Sign inSign up

hackerdogs/wiremcp-mcp

By hackerdogs

•Updated 3 months ago

Wiremcp MCP Server

Image
0

312

hackerdogs/wiremcp-mcp repository overview

Hackerdogs
hackerdogs ⁠

⁠Wiremcp MCP Server

MCP server wrapper for WireMCP⁠ — AI-assisted real-time network traffic analysis via Wireshark/tshark.

⁠What is Wiremcp?

WireMCP is a Model Context Protocol server that connects AI assistants to Wireshark (via the tshark command-line tool) for real-time network traffic capture and analysis. It enables AI-driven packet inspection, protocol analysis, traffic filtering, and network troubleshooting without leaving the chat interface. See bstefanescu/wiremcp⁠ for full documentation. No API keys are required, but tshark must be accessible and the container may need elevated network privileges to capture live traffic.

⁠Tools Reference

ToolDescription
wiremcp_infoReturn status information for the WireMCP server

⁠Example Prompts

Here are example prompts you can use with Claude (or any MCP client) when this tool is connected:

  • "Use WireMCP to capture live traffic on interface eth0 for 30 seconds and summarize the protocols seen."
  • "Filter HTTP traffic from the last capture using WireMCP and show me the request URIs."
  • "Run a tshark capture via WireMCP targeting DNS queries to identify unusual domain lookups."
  • "Use WireMCP to analyze a PCAP file and list all unique source/destination IP pairs."
  • "Capture traffic on port 443 for 60 seconds using WireMCP and report any TLS handshake anomalies."
  • "Use WireMCP to check the status of the Wireshark integration and confirm it is ready to capture."

⁠Deploy

docker-compose up -d
⁠Docker Run (stdio mode)
docker run -i --rm hackerdogs/wiremcp-mcp:latest
⁠Docker Run (HTTP streamable mode)
docker run -d -p 8458:8458 \
  -e MCP_TRANSPORT=streamable-http \
  -e MCP_PORT=8458 \
  hackerdogs/wiremcp-mcp:latest

⁠MCP Client Configuration

⁠Stdio mode (default)

Add to your Claude Desktop or Cursor MCP config:

{
  "mcpServers": {
    "wiremcp-mcp": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT", "hackerdogs/wiremcp-mcp:latest"],
      "env": {
        "MCP_TRANSPORT": "stdio"
      }
    }
  }
}
⁠HTTP mode (streamable-http)

First, start the server using Docker Compose or docker run with HTTP mode (see Deploy⁠ above), then point your MCP client at the running server:

{
  "mcpServers": {
    "wiremcp-mcp": {
      "url": "http://localhost:8458/mcp"
    }
  }
}

When to use HTTP mode: HTTP mode is ideal for shared/remote deployments, multi-user setups, and Hackerdogs⁠ scheduled prompts. The server runs as a long-lived process and accepts connections from multiple MCP clients concurrently.

⁠Environment Variables

VariableDefaultDescription
MCP_TRANSPORTstdioTransport mode: stdio or streamable-http
MCP_PORT8458HTTP port (only used with streamable-http)

⁠Installing in Hackerdogs

The fastest way to get started is through Hackerdogs⁠:

  1. Log in to your Hackerdogs account.
  2. Go to the Tools Catalog.
  3. Search for the tool by name (e.g. "nuclei", "naabu", "julius").
  4. Expand the tool card and click Install — you're ready to go.

Give it a couple of minutes to go live. Then start querying by asking Hackerdogs to use the tool explicitly (e.g. "Use naabu to scan example.com"). If you don't specify, Hackerdogs will automatically choose the best tool for the job — it may choose this one on its own.

  1. Vendor API key required? Add your key in the config environment variable field before clicking Install. Your key will be encrypted at rest.
  2. Enable / Disable the tool anytime from the Enabled Tools page.
  3. Need to update a key or parameter? Go to My Tools → toggle Show Decrypted Values → edit → Save.

Want to contribute or chat with the team? Join our Discord⁠.

⁠Build

docker build -t hackerdogs/wiremcp-mcp:latest .

⁠Testing

⁠Automated tests
./test.sh
⁠Test directly with Docker

1. Start the server in HTTP mode:

docker run -d --rm --name wiremcp-mcp-test -p 8458:8458 \
  -e MCP_TRANSPORT=streamable-http \
  hackerdogs/wiremcp-mcp:latest

2. Initialize the MCP session:

SESSION_ID=$(curl -s -D - -X POST http://localhost:8458/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0.1"}}}' \
  2>&1 | grep -i mcp-session-id | awk '{print $2}' | tr -d '\r\n')

curl -s -X POST http://localhost:8458/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "mcp-session-id: $SESSION_ID" \
  -d '{"jsonrpc":"2.0","method":"notifications/initialized"}'

3. Call a tool:

curl -s -X POST http://localhost:8458/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "mcp-session-id: $SESSION_ID" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"run_wiremcp","arguments":{"arguments":"--help"}}}'

4. Clean up:

docker stop wiremcp-mcp-test

⁠Running the tool directly (bypassing MCP)

You can run the Wiremcp CLI in the same container by overriding the entrypoint without starting the MCP server.

Show help:

docker run -i --rm --entrypoint wiremcp hackerdogs/wiremcp-mcp:latest --help

Tag summary

Content type

Image

Digest

sha256:e14c0a994…

Size

74.8 MB

Last updated

3 months ago

docker pull hackerdogs/wiremcp-mcp