hexstrike-ai: Connect AI Agents to Security Testing Tools

Summary
HexStrike AI is an MCP server that connects compatible AI agents to cybersecurity tools for authorized penetration testing, vulnerability discovery, and security research. It combines tool execution with specialized agents and workflow support.
At a glance
- Language
- Python
- License
- MIT
- Stars
- 12.3k
- Forks
- 2.5k
- Added to OSRepos
- October 12, 2025
- Last analyzed
- October 3, 2026
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
HexStrike AI is a Python MCP server that lets compatible AI clients invoke a broad collection of cybersecurity tools through an agent-oriented interface. It aims to reduce the manual work of coordinating reconnaissance, testing, and analysis by exposing tool integrations and workflows to AI agents.
It is intended for security researchers, penetration testers, bug bounty participants, and CTF users working on systems they own or are authorized to assess. The server provides powerful command execution capabilities, so it is best treated as security tooling that needs careful oversight, not as an unattended scanner.
Key Features
- Connects MCP-compatible clients, including Claude Desktop and VS Code Copilot, to a security testing server.
- Integrates 150+ security tools across network reconnaissance, web testing, cloud security, binary analysis, OSINT, and forensics, according to the project documentation.
- Includes specialized agents and workflows for tasks such as bug bounty testing, CTFs, CVE intelligence, and tool selection.
- Provides HTTP endpoints for health checks, target analysis, tool selection, telemetry, and process management.
- Supports browser-based testing with headless Chrome automation, including page and DOM inspection.
- Documents caching, process monitoring, and failure recovery features for coordinating tool runs.
Use Cases
- A penetration tester can connect an MCP client to run selected reconnaissance and vulnerability checks during an authorized assessment.
- A bug bounty researcher can use the documented workflows to organize discovery and testing within a program's scope.
- A CTF participant can expose analysis tools to an AI agent while investigating challenge files or services.
- A security team can evaluate how an AI-assisted workflow coordinates existing tools in an isolated test environment.
Project Facts
- Language: Python
- License: MIT
- Stars: 12.3k
- Forks: 2.5k
- Topics: 0x4m4, ai, ai-agents, ai-cybersecurity, ai-hacking, ai-penetration-testing, ai-security-tool, artificial-intelligence, ctf-tools, generative-ai, hexstrike, kali-linux, kali-tools, llm, llm-integration, mcp, mcp-server, mcp-tools, pentesting, pentesting-tools
- Archived: No
Getting Started
Clone the repository, install its Python requirements, and start the server:
git clone https://github.com/0x4m4/hexstrike-ai.git
cd hexstrike-ai
pip3 install -r requirements.txt
python3 hexstrike_server.py
The server also needs the external security tools required for the tasks you plan to run. See the README for client configuration, tool installation, and further setup details.
Alternatives
- Argus: Argus runs reconnaissance checks through an interactive CLI, while HexStrike connects AI agents to security tools through MCP and supports broader testing workflows.
Considerations
- Security tools are external dependencies and must be installed separately; the README lists examples but does not make every tool available through the Python requirements alone.
- AI agents can execute powerful commands. Use an isolated environment, supervise activity, and test only systems for which you have authorization.
- The README describes the platform as supporting 150+ tools and 12+ agents, but actual capabilities depend on installed tools and client configuration.
- The repository was created in 2025 and is not archived. Its README includes self-reported performance and success metrics, which should not be treated as independently verified results.
Comparisons
Source repository
Open the original repository on GitHub.
16 counted GitHub visits
Related repositories
Similar repositories that may be relevant next.

agentevals: Evaluate AI Agents from OpenTelemetry Traces
October 4, 2026
agentevals scores AI agent behavior from existing OpenTelemetry traces, without rerunning agents or making extra model calls. It suits teams building instrumented agents that need local evaluation, golden-set checks, or CI quality gates.

web-design: Create Consistent Web Pages with a Claude Code Skill
October 3, 2026
web-design is a Claude Code skill that turns product briefs, reference URLs, or screenshots into an editable design specification before generating web code. It is suited to developers and designers who want a repeatable, spec-led workflow for building consistent pages.

oomwoo: Build a DIY Robot Vacuum
October 2, 2026
OOMWOO is a planned, hackable robot vacuum built around Raspberry Pi, ROS2 and 2D LiDAR. It is aimed at makers who want to build and customize a locally controlled vacuum, but its hardware and build instructions are still in development.

shepherd: Supervise Agents with Reversible Execution Traces
October 2, 2026
Shepherd records agent work as inspectable, reversible execution traces and keeps changes as proposals for review. It is aimed at developers building systems that supervise, replay, or manage the work of other agents.