# HexStrike AI MCP Agents: Running 150+ Security Tools Through Claude, GPT, and Copilot

> HexStrike AI MCP Agents v6.0 is a Python MCP server that exposes over 150 offensive security tools to AI clients including Claude Desktop, VS Code Copilot, and Cursor. Security professionals doing authorized penetration testing and bug bounty work can invoke network scanners, web application fuzzers, and binary analysis utilities through a single interface rather than switching between dozens of command-line tools.

**0x4m4/hexstrike-ai** — HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.

- Repository: https://github.com/0x4m4/hexstrike-ai
- Website: https://www.hexstrike.com/
- Stars: 11,931 · Forks: 2,448
- Language: Python
- License: MIT
- Published: 2026-09-09 · Updated: 2026-09-09 · Language: en
- Canonical page: https://hysenlabs.com/projects/0x4m4-hexstrike-ai

## What HexStrike AI Solves and Who Should Use It

Running a penetration test manually means context-switching across dozens of tools: nmap for discovery, gobuster for directory brute-force, sqlmap for injection testing, hydra for credential attacks, and so on. Each tool has its own argument syntax, output format, and failure modes. HexStrike AI MCP Agents v6.0 addresses this by wrapping all those tools inside a Model Context Protocol server, so an AI client can invoke them through structured function calls rather than direct CLI invocations.

The target audience is security professionals conducting authorized engagements: penetration testers, bug bounty hunters, and security researchers. The README identifies OTT Cybersecurity LLC as the owner and developer. This is not a defensive monitoring tool, a SIEM integration, or a compliance scanner. The README makes no claim of suitability for regulated environments or deployments that require audit trails from the scanning layer itself.

## Multi-Agent Architecture and the FastMCP Protocol

The README describes the server's internals in three subsystems. The Intelligent Decision Engine sits at the center, holding a Tool Selection AI component that chooses which underlying tool to call and a Parameter Optimization component that assembles the correct flags for a given target. A second layer consists of twelve or more autonomous AI agents, each handling a domain such as network reconnaissance, web application testing, or binary analysis. A third component, the Visual Engine, renders output with vulnerability cards and risk analysis summaries.

Client connections use FastMCP. The Python package fastmcp, pinned at version 0.2.0 or later per requirements.txt, handles the MCP transport layer. Flask provides the underlying REST API. Any MCP-compatible client receives the server's tool catalog and can request individual tools by name without knowing the CLI syntax of nmap, sqlmap, or any other specific tool.

Beyond fastmcp, the Python dependencies include requests and aiohttp for HTTP communication, psutil for system utilities, and mitmproxy for proxy-based testing. The browser agent subsystem adds BeautifulSoup4, Selenium, and webdriver-manager, which means Chrome or Chromium must be installed separately on the host.

## Installing HexStrike AI and Starting the Server

The setup follows four steps documented in the README: clone the repository, create a Python virtual environment, install dependencies, and start the server.

```bash
git clone https://github.com/0x4m4/hexstrike-ai.git
cd hexstrike-ai
```

Create and activate a virtual environment to isolate the Python packages:

```bash
python3 -m venv hexstrike-env
source hexstrike-env/bin/activate
```

Install the Python packages from the requirements file. The file specifies version ranges rather than pinned versions, so different patch releases may be pulled over time:

```bash
pip3 install -r requirements.txt
```

Start the server. The README documents a plain start, a debug mode, and a custom port flag:

```bash
python3 hexstrike_server.py
python3 hexstrike_server.py --debug
python3 hexstrike_server.py --port 8888
```

Verify the server is accepting connections before attaching a client:

```bash
curl http://localhost:8888/health
```

Separately, each underlying security tool must be installed on the host. The README gives apt-based install examples grouped by category: a network and reconnaissance block that includes nmap, masscan, rustscan, amass, and subfinder; a web application security block covering gobuster, feroxbuster, sqlmap, and nikto; a password and authentication block with hydra, john, and hashcat; and a binary analysis block that includes gdb, radare2, binwalk, ghidra, and volatility3. Cloud security tools listed include prowler, scout-suite, trivy, kube-hunter, kube-bench, and docker-bench-security. The README provides only apt-based Linux install examples for these tools, making Kali Linux the natural host platform.

## Configuring Claude Desktop and VS Code Copilot

Registering the server with an AI client requires editing the client's MCP configuration file. For Claude Desktop and Cursor, the README specifies editing `~/.config/Claude/claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "hexstrike-ai": {
      "command": "python3",
      "args": [
        "/path/to/hexstrike-ai/hexstrike_mcp.py",
        "--server",
        "http://localhost:8888"
      ],
      "description": "HexStrike AI v6.0 - Advanced Cybersecurity Automation Platform",
      "timeout": 300,
      "disabled": false
    }
  }
}
```

For VS Code Copilot, the configuration goes into `.vscode/settings.json`:

```json
{
  "servers": {
    "hexstrike": {
      "type": "stdio",
      "command": "python3",
      "args": [
        "/path/to/hexstrike-ai/hexstrike_mcp.py",
        "--server",
        "http://localhost:8888"
      ]
    }
  },
  "inputs": []
}
```

The timeout of 300 seconds in the Claude Desktop configuration reflects the potentially long execution time of tools like AutoRecon, which the README describes as running 35 or more parameters. The README notes that Roo Code is supported and that 5ire version 0.14.0 is not currently supported.

## The Tool Arsenal: Categories, Scope, and Missing Tool Behavior

The README groups the 150+ tools into categories. Network reconnaissance and scanning lists more than 25 tools including rustscan (described as ultra-fast), masscan (high-speed), and autorecon (comprehensive automated reconnaissance with 35+ parameters). The web application security category includes gobuster, feroxbuster, ffuf, dirsearch, katana, nikto, sqlmap, wpscan, dalfox, wafw00f, arjun, and paramspider. Password and authentication tools cover hydra, john, hashcat, medusa, and crackmapexec. Binary analysis and reverse engineering includes gdb, radare2, binwalk, ghidra, checksec, volatility3, foremost, steghide, and exiftool.

Cloud security gets a separate grouping: prowler, scout-suite, trivy, kube-hunter, kube-bench, and docker-bench-security.

A significant operational constraint is that the server depends entirely on the host having each tool installed. If nmap or sqlmap is absent from the host path, the corresponding AI agent call fails. The README does not document how the server communicates a missing tool error to the calling AI client, which means the client may receive a cryptic error or a silent failure during an active engagement. This is a real operational risk when running the server on a freshly provisioned system or when tools are removed or renamed during an OS upgrade.

## Where HexStrike AI Falls Short: No Releases, No API Auth, Legal Scope

The repository has no GitHub releases. The version number 6.0 appears only in the README heading. Teams that require pinned, reproducible builds have no formal artifact to reference. Tracking changes between deployments means reading raw commit history.

The REST API on port 8888 has no documented authentication mechanism. The README shows both a /health endpoint and a /api/intelligence/analyze-target endpoint accessible with plain curl calls and no authorization header. Running the server on any interface other than localhost without adding authentication at the network layer exposes every tool in the arsenal to anyone who can reach that port.

Compared to running security tools individually from the command line, HexStrike AI adds a layer of abstraction that may help with workflow orchestration but introduces new dependencies: a running Python server, a compatible AI client version, and a working MCP configuration. If any layer fails, debugging requires isolating whether the problem is in the AI client, the MCP transport, the Flask server, or the underlying tool. The README does not document a troubleshooting procedure for this layered failure mode.

All tools in the arsenal require explicit written authorization from the target system owner before use. Running automated reconnaissance or exploitation attempts against systems without permission violates computer misuse laws in most jurisdictions.

## Maintenance, Licence, and Ownership

The repository is not archived. The last push was on 2026-08-03. HexStrike AI MCP Agents is released under the MIT licence, which permits use, modification, and redistribution. The README identifies OTT Cybersecurity LLC as the owner and developer, with a homepage at hexstrike.com.

The MIT licence covers the server code only. Each of the 150+ security tools in the arsenal carries its own licence. Some are permissively licensed (ghidra under Apache 2.0, hashcat under MIT), and others carry restrictions that vary by distribution. The README does not enumerate the licensing terms for the tools it invokes, so organizations with licence compliance requirements should audit each tool individually.

The absence of releases means upgrade cost is undefined. Running git pull on master will incorporate whatever the maintainers have pushed since the last update. There is no changelog file listed in the top-level repository entries, so evaluating the scope of changes between updates requires reading the commit log directly.

## Conclusion

Authorized penetration testers and bug bounty hunters who already use Claude Desktop, VS Code Copilot, Cursor, or Roo Code will find HexStrike AI useful for orchestrating multi-tool reconnaissance and vulnerability workflows through natural language. The absence of GitHub releases means there is no formal artifact to pin or roll back to, which matters for teams with reproducibility requirements. Before integrating, confirm that the required underlying tools such as nmap, sqlmap, and ghidra are installed and reachable from the server path, and verify the server starts cleanly with curl http://localhost:8888/health.

## FAQ

### What is HexStrike AI?

HexStrike AI MCP Agents v6.0 is a Python-based MCP server developed by OTT Cybersecurity LLC. It allows AI clients such as Claude Desktop, VS Code Copilot, and Cursor to invoke over 150 cybersecurity tools for automated penetration testing, vulnerability discovery, and bug bounty automation.

### How do I install HexStrike AI?

Clone the repository, create a Python virtual environment, run pip3 install -r requirements.txt, then start the server with python3 hexstrike_server.py. The server listens on port 8888 by default. Security tools such as nmap, sqlmap, and hydra must be installed separately on the host.

### How do I use HexStrike AI?

Start the local server and confirm it responds at http://localhost:8888/health, then add the hexstrike-ai entry to your AI client's MCP configuration file. For Claude Desktop, edit ~/.config/Claude/claude_desktop_config.json to point hexstrike_mcp.py at --server http://localhost:8888.

### Is HexStrike AI open source?

Yes. The server code is released under the MIT licence and the repository is public on GitHub. OTT Cybersecurity LLC is listed as the owner and developer.

## Sources

- [0x4m4/hexstrike-ai on GitHub](https://github.com/0x4m4/hexstrike-ai)
- [Issues](https://github.com/0x4m4/hexstrike-ai/issues)
- [License: MIT](https://github.com/0x4m4/hexstrike-ai/blob/master/LICENSE)
- [Project website](https://www.hexstrike.com/)
- [README](https://github.com/0x4m4/hexstrike-ai/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/0x4m4-hexstrike-ai
