A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.
☆266Dec 18, 2025Updated 7 months ago
Alternatives and similar repositories for vulnerable-mcp-servers-lab
Users that are interested in vulnerable-mcp-servers-lab are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Hands-on MCP security lab: 10 real incidents reproduced with vulnerable/secure MCP servers, pytest regressions, and Claude/Cursor battle-…☆89Dec 3, 2025Updated 7 months ago
- A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth fl…☆34Apr 7, 2026Updated 3 months ago
- AWS Attack Path Scanner - Discover privilege escalation paths across 10+ AWS services☆155Dec 4, 2025Updated 7 months ago
- AI-driven vulnerability discovery and live validation☆335May 5, 2026Updated 2 months ago
- Security preflight and guardrails for OpenClaw/Moltbot☆19Jan 30, 2026Updated 5 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆25Dec 5, 2025Updated 7 months ago
- SecureMCP is a security auditing tool designed to detect vulnerabilities and misconfigurations in applications using the [Model Context P…☆140Jun 7, 2025Updated last year
- Semgrep Pro Rules to ensure code using LLMs is following best practices☆71Mar 25, 2026Updated 3 months ago
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆37Jun 19, 2026Updated last month
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆172Updated this week
- A universal MCP client with proxying feature to interact with MCP Servers which support STDIO transport.☆22Apr 17, 2026Updated 3 months ago
- Open-source EDR for AI agents. Monitor processes, files, network, and behavior of autonomous AI agents.☆138Jun 6, 2026Updated last month
- A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.☆741Apr 8, 2026Updated 3 months ago
- Scan A2A agents for potential threats and security issues☆161Apr 16, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated last month
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆367Jun 27, 2026Updated 3 weeks ago
- PayloadsAllTheThings Skills Plugin for Claude Code☆21Jan 3, 2026Updated 6 months ago
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.☆28May 23, 2026Updated last month
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆70Nov 27, 2025Updated 7 months ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,354Updated this week
- SimpleCrypt is a powerful command-line tool designed for securely encrypting and decrypting files and directories using AES-256 encryptio…☆20Mar 22, 2026Updated 3 months ago
- A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS ac…☆159Jun 10, 2026Updated last month
- Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems☆122Updated this week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- MCP server for AI-driven security pipelines☆799Apr 9, 2026Updated 3 months ago
- AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.☆2,017Feb 13, 2026Updated 5 months ago
- Gixy-Next: NGINX Configuration Security Scanner & Performance Checker☆184Jun 9, 2026Updated last month
- MCP to help Defenders Detection Engineer Harder and Smarter☆462Jun 16, 2026Updated last month
- High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential v…☆639Updated this week
- A comprehensive database of Model Context Protocol vulnerabilities, security research, and exploits☆39Feb 16, 2026Updated 5 months ago
- Nova-Proximity is a MCP and Agent Skills security scanner powered with NOVA☆302Mar 26, 2026Updated 3 months ago
- An AWS IAM Privilege Escalation Path Library☆148Jul 7, 2026Updated last week
- ☆106Updated this week
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- BlueSky OSINT Tool☆15Dec 10, 2024Updated last year
- AI-Driven Threat Modeling & Attack Tree Generation with MITRE ATT&CK Integration☆63Updated this week
- Scan MCP servers for potential threats & security findings.☆987Updated this week
- ☆453Mar 4, 2026Updated 4 months ago
- Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.☆113Dec 3, 2025Updated 7 months ago
- CredData is a set of files including credentials in open source projects. CredData includes suspicious lines with manual review results a…☆95Jul 6, 2026Updated 2 weeks ago
- Threat modeling playbook for cloud-native, AI (RAG, agents), and A2A systems with STRIDE, risk models, controls, and test plans.☆17Jul 3, 2026Updated 2 weeks ago