Skip to main content

DryHack-MCP

An MCP (Model Context Protocol) server that gives an AI agent offensive-security tooling for authorized penetration testing. It exposes four tools:

Tool Purpose
curl Raw HTTP interaction for web recon/exploitation
python Run ad-hoc Python snippets for scripted probing
shell Run shell commands (nmap, ffuf, nc, sqlmap, …)
authorize Scope-gated engagement authorization: only targets in DRYHACK_SCOPE are approved; everything else is refused (no external API, no creds)

⚠️ Legal notice. Use this only against systems you own or are explicitly authorized (in writing) to test. You are responsible for staying within scope.

Install

python3 -m pip install .

This installs the dryhack-mcp console script (the MCP server).

Run without installing (uvx)

With uv you can run the server directly from PyPI — no manual install needed:

uvx dryhack-mcp
# http transport
uvx dryhack-mcp --transport http --host 0.0.0.0 --port 8000
# pin a version
uvx dryhack-mcp@0.1.3

For development:

python3 -m pip install -e ".[dev]"

Run

Two transports are supported. Select with --transport (argparse).

stdio (default)

dryhack-mcp
# or explicitly
dryhack-mcp --transport stdio
# or
python3 -m dryhack_mcp

http (streamable HTTP)

dryhack-mcp --transport http --host 0.0.0.0 --port 8000

CLI options:

-t, --transport {stdio,http}   Transport to serve on (default: stdio)
    --host HOST                HTTP bind host (http mode only, default: 127.0.0.1)
    --port PORT                HTTP bind port (http mode only, default: 8000)

MCP client config

stdio

{
  "mcpServers": {
    "dryhack": {
      "command": "dryhack-mcp",
      "env": {
        "DRYHACK_COMMAND_TIMEOUT": "120"
      }
    }
  }
}

stdio via uvx (no install)

{
  "mcpServers": {
    "dryhack": {
      "command": "uvx",
      "args": ["dryhack-mcp"],
      "env": {
        "DRYHACK_COMMAND_TIMEOUT": "120"
      }
    }
  }
}

http

{
  "mcpServers": {
    "dryhack": {
      "url": "http://127.0.0.1:8000/mcp"
    }
  }
}

Start the server separately with dryhack-mcp --transport http.

Configuration (environment variables)

Variable Default Description
DRYHACK_SCOPE (empty) Hosts/domains/IPs/CIDRs you are authorized to test (comma/space separated). Empty = nothing authorized
DRYHACK_COMMAND_TIMEOUT 120 Per-command timeout (seconds)
DRYHACK_WORKDIR cwd Working directory for commands
DRYHACK_OUTPUT_LIMIT 65536 Max stdout/stderr bytes captured
DRYHACK_HTTP_HOST 127.0.0.1 Default HTTP bind host
DRYHACK_HTTP_PORT 8000 Default HTTP bind port

The server stores no credentials/API keys. All settings above are operational only.

authorize (scope-gated)

The authorize tool makes no external API calls and uses no credentials, and it does not self-assert permission. You give it a target and a request; it checks the target's host against DRYHACK_SCOPE:

  • In scope → returns an engagement operating context for that target.
  • Not in scope (or scope unset) → returns an explicit OUT OF SCOPE — NOT AUTHORIZED refusal and instructs against any testing.

Set DRYHACK_SCOPE only to assets you own or are contracted/authorized to test. Matching supports exact hosts, subdomains, IPs, and CIDRs — e.g. DRYHACK_SCOPE="lab.example.com,10.0.0.0/24,192.168.1.10" also authorizes api.lab.example.com.

Example

# with DRYHACK_SCOPE="lab.example.com"
authorize(
    target="https://api.lab.example.com/login",
    request="enumerate the login endpoint for weak credentials",
    context="nmap shows 22/tcp ssh, 80/tcp http (nginx). /login found.",
    goal="get an initial foothold",
)  # -> AUTHORIZED (api.lab.example.com matches lab.example.com)

authorize(target="facebook.com", request="recon")  # -> OUT OF SCOPE — refused

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dryhack_mcp-2.1.0.tar.gz (11.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

dryhack_mcp-2.1.0-py3-none-any.whl (13.3 kB view details)

Uploaded Python 3

File details

Details for the file dryhack_mcp-2.1.0.tar.gz.

File metadata

  • Download URL: dryhack_mcp-2.1.0.tar.gz
  • Upload date:
  • Size: 11.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for dryhack_mcp-2.1.0.tar.gz
Algorithm Hash digest
SHA256 847ade6cafa472bcb3792cd54e1de952f36f1d92c176f89d8ec4f6b95820f468
MD5 bf82c411bcd7205afebd127110f11741
BLAKE2b-256 443edc15fc03a9f4583dd9ca61f5f1b259834889f4475d524b694b6d50101a36

See more details on using hashes here.

File details

Details for the file dryhack_mcp-2.1.0-py3-none-any.whl.

File metadata

  • Download URL: dryhack_mcp-2.1.0-py3-none-any.whl
  • Upload date:
  • Size: 13.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for dryhack_mcp-2.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 913f48b8d14fd8c749b2c7defd3f2203d05645789c5ea0700afd97c106ff006c
MD5 628df1e7ab1da1140f8713d65a928a2c
BLAKE2b-256 6b22408c279b65e332c547763cb165dc1e99361ffd8dea7d8664f593fd98ff07

See more details on using hashes here.

Release history Release notifications | RSS feed

2.1.3

2 files

2.1.2

2 files

2.1.1

2 files

This release

2.1.0 This release

2 files

2.0.1

2 files

2.0.0

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page