# Hercules MCP MCP server

Agent View of the PolicyLayer registry record for Hercules MCP: identity, probed posture, risk grade, and all 45 tools classified. HTML page: https://policylayer.com/tools/0xmihirk-hercules-mcp

## Facts

- Server id: `0xmihirk/hercules-mcp`
- Homepage: https://github.com/0xMihirK/hercules-mcp
- Registry record: grade F, identity unverified
- Lifecycle: active
- Rate-limited: no
- Tools: 45
- Tool categories present: Execute, Read, Write
- Tags: 0xmihirk hercules mcp, automation
- Record last modified: 2026-06-29T09:38:52.383Z

## Tools (45)

| Tool | Category | Risk | Record |
| --- | --- | --- | --- |
| `browser_act` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-act.md |
| `browser_cmd` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-cmd.md |
| `browser_eval` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-eval.md |
| `browser_open` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-open.md |
| `browser_session` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-session.md |
| `browser_wait` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-wait.md |
| `bruteforce_hydra` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/bruteforce-hydra.md |
| `crack_john` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/crack-john.md |
| `ctf_binwalk` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/ctf-binwalk.md |
| `ctf_steghide` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/ctf-steghide.md |
| `fuzz_dirs` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/fuzz-dirs.md |
| `metasploit_generate_payload` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/metasploit-generate-payload.md |
| `metasploit_manage` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/metasploit-manage.md |
| `metasploit_run_module` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/metasploit-run-module.md |
| `metasploit_start_listener` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/metasploit-start-listener.md |
| `ncat` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/ncat.md |
| `network_curl` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/network-curl.md |
| `network_hping3` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/network-hping3.md |
| `nmap_run_nse_script` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/nmap-run-nse-script.md |
| `nmap_scan` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/nmap-scan.md |
| `nmap_write_nse_script` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/nmap-write-nse-script.md |
| `nuclei_run` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/nuclei-run.md |
| `recon_amass` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/recon-amass.md |
| `recon_dns` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/recon-dns.md |
| `searchsploit` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/searchsploit.md |
| `shell_exec` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/shell-exec.md |
| `shell_exec_background` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/shell-exec-background.md |
| `shell_kill_job` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/shell-kill-job.md |
| `sqlmap_run` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/sqlmap-run.md |
| `system_start_new_session` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/system-start-new-session.md |
| `system_stop_container` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/system-stop-container.md |
| `web_scan` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/web-scan.md |
| `web_vuln_scan` | Execute | High | https://policylayer.com/tools/0xmihirk-hercules-mcp/web-vuln-scan.md |
| `browser_read` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-read.md |
| `browser_screenshot` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-screenshot.md |
| `browser_skill` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-skill.md |
| `browser_snapshot` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/browser-snapshot.md |
| `metasploit_search` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/metasploit-search.md |
| `recon_whois` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/recon-whois.md |
| `shell_check_job` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/shell-check-job.md |
| `system_list_sessions` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/system-list-sessions.md |
| `system_network_info` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/system-network-info.md |
| `workspace_read_file` | Read | Low | https://policylayer.com/tools/0xmihirk-hercules-mcp/workspace-read-file.md |
| `nuclei_write_template` | Write | Medium | https://policylayer.com/tools/0xmihirk-hercules-mcp/nuclei-write-template.md |
| `workspace_write_file` | Write | Medium | https://policylayer.com/tools/0xmihirk-hercules-mcp/workspace-write-file.md |

## Tool descriptions

- `browser_act` — Interact with an element (click/fill/type/press/hover/select/check).
- `browser_cmd` — Escape hatch: run any agent-browser subcommand against the stealth session.
- `browser_eval` — Run JavaScript in the page and return the result.
- `browser_open` — Open a URL in a stealth Chromium session.
- `browser_session` — Manage browser sessions / live-view stream.
- `browser_wait` — Wait for a selector / ms / text / url / load state.
- `crack_john` — Offline password cracking using John the Ripper. Hashes written to temp file.
- `ctf_binwalk` — Firmware/archive analysis and extraction using binwalk.
- `ctf_steghide` — Steganography analysis and extraction via steghide.
- `fuzz_dirs` — Directory brute-forcing (gobuster/ffuf).
- `metasploit_generate_payload` — Generate a payload. Tries RPC first, falls back to msfvenom CLI.
- `metasploit_manage` — Manage Metasploit sessions and jobs.
- `metasploit_start_listener` — Start exploit/multi/handler as a background job to catch reverse shells.
- `ncat` — Use ncat to connect, listen, or interact with a background listener.
- `network_curl` — HTTP client (curl) for arbitrary web requests.
- `network_hping3` — Packet crafting and firewall testing (hping3).
- `nmap_run_nse_script` — Run a custom NSE script against a target.
- `nmap_scan` — Run nmap in quick, aggressive, port, script, or custom mode.
- `nmap_write_nse_script` — Write custom NSE script and update DB.
- `nuclei_run` — Run nuclei vulnerability scanner against targets.
- `recon_amass` — Subdomain enumeration via amass.
- `recon_dns` — Run DNS lookups with dig or bulk DNS resolution with dnsx.
- `searchsploit` — Exploit-DB search or exploit retrieval.
- `shell_exec_background` — Run a long shell command in the background, returning a job_id.
- `shell_kill_job` — Kill a running background shell job (useful for stuck commands).
- `sqlmap_run` — Automated SQL injection suite. Always uses --batch.
- `web_scan` — Run one web fingerprinting scanner selected by tool.
- `web_vuln_scan` — Run Dalfox XSS scanning or Commix command-injection scanning.
- `browser_read` — Read text/html/value/url/title from the page.
- `browser_screenshot` — Capture a PNG screenshot into the session's workspace directory.
- `browser_skill` — Load agent-browser's own skill/command documentation.
- `browser_snapshot` — Accessibility-tree snapshot with @e refs.
- `metasploit_search` — Search MSF modules by name, CVE, or keyword. Returns matching exploits, auxiliary, and post modules.
- `recon_whois` — Domain OSINT via whois.
- `shell_check_job` — Check the status and read live output of a background shell job. Use tail_lines to control how many lines to retrieve.
- `workspace_read_file` — Read the contents of a file inside the container workspace.
- `nuclei_write_template` — Write custom nuclei YAML template to workspace.
- `workspace_write_file` — Write content to a file inside the container workspace (overwrites if exists).

## Related servers

- UnClick (1658 tools) — https://policylayer.com/tools/io-github-malamutemayhem-unclick-mcp-server.md
- Nodebench (824 tools) — https://policylayer.com/tools/io-github-homenshum-nodebench.md
- Yaver (813 tools) — https://policylayer.com/tools/io-github-kivanccakmak-yaver.md
- Binance MCP Server (734 tools) — https://policylayer.com/tools/nirholas-binance-mcp.md
- Crawlora (728 tools) — https://policylayer.com/tools/crawlora-mcp.md
- MCP Framework Personal (643 tools) — https://policylayer.com/tools/inggerman-mcps.md
- Crow (587 tools) — https://policylayer.com/tools/kh0pper-crow.md
- Fortimanager (584 tools) — https://policylayer.com/tools/jmpijll-fortimanager-mcp.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=0xmihirk-hercules-mcp · API: https://policylayer.com/registry/api · Recommended policies for every tool: https://policylayer.com/policies/0xmihirk-hercules-mcp
