evil-winrm-py — security grade SAFE, quality 67/100

Security audit verdict: SAFE · quality 67/100

Flagged: sudo usage. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by adityatelange · MCP Server · ★ 397

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is evil-winrm-py safe to install? View the security audit →

About evil-winrm-py

evil-winrm-py is a python-based tool for executing commands on remote Windows machines using the WinRM (Windows Remote Management) protocol. It provides an interactive shell with enhanced features like file upload/download, command history, and colorized output. It supports various authentication methods including NTLM, Pass-the-Hash, Certificate, and Kerberos. [!NOTE] This tool is designed strictly for educational, ethical use, and authorized penetration testing. Always ensure you have explicit authorization before accessing any system. Unauthorized access or misuse of this tool is both illegal a

active-directoryclihacktheboxinfosectoolsjeakerberosmcpmcp-serverpentest-toolpentesting

Quick Facts

Stars397
Forks37
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score67.4735955162004/100
Open Issues2
Last Updated2026-09-20
Created2025-04-13
Platformscli, mcp, python
Est. Tokens~15k

Compatible Skills

These tools work well together with evil-winrm-py for enhanced workflows:

  • communitytools — semantic(0.19)+complementary+rare_topics+same_lang+similar_pop+shared_platform (61%)
  • deepseek-translation-studio — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (57%)
  • claude-keysmith — semantic(0.18)+complementary+same_lang+similar_pop+shared_platform (56%)

evil-winrm-py alternative? Top 6 similar tools

Looking for a evil-winrm-py alternative? If you're comparing evil-winrm-py with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • AutoRedTeam-Orchestrator by Coff0xc · ⭐ 263

    MCP-native security automation workbench (SDK + CLI + MCP) — authorized testing + static AI/MCP attack-surface

  • cheatengine-mcp-bridge by miscusi-peek · ⭐ 1.2k

    Connect Cursor, Copilot & Claude AI directly to Cheat Engine via MCP. Automate reverse engineering, pointer sc

  • agentic-radar by splx-ai · ⭐ 1.1k

    A security scanner for your LLM agentic workflows

  • Dark-Moon by ASCIT31 · ⭐ 957

    Open source autonomous AI penetration testing platform. 50+ specialist agents for AI security testing across w

  • drift by dadbodgeoff · ⭐ 785

    Codebase intelligence for AI. Detects patterns & conventions + remembers decisions across sessions. MCP server

  • blitzstrike by shinthink · ⭐ 637

    ⚡ Blitz Strike — a universal MCP penetration-testing toolbelt. Structured methodology: reconnaissance & attack

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is evil-winrm-py?

evil-winrm-py is Execute commands interactively on remote Windows machines using the WinRM protocol (just faster). It is categorized as a MCP Server with 397 GitHub stars.

What programming language is evil-winrm-py written in?

evil-winrm-py is primarily written in Python. It covers topics such as active-directory, cli, hackthebox.

How do I install or use evil-winrm-py?

You can find installation instructions and usage details in the evil-winrm-py GitHub repository at github.com/adityatelange/evil-winrm-py. The project has 397 stars and 37 forks, indicating an active community.

What license does evil-winrm-py use?

evil-winrm-py is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to evil-winrm-py?

The top alternatives to evil-winrm-py on Agent Skills Hub include AutoRedTeam-Orchestrator, cheatengine-mcp-bridge, agentic-radar. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools