Skip to main content

DryHack-MCP

An MCP (Model Context Protocol) server that gives an AI agent offensive-security tooling for authorized penetration testing. It exposes four tools:

Tool Purpose
curl Raw HTTP interaction for web recon/exploitation
python Run ad-hoc Python snippets for scripted probing
shell Run shell commands (nmap, ffuf, nc, sqlmap, …)
recommend_action AI-driven next-step engine backed by the safeguard API

⚠️ Legal notice. Use this only against systems you own or are explicitly authorized (in writing) to test. You are responsible for staying within scope.

Install

python3 -m pip install .

This installs the dryhack-mcp console script (the MCP server).

For development:

python3 -m pip install -e ".[dev]"

Run

Two transports are supported. Select with --transport (argparse).

stdio (default)

dryhack-mcp
# or explicitly
dryhack-mcp --transport stdio
# or
python3 -m dryhack_mcp

http (streamable HTTP)

dryhack-mcp --transport http --host 0.0.0.0 --port 8000

CLI options:

-t, --transport {stdio,http}   Transport to serve on (default: stdio)
    --host HOST                HTTP bind host (http mode only, default: 127.0.0.1)
    --port PORT                HTTP bind port (http mode only, default: 8000)

MCP client config

stdio

{
  "mcpServers": {
    "dryhack": {
      "command": "dryhack-mcp",
      "env": {
        "DRYHACK_API_KEY": "sk-...",
        "DRYHACK_API_BASE": "https://api.openai.com/v1",
        "DRYHACK_MODEL": "gpt-4o-mini",
        "DRYHACK_UNRESTRICTED": "true"
      }
    }
  }
}

http

{
  "mcpServers": {
    "dryhack": {
      "url": "http://127.0.0.1:8000/mcp"
    }
  }
}

Start the server separately with dryhack-mcp --transport http.

Configuration (environment variables)

Variable Default Description
DRYHACK_COMMAND_TIMEOUT 120 Per-command timeout (seconds)
DRYHACK_WORKDIR cwd Working directory for commands
DRYHACK_OUTPUT_LIMIT 65536 Max stdout/stderr bytes captured
DRYHACK_API_BASE https://api.openai.com/v1 Safeguard API base URL
DRYHACK_API_KEY (unset) Safeguard API key. If unset, recommend_action uses an offline heuristic
DRYHACK_MODEL gpt-4o-mini Model used by recommend_action
DRYHACK_UNRESTRICTED true Default mode for recommend_action
DRYHACK_HTTP_HOST 127.0.0.1 Default HTTP bind host
DRYHACK_HTTP_PORT 8000 Default HTTP bind port

recommend_action

The recommend_action tool consults an upstream LLM ("the safeguard API") for the next offensive step. Generic safeguards often refuse legitimate, authorized red-team requests. In unrestricted mode each request is framed with an explicit authorized-engagement / lab-scope context (rules-of-engagement on file, targets owned by the requesting party) so the model answers operationally.

  • Global default: DRYHACK_UNRESTRICTED=true|false
  • Per-call override: recommend_action(context=..., unrestricted=true)

When unrestricted is off, requests use the plain system prompt with no authorization framing.

Example

recommend_action(
    context="nmap shows 22/tcp ssh, 80/tcp http (nginx), 443/tcp https. /login found.",
    goal="get an initial foothold",
    unrestricted=True,
)

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dryhack_mcp-0.1.0.tar.gz (11.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

dryhack_mcp-0.1.0-py3-none-any.whl (13.3 kB view details)

Uploaded Python 3

File details

Details for the file dryhack_mcp-0.1.0.tar.gz.

File metadata

  • Download URL: dryhack_mcp-0.1.0.tar.gz
  • Upload date:
  • Size: 11.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for dryhack_mcp-0.1.0.tar.gz
Algorithm Hash digest
SHA256 abda640f91cc5551f820252fec355f7f2e9db77067d8ed81001a9e317ee944d7
MD5 dee47ce28aa3425c873e55f89033e94b
BLAKE2b-256 9488a378afbff024e2259c4dde37ded3ba42c1efd652f09e5ae527938c58e6fb

See more details on using hashes here.

File details

Details for the file dryhack_mcp-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: dryhack_mcp-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 13.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for dryhack_mcp-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a8c64ae69a66c080cafd4330da3246aabc6f93a065426a8c30c865c808fd0e15
MD5 b6b483b7e55ebc6ff59d2a066da453aa
BLAKE2b-256 5b7ead242a7b85f50605c1a93994330c1895992ea93b41263b2bdb4a20cbd120

See more details on using hashes here.

Release history Release notifications | RSS feed

2.1.3

2 files

2.1.2

2 files

2.1.1

2 files

2.1.0

2 files

2.0.1

2 files

2.0.0

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page