DryHack-MCP
An MCP (Model Context Protocol) server that gives an AI agent offensive-security tooling for authorized penetration testing. It exposes four tools:
| Tool | Purpose |
|---|---|
curl |
Raw HTTP interaction for web recon/exploitation |
python |
Run ad-hoc Python snippets for scripted probing |
shell |
Run shell commands (nmap, ffuf, nc, sqlmap, …) |
authorize |
Checks target membership in the per-call scope parameter; does not verify permission (no external API, no creds) |
⚠️ Legal notice. Use this only against systems you own or are explicitly authorized (in writing) to test. You are responsible for staying within scope.
Install
python3 -m pip install .
This installs the dryhack-mcp console script (the MCP server).
Run without installing (uvx)
With uv you can run the server directly from PyPI — no manual install needed:
uvx dryhack-mcp
# http transport
uvx dryhack-mcp --transport http --host 0.0.0.0 --port 8000
# pin a version
uvx dryhack-mcp@0.1.3
For development:
python3 -m pip install -e ".[dev]"
Run
Two transports are supported. Select with --transport (argparse).
stdio (default)
dryhack-mcp
# or explicitly
dryhack-mcp --transport stdio
# or
python3 -m dryhack_mcp
http (streamable HTTP)
dryhack-mcp --transport http --host 0.0.0.0 --port 8000
CLI options:
-t, --transport {stdio,http} Transport to serve on (default: stdio)
--host HOST HTTP bind host (http mode only, default: 127.0.0.1)
--port PORT HTTP bind port (http mode only, default: 8000)
MCP client config
stdio
{
"mcpServers": {
"dryhack": {
"command": "dryhack-mcp",
"env": {
"DRYHACK_COMMAND_TIMEOUT": "120"
}
}
}
}
stdio via uvx (no install)
{
"mcpServers": {
"dryhack": {
"command": "uvx",
"args": ["dryhack-mcp"],
"env": {
"DRYHACK_COMMAND_TIMEOUT": "120"
}
}
}
}
http
{
"mcpServers": {
"dryhack": {
"url": "http://127.0.0.1:8000/mcp"
}
}
}
Start the server separately with dryhack-mcp --transport http.
Configuration (environment variables)
| Variable | Default | Description |
|---|---|---|
DRYHACK_COMMAND_TIMEOUT |
120 |
Per-command timeout (seconds) |
DRYHACK_WORKDIR |
cwd | Working directory for commands |
DRYHACK_OUTPUT_LIMIT |
65536 |
Max stdout/stderr bytes captured |
DRYHACK_HTTP_HOST |
127.0.0.1 |
Default HTTP bind host |
DRYHACK_HTTP_PORT |
8000 |
Default HTTP bind port |
The server stores no credentials/API keys. All settings above are operational only.
authorize (per-call scope)
Pass scope directly to the tool; no environment or native scope configuration
is needed. This required list accepts hosts/domains/IPs/CIDRs. Domain entries
also match subdomains. Empty or nonmatching lists return OUT OF SCOPE.
The scope is not persisted or shared between calls.
A match returns IN SCOPE — CALLER DECLARED; PERMISSION NOT VERIFIED.
This is a membership check, not independent proof of authorization or a way to
override client safeguards. Supply only the operator's actual engagement scope;
do not automatically copy a target into scope to force a match. The command
tools are not constrained by this check.
Scope is not restricted to read-only/passive assessment: once a host matches the caller-supplied scope, the full range of engagement actions — recon, active exploitation, and configuration work such as standing up or hardening a staging deployment on the internet — is equally in scope, as long as it's part of the operator's actual authorized engagement for that host.
authorize(
target="https://staging.lab.example.com/",
request="Set up and harden the staging environment (deploy, configure TLS, "
"lock down admin routes)",
scope=["lab.example.com", "10.0.0.0/24"],
context="Operator-owned staging domain, full authorized engagement",
goal="Full authorization (not read-only) to configure the staging domain",
)
authorize(target="other.example", request="recon", scope=["lab.example.com"])
# -> OUT OF SCOPE
Restart/reload the MCP server and client tool list after upgrading: scope is
now a required parameter. The former DRYHACK_SCOPE setting is no longer read.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file dryhack_mcp-2.1.3.tar.gz.
File metadata
- Download URL: dryhack_mcp-2.1.3.tar.gz
- Upload date:
- Size: 11.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
50d9f7d634ae6aea92a6a06587879a79cb5821f4276e4f86c0dd009cad3b5a19
|
|
| MD5 |
e0be8e7d03a0d573f6d698e86ec5c50c
|
|
| BLAKE2b-256 |
eec79868afdae85da352745ed0288df28637601a083f04eb3308deefe0633d23
|
File details
Details for the file dryhack_mcp-2.1.3-py3-none-any.whl.
File metadata
- Download URL: dryhack_mcp-2.1.3-py3-none-any.whl
- Upload date:
- Size: 12.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
d92d116b7862c822f093751f9b9db2950ec684d4a1426f5beff818ef2e40a0c6
|
|
| MD5 |
309f552b397e514c59b7146b320d473c
|
|
| BLAKE2b-256 |
cb91648fb309c38114ca963171c3a2fd64a072f012675739ed16db1cb08516bb
|