MCP server for Exegol - provides tools to manage Exegol containers, execute commands, download images, and interact with penetration testing resources
Server has 11 tools with generally good descriptions (100-300 chars) and clear naming conventions (verb_noun pattern). However, significant gaps exist: (1) Input schemas are present but inconsistently detailed, parameters lack explicit type constraints (enums, minLength, maxLength, pattern); (2) Output schemas are documented as return type hints in docstrings but not in structured JSON Schema format visible in tool registration; (3) Error handling is basic (ValueError, RuntimeError raised) with minimal recovery guidance; (4) Security concerns: execute_remote_command exposes credentials (username, password) as parameters rather than server-side injection; (5) A few tools lack parameter descriptions (e.g., execute_remote_command's 'use_powershell' is vague about when to use it).
Download and install an Exegol image, this can be a new image or update an already installed but outdated one. IMPORTANT: Always check if there isn't a more specific tool created for this task before using this tool. RELATED TOOLS: - list_all_images: To discover available images before downloading - list_installed_images: To check current installation status - list_exegol_containers: To see how images are used in practice
Execute a command in an Exegol container. IMPORTANT: Always check if there isn't a more specific tool created for this task (like execute_remote_command for remote connections) before using this tool. RELATED TOOLS: - execute_remote_command: For remote network connections (SSH, WinRM, SMB, etc.) - list_installed_tools: To discover available tools before executing commands - get_tool_help: To get help documentation for specific tools - list_exegol_containers: To check container status before execution - start_container/stop_container: To manage container lifecycle
Execute a command remotely through various protocols (SSH, WinRM, SMB, MSSQL, WMI, RDP). This tool directly executes the command without creating a persistent session. IMPORTANT: This tool is more specific than execute_command_in_container - use it for all remote network connections. RELATED TOOLS: - execute_command_in_container: For local container operations (not network-based) - list_exegol_containers: To choose which container to use for remote execution - start_container: To ensure the container is running before remote operations - list_installed_tools: To discover network/security tools available in containers SUPPORTED PROTOCOLS: - ssh: Secure Shell connections - winrm: Windows Remote Management - smb: Server Message Block (Windows file sharing) - mssql: Microsoft SQL Server - wmi: Windows Management Instrumentation - rdp: Remote Desktop Protocol
Credentials exposed as tool parameters (username, password in execute_remote_command). Secrets in parameters are logged in traces and prompt history, creating a compliance and security risk.
Parameter schemas lack formal constraints (enums, minLength, pattern, minValue/maxValue). For example, 'protocol' in execute_remote_command should be an enum {ssh, winrm, smb, mssql, wmi, rdp}; 'port' lacks minValue/maxValue bounds; 'target_os' in list_installed_exegol_resources has no enum constraint.
Output schemas are documented only in docstrings (e.g., 'Returns: List of Exegol containers with their metadata') but not formalized in tool registration. LLMs cannot reliably parse prose descriptions of outputs, JSON Schema definitions are required for consistent downstream tool chaining.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 59 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 10 | - | v1 |
Get help/documentation for a specific tool installed in an Exegol container. Tries common help flags: -h, --help, help IMPORTANT: Always check if there isn't a more specific tool created for this task before using this tool. RELATED TOOLS: - list_installed_tools: To discover available tools before getting help - execute_command_in_container: To test tools after reading their help - list_exegol_containers: To choose which container to get help from
List all Exegol images with their status. IMPORTANT: Always check if there isn't a more specific tool created for this task before using this tool. RELATED TOOLS: - list_installed_images: To see only installed images (faster) - download_image: To download and install images from this list - list_exegol_containers: To understand current container setup Returns a list of Exegol images installed on the system and available to download with their detailed information (name, version, up-to-date status, etc...).
List all available Exegol containers with their status. IMPORTANT: Always check if there isn't a more specific tool created for this task before using this tool. RELATED TOOLS: - start_container/stop_container: To manage specific containers after listing - execute_command_in_container: To execute commands in listed containers - list_installed_tools: To see tools available in specific containers - list_installed_images: To check what images are available for containers Returns a list of Exegol containers configured on the system with their detailed information (name, status, image, network_driver etc...) in a chart.
Exegol's "offline resources" are a neat choice of standalone tools and scripts that are often used during penetration tests, CTFs and red-teams. While many penetration testers download those resources again every time they need them, Exegol users don't have to. This tool lists all installed resources in an Exegol container by listing files in /opt/resources/<target_os>.
List all installed Exegol images with their status. IMPORTANT: Always check if there isn't a more specific tool created for this task before using this tool. RELATED TOOLS: - list_all_images: To see both installed and available images - download_image: To install/update images from this list - list_exegol_containers: To see which images are used by containers Returns a list of Exegol images installed on the system with their detailed information (name, version, up-to-date status, etc...) in a chart.
List all installed tools in an Exegol container by reading the installed_tools.csv file. IMPORTANT: Always check if there isn't a more specific tool created for this task before using this tool. RELATED TOOLS: - get_tool_help: To get detailed help for specific tools from this list - execute_command_in_container: To actually use the tools listed here - list_exegol_containers: To choose which container to explore - start_container: To ensure container is running before listing tools
Start an Exegol container if it is not running yet. IMPORTANT: Always check if there isn't a more specific tool created for this task before using this tool. RELATED TOOLS: - list_exegol_containers: To check container status before starting - execute_command_in_container: To execute commands in the started container - list_installed_tools: To discover tools available in the container - stop_container: To stop the container when done
Stop an Exegol container if it is running. IMPORTANT: Always check if there isn't a more specific tool created for this task before using this tool. RELATED TOOLS: - list_exegol_containers: To check container status before stopping - start_container: To restart the container later if needed - execute_command_in_container: Use before stopping to save work/cleanup
Error handling is minimal. Most errors are generic exceptions (ValueError, RuntimeError) with no guidance on recovery. Tools should categorize errors as retryable vs. user-fixable and offer recovery hints (e.g., 'Container not found. Available containers: [list]. Try one of these.' or 'Command timed out. Retry with a longer timeout or simpler command.').
Parameter descriptions are sometimes vague. Example: execute_remote_command's 'use_powershell' has description 'Use PowerShell flag (-X) instead of normal flag (-x)', unclear when an LLM should set this to true. Better: 'Set to true when executing PowerShell commands on Windows targets (WinRM/WMI); use false for bash/sh commands on Unix targets.'
Missing pagination and result limits. list_exegol_containers, list_installed_images, list_all_images, and list_installed_tools may return unbounded results, risking context window exhaustion. Introduce limit/offset parameters and cap default results at 20-50 items with a clear statement in tool descriptions.
No permission checks or scope declarations. Tools like execute_command_in_container and execute_remote_command can run arbitrary commands but have no authorization layer. Add tool-level scope declarations (e.g., 'Requires: exec:container' or 'Requires: exec:remote') and verify caller permissions server-side.
No audit logging visible in tool implementations. For security-sensitive operations (execute_command_in_container, execute_remote_command, download_image), there should be comprehensive logging: who called it, with which parameters (sanitized), when, and what the result was.
No destructive operation confirmation or dry-run mode. download_image (irreversible), execute_remote_command (can modify target systems), and execute_command_in_container (can delete/modify data) lack user confirmation or preview steps. Implement a confirmation_request pattern or add a dry_run parameter.