MetasploitMCP

MCP.Pizza Chef: GH05TCREW

Penetration testers already run Metasploit; this puts a conversation in front of it. An assistant can search the exploit and payload catalogue, set up and launch a module against a target you are authorised to test, open a listener, list live sessions and run commands inside them. Nothing here is gentle, and the authors stress that it should only touch systems you have permission to attack. You need Metasploit installed with its background service running, plus Python 3.10 or newer.

Coding
Other

Use This MCP server To

Find the right exploit module for a known weakness Launch a test exploit against my own lab machine List the sessions I currently have open Run a command inside an active session Generate a payload file for a lab exercise Start a listener and shut it down afterwards

README

Metasploit MCP Server

A Model Context Protocol (MCP) server for Metasploit Framework integration.

22829111.mp4

Description

This MCP server provides a bridge between large language models like Claude and the Metasploit Framework penetration testing platform. It allows AI assistants to dynamically access and control Metasploit functionality through standardized tools, enabling a natural language interface to complex security testing workflows.

Features

Module Information

  • list_exploits: Search and list available Metasploit exploit modules
  • list_payloads: Search and list available Metasploit payload modules with optional platform and architecture filtering

Exploitation Workflow

  • run_exploit: Configure and execute an exploit against a target with options to run checks first
  • run_auxiliary_module: Run any Metasploit auxiliary module with custom options
  • run_post_module: Execute post-exploitation modules against existing sessions

MetasploitMCP FAQ

Which apps does it work in?
Claude Desktop is documented in detail, and other MCP clients can connect through its web mode instead.
Do I need Metasploit already installed?
Yes. This drives an existing Metasploit installation and needs its background service started first.
Is a paid key required?
No key, but you set a password for the Metasploit service and pass that through in the configuration.
Can I use this to practise on lab machines and capture-the-flag boxes?
Yes. Working through practice targets is exactly the case shown in the project's demo videos.
How hard is setup?
Developer level. Python 3.10 or newer, a package install, and starting the Metasploit service by hand.
Is it safe?
Only in a lab. It can run real attacks, so the authors insist on segregated test environments or written authorisation.