "args": ["--transport", "stdio"] }
     }
   }
   ```
5. **Verify before relying on it:** list the exposed tools and run one harmless call (e.g. a
   version check) against a lab target before pointing anything at a real engagement.

## Gotchas
- **A terminal bridge is arbitrary command execution** — bind to localhost only, never expose the
  port on a network interface, and treat the bridge host as compromised-adjacent.
- **Community MCP servers are supply chain** — audit or pin versions before installing; a malicious
  tool server sees every command and result. Prefer Kali-official packages when they exist.
- **Scope still applies** — a registered scanner makes it *easier* to fire out-of-scope requests,
  not more allowed. Keep `scope.txt` loaded and check targets against it before every call.
- **Container bundles run as root with mounted sockets** — pentestMCP's Docker has full tool
  capability; don't mount engagement data you can't afford to leak into it.
- **Tool availability ≠ tool correctness** — the server reports what its manifest claims; confirm
  the underlying binary exists and is the expected version (`nmap --version`, etc.).

## Verify success
The MCP client lists the server's tools, a harmless invocation returns sane structured output, and
every subsequent call is logged against an in-scope target in the engagement workspace.

## References
Kali blog on MCP/LLM integration; Wh0am123/MCP-Kali-Server; GH05TCREW/MetasploitMCP;
ramkansal/pentestMCP; FuzzingLabs/mcp-security-hub; 0x4m4/hexstrike-ai.

---
_Portions adapted from [reverse-skill](https://github.com/zhaoxuya520/reverse-skill) by zhaoxuya520, MIT License._

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…