This repository demonstrates a security vulnerability in MCP (Model Context Protocol ) servers that allows for remote code execution and data exfiltration through tool poisoning.
☆25Apr 21, 2025Updated last year
Alternatives and similar repositories for mcp-exploit-demo
Users that are interested in mcp-exploit-demo are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- One scan for AI risk. `opena2a review` checks an AI project across credentials, shadow agents, MCP servers, and dependencies, returns a s…☆21Sep 12, 2026Updated last week
- This repository demonstrates a variety of **MCP Poisoning Attacks** affecting real-world AI agent workflows.☆15Jun 14, 2025Updated last year
- ☆84Aug 11, 2026Updated last month
- A tool for deobfuscation of JVM bytecode by analyzing similarities in call-graphs and other program features☆14Nov 14, 2012Updated 13 years ago
- Use Hive to hijack a Hadoop cluster+☆17Apr 30, 2020Updated 6 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A modular, extensible vulnerability scanner in Go.☆18Updated this week
- IP over DNS tunnel☆23May 23, 2017Updated 9 years ago
- 南开大学教学管理系统安卓客户端☆10Jan 20, 2014Updated 12 years ago
- ☆14Aug 7, 2025Updated last year
- A Jailbreak Package Manager for Apple Devices (based on PurePKG)☆12Feb 25, 2025Updated last year
- A living map of the AI agent security ecosystem.☆71Jun 12, 2026Updated 3 months ago
- only 5 characters to rce☆16Aug 17, 2022Updated 4 years ago
- ☆18Dec 15, 2021Updated 4 years ago
- The purpose of this script is to bypass disablefund, provide some useful information, and dig the hook function of PHP extension.☆14Jul 1, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Jagged Frontier: LLM vulnerability detection benchmark harnesses (API + Claude Code agentic)☆15Updated this week
- GUARDRAIL - MCP Security - Gateway for Unified Access, Resource Delegation, and Risk-Attenuating Information Limits☆18Jul 21, 2025Updated last year
- ☆16Aug 6, 2025Updated last year
- ☆11Dec 11, 2018Updated 7 years ago
- ☆50Feb 26, 2025Updated last year
- os_log command line tool implementation for iOS☆13Feb 18, 2022Updated 4 years ago
- ☆15Apr 13, 2026Updated 5 months ago
- OWASP Foundation Web Respository☆16Oct 4, 2025Updated 11 months ago
- The IAM layer for AI agents: cryptographic identity, capability authorization, and audit trails for non-human identities. Open source.☆67Updated this week
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- 基于多种策略, 对已有 JAR 包中的全限定类名进行变换, 无限生成高度相似的虚假类名☆20Jul 30, 2025Updated last year
- A comprehensive database of Model Context Protocol vulnerabilities, security research, and exploits☆40Feb 16, 2026Updated 7 months ago
- Two-Level Collaborative Fuzzing for Python Runtimes☆18Nov 25, 2023Updated 2 years ago
- ☆13Aug 29, 2024Updated 2 years ago
- macOS Record Replay Debugger☆60Apr 7, 2026Updated 5 months ago
- Damn Vulnerable AI Application - For LLM Red Team Training. LLM testing, RAG testing, Multimodal testing, Agent testing, LLM paload gener…☆41Jul 21, 2026Updated 2 months ago
- OPA OpenFGA experiments☆20Nov 6, 2022Updated 3 years ago
- AArch64 FEAT_CSSC support for IDA Pro (disassembler/Hex-Rays) and Ghidra☆19Sep 20, 2025Updated last year
- A Skill for using UniFuncs for deepsearch, deepresearch, and web search and web page reading capabilities.☆18May 27, 2026Updated 3 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A durable blackboard runtime for verifiable Claude Code agent loops.☆19Jun 10, 2026Updated 3 months ago
- A tool for extracting, modifying, and crafting ASDM binary packages (CVE-2022-20829)☆14Aug 15, 2022Updated 4 years ago
- Example usage of github.com/go-webauthn/webauthn☆19Dec 15, 2023Updated 2 years ago
- Rust bindings for Apple's FoundationModels.framework☆24Aug 16, 2026Updated last month
- A lightweight utility to monitor filesystem events and run a script on matching conditions.☆15May 6, 2026Updated 4 months ago
- Puppet module for OpenSCAP☆14Sep 9, 2026Updated 2 weeks ago
- Zero Trust Agent☆59Mar 28, 2026Updated 5 months ago