kali-mcp-server: Instructions file for Claude Code

CLAUDE.md

kali-mcp-server CLAUDE.md is an instructions file for Claude Code from scottcrosby-securebine/kali-mcp-server. It costs 2,151 tokens per session, scanned A, original, MIT.

A Claude Code instruction file for a single-file MCP server that exposes Kali Linux security tools through the Model Context Protocol, a way for agent clients to call tools. It also documents Docker startup, launcher checks, tests, and a redaction check.

In plain words
What is it for?
Explaining the repository, building its Docker image, inspecting the launcher command, running the native test suite, and performing the separate redaction check.
Why use it?
It gives the coding agent the repository's operating rules and commands. This helps it build and run the server in the intended Docker-based setup and verify changes.

Instructions file for Claude Code

Written for Claude Code: the file is CLAUDE.md. Also seen: mentions CLAUDE.md; mentions Claude Code.

This is scottcrosby-securebine/kali-mcp-server's own configuration. It tells Claude Code how to work on kali-mcp-server itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything kali-mcp-server configures →

Reuse

Borrowing it

Nothing to install: this file belongs to scottcrosby-securebine/kali-mcp-server. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/scottcrosby-securebine/kali-mcp-server/main/CLAUDE.md
Clone the repo
git clone --depth 1 https://github.com/scottcrosby-securebine/kali-mcp-server

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for kali-mcp-server CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/scottcrosby-securebine/kali-mcp-server/claude-md/github.svg)](https://agentmods.dev/instructions/scottcrosby-securebine/kali-mcp-server/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/scottcrosby-securebine/kali-mcp-server/claude-md"><img src="https://agentmods.dev/badge/instructions/scottcrosby-securebine/kali-mcp-server/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for kali-mcp-server CLAUDE.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/scottcrosby-securebine/kali-mcp-server/claude-md"><img src="https://agentmods.dev/badge/instructions/scottcrosby-securebine/kali-mcp-server/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 2,151 This file is loaded in full into every session.
When invoked 2,151 The same file — it is already loaded in full.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.02151 $0.02151
Opus 5 $0.01076 $0.01076
Sonnet 5 $0.00430 $0.00430
Haiku 4.5 $0.00215 $0.00215

Measured 6d ago against content hash 9988b5a71d2b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

kali-mcp-server CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Runs shell commandslowCapability

Expected in a hook, worth knowing in a rule or an instructions file.

- `execute_command(cmd_list, timeout, ...)` — the only place `subprocess.run` is called. It always uses an **argument list** (no `shell=True`) and returns the structured process result. Both public-output and structured
CLAUDE.md · 118 lines

How it starts

The opening of the file, as written. The whole thing — 118 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.

What this is

A single-file MCP (Model Context Protocol) server preserving 41 Kali Linux calls and adding eight bounded scanning/reporting calls. An MCP client calls the tools over stdio; the server invokes underlying Kali binaries and returns strings. MCP behavior lives in kali_pentest_server.py. Host-side Docker profile selection lives in kali_mcp_launcher.py and its scripts/kali-mcp entry point.

Commands

# Build the image from pinned base and package inputs
docker build -t kali-mcp-server:latest .

# Inspect the hardened launcher command, then run it through an MCP client
scripts/kali-mcp --image kali-mcp-server:latest --dry-run

# Host startup is only a development convenience
python3 kali_pentest_server.py          # host: needs `pip install -r requirements.txt` + the Kali tools on PATH

# Run the native contract, adapter, report, launcher, registry, and browser tests
python3 -m unittest discover -s tests -v

# Redaction gate. NOT collected by unittest discover -- run it directly, and read
# the EXIT STATUS, not the last line of output (a launcher test prints a docker
# line after `OK`). Three states: 0 measured and clean; 3 NOTHING TO MEASURE,
# the base carries a byte-identical kali_pentest_server.py so the run is a pass
# that proves nothing; any other status a failure. 1 is the real verdict -- a
# leak opened, legitimate content destroyed, a parser the corpus never
# exercised, or a sweep combination the base redacted and HEAD does not. 2 is
# not a verdict at all: CPython exits 2 on a script it cannot open and argparse
# exits 2 on a bad flag, which is why "nothing to measure" is 3 and 2 fails.
# Pass --base after this branch merges.
python3 tests/redaction_differential.py [--base <rev>] [--json out.json]

# Mutation check: swap kali_pentest_server.py for the version at <base-rev>, run
# the tests matching <test-pattern> (default `test_scanner_adapters.py`) against
# it, and require a real ASSERTION failure -- 0 the mutation was caught, 1 the
# suite ran clean so those assertions pin nothing, 2 INCONCLUSIVE (nothing
# collected, or an error, neither of which proves anything either way), 3 the
# base is byte-identical to the working tree so nothing was mutated. Same 3 as
# the redaction gate above, and for the same reason: a run that measured nothing
# must not report either a pass or an accusation. Refuses to start while
# kali_pentest_server.py has uncommitted changes. Restores the tree on any exit.
scripts/mutation-check <base-rev> [test-pattern]

# Verify a built image under the required NNP boundary
docker run --rm --security-opt=no-new-privileges \
  --entrypoint verify-kali-mcp-image kali-mcp-server:latest

# Exercise the real MCP/container seam after building the requested platform image
python3 tests/integration/run_container_integration.py \
  --image kali-mcp-server:latest --platform linux/amd64

# Stage an explicitly reviewed, detection-only Nuclei template set
scripts/update-nuclei-templates --source /path/to/upstream \
  --destination /new/staging/directory --version UPSTREAM_VERSION \
  http/cves/example.yaml

Read the full file on GitHub · 118 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago Changed · +27 tokens per session 9988b5a71d2b
  2. 10d ago First seen · 118 lines · 2,124 tokens per session scan A ef9218075114

Subscribe to this mod's changes

kali-mcp-server CLAUDE.md is an instructions file published in the GitHub repository scottcrosby-securebine/kali-mcp-server (2 stars, last pushed 7d ago), licensed MIT. It adds 2,151 tokens to every session, about $0.0108 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens