awsome_kali_MCPServers

MCP.Pizza Chef: ccq1

Twenty-seven ready-made commands wrap six command-line security tools, covering network scanning, route tracing, symbol listing, disassembly, readable-text extraction, and packet inspection. Three things to know first: the advertised safe sandbox mode is commented out of the source and never runs, so every command executes directly with no time limit; the image is plain Debian with a few tools added rather than actual Kali Linux; and it writes a startup sentence onto the channel your app reads replies from. Your own files stay invisible to it unless you add a folder share yourself.

Coding
Data

Use This MCP server To

Scan a machine I own and list its open ports Check which services and versions a server is running Pull the readable text out of a program file Read a saved packet capture and summarise the traffic Trace the network path from here to a host Disassemble a binary I am investigating

README

awsome-kali-MCPServers

Overview

Welcome to awsome-kali-MCPServers! This repository is a collection of Model Context Protocol (MCP) servers designed specifically for Kali Linux environments. The goal is to enhance reverse engineering, security testing, and automation workflows by integrating powerful tools and flexible features. Whether you're a security researcher or a developer, this project aims to streamline your tasks with Kali Linux.

Quick Start

Follow these steps to quickly get started with kali-mcps:

  1. Build the Docker Image First, build the Docker image, temporarily named kali-mcps. Run the following command in the project root directory:
docker build -t kali-mcps:latest .
  1. Launch an MCP Client Ensure you have an MCP client installed, such as claude desktop, cline, goose, or roo code. Open your chosen MCP client.
  2. Configure the MCP Client In your MCP client, create a configuration file (e.g., config.json) with the following content:
{
  "mcpServers": {
    "kali-docker": {
      "command": "docker",
      "args": ["run", "-i", "kali-mcps:latest"]
    }
  }
}
  • "kali-docker" is the server name, which you can customize.
  • "command": "docker" specifies that Docker will be used to run the container.
  • "args" defines the Docker run parameters: -i enables interactive mode, and kali-mcps:latest is the image you just built.
  1. Use Kali Tools Once configured, connect to the kali-mcps container via the MCP client and start using the built-in Kali tools (e.g., Nmap, nm, objdump, strings, tshark) for your tasks. Examples include:
  • Run basic_scan for basic network scanning.
  • Run disassemble to disassemble a target file.
  • Run capture_live to capture real-time network traffic.

image

awsome_kali_MCPServers FAQ

Which apps does it work in?
The setup guide covers Claude Desktop, Cline, Goose, and Roo Code, and any app that can launch a local Docker command should work.
Do I need a paid key or an account?
Neither. Nothing signs in anywhere; every tool runs on your own machine inside a container you build.
Is the sandbox real?
No, and this matters. The code that would run commands inside an isolated container is commented out, so the IS_SAFE setting changes nothing and everything runs directly.
Can I use this to check my own home network?
Yes — but only ever scan machines you own or have written permission to test, because port and vulnerability scanning other people's systems is illegal in many countries.
Can it look at a file on my computer?
Not as documented. The container is started without access to your folders, so file-based tools see nothing until you add a share yourself.
Is it actually Kali Linux?
No. Despite the name, the image is Debian with nmap, binutils, traceroute, and tshark installed.
Can I set the minimum length or the encoding for text extraction?
No, even though the write-up implies it. Those settings are fixed in the code and are not offered as choices, so three of the text tools behave the same way.
How hard is setup?
You build a container image from the source and paste a snippet into your app's settings, so you need some comfort with a terminal.
Is it finished?
The author calls it early-stage, and the last code change was November 2025.