Command Palette

Search for a command to run...

UnylyUnyly
Весь каталог

Vulnerable Mcp Servers Lab

БесплатноНе проверен

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

GitHubEmbed

Описание

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

README

Vulnerable MCP Servers Lab

This repository contains intentionally vulnerable implementations of Model Context Protocol (MCP) servers (both local and remote). Each server lives in its own folder and includes a dedicated README.md with full details on what it does, how to run it, and how to demonstrate/attack the vulnerability.

Do not run any of this outside a controlled lab environment.

What this repo is for

  • Security training / research into common MCP server and tool-integration failure modes.
  • Hands-on demos of how vulnerable MCP servers can lead to data exposure, instruction injection, supply-chain compromise, and code execution.

Safety / lab guidance

  • Use a disposable VM/container and avoid using real secrets or personal data.
  • Prefer running on an isolated network; several servers make outbound network calls.
  • Treat all tool output and retrieved content as untrusted data.
  • If you expose any server over HTTP, assume it may be reachable/abused unless you add proper controls.

Getting started

  • Pick a server from the index below.
  • Open its per-server README and follow the instructions there.
  • Many servers include a claude_config.json snippet intended to be merged into Claude Desktop’s MCP configuration.

MCP servers in this repo

About Appsecco

Appsecco is a cybersecurity company specializing in product security testing, penetration testing, and security assessments. We hack SaaS products, AI Agents, MCP Servers and cloud/K8s infrastructure like attackers do, focusing on pragmatic, high-signal outcomes for real-world systems.

This lab repository exists to support security research and hands-on training for pentesters, who are on their journey to becoming AI Red Teamers, around MCP server vulnerabilities and the risks of integrating untrusted tools and untrusted content into AI agent workflows.

Contact

License

See LICENSE.

Links to Appsecco Resources

from github.com/appsecco/vulnerable-mcp-servers-lab

Установка Vulnerable Mcp Servers Lab

У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.

▸ github.com/appsecco/vulnerable-mcp-servers-lab

FAQ

Vulnerable Mcp Servers Lab MCP бесплатный?

Да, Vulnerable Mcp Servers Lab MCP бесплатный — установка в пару кликов через Unyly без оплаты.

Нужен ли API-ключ для Vulnerable Mcp Servers Lab?

Нет, Vulnerable Mcp Servers Lab работает без API-ключей и переменных окружения.

Vulnerable Mcp Servers Lab — hosted или self-hosted?

Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.

Как установить Vulnerable Mcp Servers Lab в Claude Desktop, Claude Code или Cursor?

Открой Vulnerable Mcp Servers Lab на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.

Похожие MCP

Compare Vulnerable Mcp Servers Lab with

Не уверен что выбрать?

Найди свой стек за 60 секунд

Автор?

Embed-бейдж для README

Похожее

Все в категории ai