Penetration testing tools via containerized Kali Linux for Claude.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.MSF_PASSWORD— hercules Password used by msfrpcd and the Metasploit RPC client.SKIP_METASPLOIT— Metasploit enabled, default =false 45PRESERVE_CONTAINER— false Keep the Docker container after MCP shutdown for debugging.USE_PRIVILEGED— false Use Docker --privileged instead of minimal network capabilities.TOOL_INSTALL_MODE— minimal Tool install mode value passed through configuration.MAX_CONCURRENT_HEAVY— 3 Semaphore limit for heavy operations.MAX_CONCURRENT_LIGHT— 10 Semaphore limit for light operations.ALLOWED_TARGETS— empty Comma-separated allow-list. Empty means no allow-list restriction.BLOCKED_TARGETS— empty Comma-separated block-list. Block rules take priority.HERCULES_DISABLED_TOOLS— empty Comma-separated MCP tools to not register (managed by the setup UI). Trims their schema from the agent's context; the binary stays usable via shell_exec. Core tools cannot be disabled.CONTAINER_CPU_LIMIT— 0 Docker CPU limit. 0 means unlimited.CONTAINER_MEM_LIMIT— 0 Docker memory limit. 0 means unlimited.DEFAULT_TIMEOUT— 300 Default command timeout in seconds.MAX_EXEC_TIMEOUTWATCHDOG_INTERVAL— 20 Seconds between container health checks; 0 disables the watchdog.BROWSER_HEADLESS— true Run the stealth browser headless, or headed under Xvfb when false.BROWSER_STREAM_PORT— 0 Forward a headed live-view port to the host (0 = off, headed mode only).BROWSER_PROXY— empty Default upstream proxy for browser sessions.BROWSER_TIMEZONEBROWSER_LOCALE[](https://m8ven.ai/mcp/0xmihirk-hercules-mcp-1bihql)