MCP servers for automated penetration testing and OSINT.
Hostile‑Command‑Suite MCP server is a locally run integration for AI assistants that speak the Model Context Protocol. MCP servers for automated penetration testing and OSINT.
A terminal-based OSINT investigation framework with AI-powered analysis and intelligent agent decision-making. Features automated profile scraping, multi-platform username investigation, and local LLM integration for enhanced intelligence gathering.
The server ships on PyPI as sherlock-project, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.
Once Hostile‑Command‑Suite is connected, these are the calls the assistant has available:
Prerequisites — 1. Install ollama (for AI analysis): bash curl -fsSL https://ollama.ai/install.sh | sh ollama pull qwen3:8b # recommended modelInstallation — The Installation tool exposed by this serverUsage — The Usage tool exposed by this serverPlenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. Hostile‑Command‑Suite's toolset — Prerequisites, Installation, Usage — is a fair guide to whether it matches your workflow. It is maintained by cycloarcane; worth a glance at recent repository activity before you build anything load-bearing on it.
We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.
| Tool | What it does |
|---|---|
| Prerequisites | 1. **Install ollama** (for AI analysis): bash curl -fsSL https://ollama.ai/install.sh | sh ollama pull qwen3:8b # recommended model |
| Installation | The Installation tool exposed by this server. |
| Usage | The Usage tool exposed by this server. |
{
"mcpServers": {
"hostile-command-suite": {
"command": "uvx",
"args": ["sherlock-project"]
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.