Skip to main content

Metasploit MCP Server

A Model Context Protocol (MCP) server for interacting with the Metasploit Framework.

Changelog

v1.6.4

  • Bug Fix: Fixed invalid pymetasploit3 API parameters in session.run_with_output() calls
  • Removed non-existent parameters: terminating_strs, timeout_exception, and timeout
  • Implemented proper timeout handling using asyncio.wait_for() wrapper
  • Changed exception handling from TimeoutError to asyncio.TimeoutError
  • This resolves compatibility issues with the pymetasploit3 library

v1.6.3

  • Breaking Change: Changed default execution mode from async (run_as_job: true) to sync (run_as_job: false) for run_exploit and run_post_module functions
  • This resolves issues where async execution returned boolean values that caused "'bool' object is not subscriptable" errors
  • Users can still explicitly set run_as_job: true for async execution when needed
  • run_auxiliary_module was already defaulting to sync execution

Features

  • List exploits and payloads
  • Generate payloads
  • Run exploits, post modules, and auxiliary modules
  • Manage sessions and listeners
  • Send commands to active sessions

Installation

pip install gc-metasploit

Or install with uvx:

uvx gc-metasploit

Usage

Ensure Metasploit RPC is running:

msfrpcd -P your_password -S -a 127.0.0.1

Then start the MCP server:

# As a command-line tool (HTTP/SSE mode by default):
gc-metasploit

# Or as a module:
python -m gc_metasploit.server

# Specify transport mode and options:
gc-metasploit --transport http --host 0.0.0.0 --port 8085
gc-metasploit --transport stdio

Transport Options

The server supports two transport methods:

  • HTTP/SSE (Server-Sent Events): Default mode for interoperability with most MCP clients
  • STDIO (Standard Input/Output): Used with Claude Desktop and similar direct pipe connections

For Claude Desktop integration, configure claude_desktop_config.json:

{
    "mcpServers": {
        "metasploit": {
            "command": "gc-metasploit",
            "args": [
                "--transport",
                "stdio"
            ],
            "env": {
                "MSF_PASSWORD": "yourpassword"
            }
        }
    }
}

For other MCP clients that use HTTP/SSE:

  1. Start the server in HTTP mode (default):

    gc-metasploit --transport http --host 0.0.0.0 --port 8085
    
  2. Configure your MCP client to connect to:

    • SSE endpoint: http://your-server-ip:8085/sse

Environment Variables

  • MSF_PASSWORD: Metasploit RPC password (default: 'yourpassword')
  • MSF_SERVER: Metasploit RPC server (default: '127.0.0.1')
  • MSF_PORT: Metasploit RPC port (default: '55553')
  • MSF_SSL: Use SSL (default: 'false')
  • PAYLOAD_SAVE_DIR: Directory to save generated payloads (default: '~/payloads')

License

Apache 2.0

Metadata

Release files for gc-metasploit 1.6.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for gc-metasploit 1.6.4
File Size Uploaded
gc_metasploit-1.6.4.tar.gz 21.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for gc-metasploit 1.6.4
File Interpreter ABI Platform
gc_metasploit-1.6.4-py3-none-any.whl Python 3 none any Details

Total release size: 43.7 kB

Release files / gc_metasploit-1.6.4.tar.gz

Download URL gc_metasploit-1.6.4.tar.gz
Size 21.2 kB
Tags Source
SHA-256 checksum
How to use checksums
63b6242f3dd1ff79b940d6a888957ed0a8cafd9c7a5e0d42b65640a76cdc8fda
BLAKE2b-256 checksum
How to use checksums
421b4e47f3a616ee582b5c17111da9561b5bf292de5c74556fc2ce1cba96cec0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.10.11

Release files / gc_metasploit-1.6.4-py3-none-any.whl

Download URL gc_metasploit-1.6.4-py3-none-any.whl
Size 22.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8e49a3497ea20a4b3aa744f412311eebd5629996f5fe28bb8b2662ed7f53ccc8
BLAKE2b-256 checksum
How to use checksums
38164142389d9b506ec7f8a6afb8e6c2bf077eaef10b03dc0b01fbb45534f63a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.10.11

Release history Release notifications | RSS feed

This release

1.6.4 This release

2 release files

1.6.3

2 release files

1.6.2

2 release files

1.6.1

2 release files

1.6.0

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page