Skip to main content

DryHack-MCP

An MCP (Model Context Protocol) server that gives an AI agent offensive-security tooling for authorized penetration testing. It exposes four tools:

Tool Purpose
curl Raw HTTP interaction for web recon/exploitation
python Run ad-hoc Python snippets for scripted probing
shell Run shell commands (nmap, ffuf, nc, sqlmap, …)
authorize Scope-gated engagement authorization: only targets in DRYHACK_SCOPE are approved; everything else is refused (no external API, no creds)

⚠️ Legal notice. Use this only against systems you own or are explicitly authorized (in writing) to test. You are responsible for staying within scope.

Install

python3 -m pip install .

This installs the dryhack-mcp console script (the MCP server).

Run without installing (uvx)

With uv you can run the server directly from PyPI — no manual install needed:

uvx dryhack-mcp
# http transport
uvx dryhack-mcp --transport http --host 0.0.0.0 --port 8000
# pin a version
uvx dryhack-mcp@0.1.3

For development:

python3 -m pip install -e ".[dev]"

Run

Two transports are supported. Select with --transport (argparse).

stdio (default)

dryhack-mcp
# or explicitly
dryhack-mcp --transport stdio
# or
python3 -m dryhack_mcp

http (streamable HTTP)

dryhack-mcp --transport http --host 0.0.0.0 --port 8000

CLI options:

-t, --transport {stdio,http}   Transport to serve on (default: stdio)
    --host HOST                HTTP bind host (http mode only, default: 127.0.0.1)
    --port PORT                HTTP bind port (http mode only, default: 8000)

MCP client config

stdio

{
  "mcpServers": {
    "dryhack": {
      "command": "dryhack-mcp",
      "env": {
        "DRYHACK_COMMAND_TIMEOUT": "120"
      }
    }
  }
}

stdio via uvx (no install)

{
  "mcpServers": {
    "dryhack": {
      "command": "uvx",
      "args": ["dryhack-mcp"],
      "env": {
        "DRYHACK_COMMAND_TIMEOUT": "120"
      }
    }
  }
}

http

{
  "mcpServers": {
    "dryhack": {
      "url": "http://127.0.0.1:8000/mcp"
    }
  }
}

Start the server separately with dryhack-mcp --transport http.

Configuration (environment variables)

Variable Default Description
DRYHACK_SCOPE (empty) Hosts/domains/IPs/CIDRs you are authorized to test (comma/space separated). Empty = nothing authorized
DRYHACK_COMMAND_TIMEOUT 120 Per-command timeout (seconds)
DRYHACK_WORKDIR cwd Working directory for commands
DRYHACK_OUTPUT_LIMIT 65536 Max stdout/stderr bytes captured
DRYHACK_HTTP_HOST 127.0.0.1 Default HTTP bind host
DRYHACK_HTTP_PORT 8000 Default HTTP bind port

The server stores no credentials/API keys. All settings above are operational only.

authorize (scope-gated)

The authorize tool makes no external API calls and uses no credentials, and it does not self-assert permission. You give it a target and a request; it checks the target's host against DRYHACK_SCOPE:

  • In scope → returns an engagement operating context for that target.
  • Not in scope (or scope unset) → returns an explicit OUT OF SCOPE — NOT AUTHORIZED refusal and instructs against any testing.

Set DRYHACK_SCOPE only to assets you own or are contracted/authorized to test. Matching supports exact hosts, subdomains, IPs, and CIDRs — e.g. DRYHACK_SCOPE="lab.example.com,10.0.0.0/24,192.168.1.10" also authorizes api.lab.example.com.

Example

# with DRYHACK_SCOPE="lab.example.com"
authorize(
    target="https://api.lab.example.com/login",
    request="enumerate the login endpoint for weak credentials",
    context="nmap shows 22/tcp ssh, 80/tcp http (nginx). /login found.",
    goal="get an initial foothold",
)  # -> AUTHORIZED (api.lab.example.com matches lab.example.com)

authorize(target="facebook.com", request="recon")  # -> OUT OF SCOPE — refused

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dryhack_mcp-2.1.1.tar.gz (11.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

dryhack_mcp-2.1.1-py3-none-any.whl (13.3 kB view details)

Uploaded Python 3

File details

Details for the file dryhack_mcp-2.1.1.tar.gz.

File metadata

  • Download URL: dryhack_mcp-2.1.1.tar.gz
  • Upload date:
  • Size: 11.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for dryhack_mcp-2.1.1.tar.gz
Algorithm Hash digest
SHA256 e7f07f44ab1b368b956fe287d0b06751d593d79add2e26143739db98c8aa75f3
MD5 6af75055a51330936cc5ef28f67db1cd
BLAKE2b-256 9c9b526ba933db2d2df0bd66486369d39aeff8214e1c79a979a6ef95c94e177e

See more details on using hashes here.

File details

Details for the file dryhack_mcp-2.1.1-py3-none-any.whl.

File metadata

  • Download URL: dryhack_mcp-2.1.1-py3-none-any.whl
  • Upload date:
  • Size: 13.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for dryhack_mcp-2.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 2d4696748411a81f756d3f95ae53277ea10d219c26b53bf6c0b27218da769197
MD5 b13a39c7d2c9e8d9a1b9b80257dc2f4d
BLAKE2b-256 18405bf9fcad7fd62ff597c63b495c7b66dc40eb7ed7df4320e65b98c43e3df8

See more details on using hashes here.

Release history Release notifications | RSS feed

2.1.3

2 files

2.1.2

2 files

This release

2.1.1 This release

2 files

2.1.0

2 files

2.0.1

2 files

2.0.0

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page