HexStrike AI

by 0x4m4

Community Security & Testing 11k likes

HexStrike AI is an MCP server that wires AI agents into 150+ real offensive-security tools, plus a layer of autonomous agents that decide which tools to run and interpret the results.

Clone and run

git clone https://github.com/0x4m4/hexstrike-ai.git && cd hexstrike-ai && pip3 install -r requirements.txt && python3 hexstrike_server.py

Source: https://github.com/0x4m4/hexstrike-ai

About

HexStrike AI MCP Agents gives Claude, GPT, Copilot, and other MCP clients direct command of a large, real security toolkit rather than just descriptions of one: network reconnaissance (Nmap, Masscan, Amass, Subfinder), web app testing (Nuclei, SQLMap, FFuf, WPScan, Nikto), password attacks (Hydra, John the Ripper, Hashcat), binary analysis (Ghidra, Radare2, GDB, Volatility), cloud/container auditing (Prowler, Trivy, Kube-Hunter), and OSINT (Sherlock, Recon-ng, Shodan) are all wired in as callable tools, 150-plus in total across those categories.

On top of the raw tool access sits a layer of 12-plus autonomous agents, including a decision engine that picks appropriate tools for a given target, CVE intelligence and exploit-generation agents, and a dedicated CTF solver, along with a smart caching layer with LRU eviction and browser automation (headless Chrome with DOM analysis and screenshot capture) for testing that needs a real rendered page. It's explicitly built for authorized security work: the project's own usage guidance is to tell the connected model you have authorization to test the target before asking it to run anything.

Key features

  • 150+ real security tools wired in as callable MCP tools across recon, web, auth, binary, cloud, and OSINT categories
  • 12+ autonomous agents including a decision engine, CVE intelligence, and exploit generation
  • Dedicated CTF-solving agent alongside general pentesting workflows
  • Browser automation via headless Chrome with DOM analysis and screenshot capture
  • Smart caching with LRU eviction to avoid redundant tool runs
  • Multi-client support: Claude Desktop, VS Code Copilot, Cursor, Roo Code

Use cases

  • Run an authorized recon-to-exploitation chain against a target you own, driven by natural-language instructions
  • Ask an agent to triage a CVE against a target and suggest (or attempt) a matching exploit path
  • Automate a bug-bounty reconnaissance sweep across subdomains, then hand off interesting findings for deeper testing
  • Solve a CTF binary or web challenge with an agent driving decompilation and exploitation tools directly

Available tools

nmap_scan

Runs network reconnaissance against a target using Nmap and returns structured results.

sqlmap_scan

Runs SQLMap against a target to test for and exploit SQL injection.

decision_engine

Autonomous agent that selects appropriate tools for a given target and objective.

ctf_solver

Autonomous agent dedicated to working through CTF challenges using the available tool set.

Frequently asked questions

Is HexStrike AI safe to point at any target?

No. It's built for authorized security testing only; the project's own guidance is to confirm authorization to test a target before directing the connected model to run tools against it.

Does it just run tools, or does it also decide what to run?

Both. Beneath the 150+ individual security tools sits a layer of 12+ autonomous agents, including a decision engine that selects which tools fit a given target and objective.