hexstrike-ai: Connect AI Agents to Security Testing Tools

hexstrike-ai: Connect AI Agents to Security Testing Tools

Summary

HexStrike AI is an MCP server that connects compatible AI agents to cybersecurity tools for authorized penetration testing, vulnerability discovery, and security research. It combines tool execution with specialized agents and workflow support.

At a glance

Language
Python
License
MIT
Stars
12.3k
Forks
2.5k
Added to OSRepos
October 12, 2025
Last analyzed
October 3, 2026
View on GitHub

Topics

Click on any tag to explore related repositories

Use at your own risk

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.

Overview

HexStrike AI is a Python MCP server that lets compatible AI clients invoke a broad collection of cybersecurity tools through an agent-oriented interface. It aims to reduce the manual work of coordinating reconnaissance, testing, and analysis by exposing tool integrations and workflows to AI agents.

It is intended for security researchers, penetration testers, bug bounty participants, and CTF users working on systems they own or are authorized to assess. The server provides powerful command execution capabilities, so it is best treated as security tooling that needs careful oversight, not as an unattended scanner.

Key Features

  • Connects MCP-compatible clients, including Claude Desktop and VS Code Copilot, to a security testing server.
  • Integrates 150+ security tools across network reconnaissance, web testing, cloud security, binary analysis, OSINT, and forensics, according to the project documentation.
  • Includes specialized agents and workflows for tasks such as bug bounty testing, CTFs, CVE intelligence, and tool selection.
  • Provides HTTP endpoints for health checks, target analysis, tool selection, telemetry, and process management.
  • Supports browser-based testing with headless Chrome automation, including page and DOM inspection.
  • Documents caching, process monitoring, and failure recovery features for coordinating tool runs.

Use Cases

  • A penetration tester can connect an MCP client to run selected reconnaissance and vulnerability checks during an authorized assessment.
  • A bug bounty researcher can use the documented workflows to organize discovery and testing within a program's scope.
  • A CTF participant can expose analysis tools to an AI agent while investigating challenge files or services.
  • A security team can evaluate how an AI-assisted workflow coordinates existing tools in an isolated test environment.

Project Facts

  • Language: Python
  • License: MIT
  • Stars: 12.3k
  • Forks: 2.5k
  • Topics: 0x4m4, ai, ai-agents, ai-cybersecurity, ai-hacking, ai-penetration-testing, ai-security-tool, artificial-intelligence, ctf-tools, generative-ai, hexstrike, kali-linux, kali-tools, llm, llm-integration, mcp, mcp-server, mcp-tools, pentesting, pentesting-tools
  • Archived: No

Getting Started

Clone the repository, install its Python requirements, and start the server:

git clone https://github.com/0x4m4/hexstrike-ai.git
cd hexstrike-ai
pip3 install -r requirements.txt
python3 hexstrike_server.py

The server also needs the external security tools required for the tasks you plan to run. See the README for client configuration, tool installation, and further setup details.

Alternatives

  • Argus: Argus runs reconnaissance checks through an interactive CLI, while HexStrike connects AI agents to security tools through MCP and supports broader testing workflows.

Considerations

  • Security tools are external dependencies and must be installed separately; the README lists examples but does not make every tool available through the Python requirements alone.
  • AI agents can execute powerful commands. Use an isolated environment, supervise activity, and test only systems for which you have authorization.
  • The README describes the platform as supporting 150+ tools and 12+ agents, but actual capabilities depend on installed tools and client configuration.
  • The repository was created in 2025 and is not archived. Its README includes self-reported performance and success metrics, which should not be treated as independently verified results.

Comparisons

Source repository

Open the original repository on GitHub.

16 counted GitHub visits

View on GitHub

Related repositories

Similar repositories that may be relevant next.

OS
OSRepos

Analysis and discovery of open source repositories. Find interesting projects and follow their updates.

Monitor your website with YourWebsiteScore

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of third-party repository code is at your own risk. Always review source code, dependencies, licenses, and security implications before running anything.

© 2025 OSRepos. Built with Nuxt 3 and lots of ❤️