# 0x4m4/hexstrike-ai

HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.

Repository: https://github.com/0x4m4/hexstrike-ai
Canonical: https://ross.abutalabs.com/products/hexstrike-ai
Homepage: https://www.hexstrike.com/
Language: Python
License: MIT
License Family: permissive
Topics: 0x4m4, ai, ai-agents, ai-cybersecurity, ai-hacking, ai-penetration-testing, ai-security-tool, artificial-intelligence, ctf-tools, generative-ai, kali-linux, kali-tools, llm, llm-integration, mcp, mcp-server, mcp-tools, pentesting, pentesting-tools, hexstrike
Last push: 2026-08-03T14:33:09+00:00

## Health v2 (maintenance only)
Score: 61/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 95, release rhythm 35, longevity 29
- inputs: {"age_days": 419, "days_push": 30, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 11381, forks 2371 (observed 2026-08-28T04:10:46.874588+00:00)

## What it is
HexStrike AI is an MCP server that bridges LLM agents (Claude, GPT, Copilot) with 150+ cybersecurity tools for autonomous penetration testing and vulnerability discovery. It provides a multi-agent architecture with specialized agents for bug bounty, CTF solving, CVE intelligence, and exploit generation.

## Use cases
- automate penetration testing with AI agents
- run security tools from Claude or GPT via MCP
- automate bug bounty reconnaissance and scanning
- discover vulnerabilities autonomously
- solve CTF challenges with LLM assistance
- generate exploits from CVE intelligence
- orchestrate Kali Linux tools through an AI agent

## When to choose
- you want LLM agents to drive real offensive security tooling
- you need an MCP server wrapping 150+ pentesting tools
- you run bug bounty or CTF workflows and want automation
- you want autonomous attack-chain discovery with dashboards

## When to avoid
- you need a defensive-only security platform
- you cannot legally or ethically run offensive tooling
- you want a simple scanner without LLM integration
- you need a fully turnkey product rather than a self-hosted server

## Facets
- artifact type: service
- maturity: active
- function: mcp, security, penetration-testing, agent-framework, llm-inference, vulnerability-scanning, osint
- domain: security, penetration-testing, artificial-intelligence, large-language-models, developer-tools
- platform: python, self-hosted, cli
- tags: mcp-server, offensive-security, bug-bounty, ctf, kali-linux, ai-agents, pentesting-automation, vulnerability-discovery, linux, docker

## Member repositories
- 0x4m4/hexstrike-ai (main) score 61

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:46.874588+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:15:41.213691+00:00, confidence not recorded.
  - readme: https://github.com/0x4m4/hexstrike-ai (fetched 2026-08-28T04:10:46.874588+00:00, sha 58f84da90d61)
  - homepage: https://www.hexstrike.com/ (fetched 2026-08-29T08:14:25.793736+00:00, sha 12c4393a2340)
- Data as of 2026-08-30T08:39:29.467469+00:00.
