kali-ssh-mcp
This MCP server connects LLM clients to a persistent Kali Linux VM over SSH, enabling scope-gated nmap, gobuster, nuclei, and nikto scans with structured JSON output and full audit logging.
README
kali-ssh-mcp
⚠️ For authorized security testing only. This tool executes offensive security tooling (nmap, gobuster, nuclei, nikto) against remote targets. Only use it against systems you own or have explicit written authorization to test. See SECURITY.md for the full disclaimer and threat model before use.
An MCP server that bridges an LLM client (Claude Desktop, or any MCP-compatible client) to a persistent Kali Linux VM over SSH — with a hard scope allowlist, structured JSON output, and a full audit log.
Read SECURITY.md before connecting this alongside other MCP tools that can browse the web. Combining always-on tool access with web-fetching creates a real prompt-injection risk — this doc explains the mitigations built in and what you should still do on your end.
Why this exists
There are already several good Kali/pentest MCP servers in the community (PENTEST-MCP-SERVER, pentest-mcp, zebbern-kali-mcp, and others — worth checking out). Almost all of them share one design decision: Kali runs as a disposable Docker container on the same machine as your MCP client. That's a great fit if you want zero setup and don't care about state persisting between sessions.
This project is for the other common setup: you already have a real, long-lived Kali VM — in VMware, VirtualBox, on bare metal, wherever — with your own tool configs, custom wordlists, and scripts already in place, and you don't want to lose that every time a container gets torn down. This server just SSHes into whatever Kali box you already have and drives it, nothing about your existing setup has to change.
| This project | Most Docker-based Kali MCPs | |
|---|---|---|
| Kali environment | Your existing, persistent VM | Fresh container per run |
| State between sessions | Persists (it's your real VM) | Resets unless you mount volumes |
| Setup | SSH key exchange | Docker install + image build |
| Best for | You already run Kali as a daily driver | Zero-setup, throwaway testing |
What it does
Exposes four scanning tools to your MCP client, each scope-gated and returning parsed JSON instead of raw terminal output:
nmap_scan— presets for quick/full/service/vuln scans, or an explicit port specgobuster_scan— directory brute-forcing, with optional session cookie support for authenticated testingnuclei_scan— template-based vulnerability scanning, filterable by severity or template setnikto_scan— web server vulnerability scanning
Plus two read-only utility tools:
list_scope— see the current engagement's allowed targetsget_audit_log— review recent tool calls (allowed and rejected)
Want to add another tool (sqlmap, subfinder, whatweb, ...)? See
EXTENDING.md — the shared scope-gate/audit-log/validation
plumbing means a new tool is usually 20-30 lines, not a rewrite.
Quick start
git clone https://github.com/1337exe/kali-ssh-mcp.git
cd kali-ssh-mcp
python3 -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
pip install -r requirements.txt
cp config.example.yaml config.yaml
Edit config.yaml:
ssh.host— your Kali VM's IPssh.username/ssh.key_path— SSH key auth strongly recommendedscope.targets— only hosts/CIDRs listed here can be scanned; update this every time your authorized scope changes
On the Kali VM, make sure SSH is running and your key is authorized:
sudo systemctl enable --now ssh
Verify the connection manually before wiring up an MCP client:
ssh -i ~/.ssh/your_key user@<kali-vm-ip> "nmap --version"
Run the offline tests (no SSH needed):
python3 test_logic.py
Start the server:
python3 server.py
Connect it to your MCP client — see
examples/claude_desktop_config.md
for a copy-paste Claude Desktop config (macOS, Linux, and Windows). A full
example conversation is in
examples/example_session.md.
Design principles
- Scope is enforced in code, not just convention. Every tool call
checks the target against
config.yaml's allowlist before anything executes on the Kali box. No match, no execution — no exceptions. - The tool whitelist is small and deliberate. Only
nmap_scanandgobuster_scanexist right now. Adding a new tool is a conscious code change (see CONTRIBUTING.md), not something the LLM can do itself. - Structured output only. Raw nmap XML and gobuster text are parsed into JSON before the LLM ever sees them — no asking the model to parse terminal output, which is slower and less reliable.
- Everything is logged. Every call — allowed or rejected — is appended
to
audit_log.jsonl. This is your record of what an LLM session actually did, which matters both for your own review and for anyone asking how a finding was reached.
Roadmap / good first contributions
- A session-capture tool pairing with a browser-automation MCP (Playwright, Claude in Chrome) to pull authenticated cookies automatically instead of pasting them in by hand
- Docker/Portainer-backed tools for long-running scans you don't want tying up the Kali VM directly
sqlmap/subfinder/whatwebwrappers
See EXTENDING.md for exactly what a new tool needs to include before it'll be merged — scope gating and input validation aren't optional. CONTRIBUTING.md covers the PR process itself.
License
MIT — see LICENSE.
Responsible use
This tool is for testing systems you own or are explicitly authorized to test. See SECURITY.md for the full disclaimer and threat model.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。