A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.
☆277Dec 18, 2025Updated 8 months ago
Alternatives and similar repositories for vulnerable-mcp-servers-lab
Users that are interested in vulnerable-mcp-servers-lab are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Hands-on MCP security lab: 10 real incidents reproduced with vulnerable/secure MCP servers, pytest regressions, and Claude/Cursor battle-…☆89Dec 3, 2025Updated 8 months ago
- A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth fl…☆40Apr 7, 2026Updated 4 months ago
- AWS Attack Path Scanner - Discover privilege escalation paths across 10+ AWS services☆158Dec 4, 2025Updated 8 months ago
- AI-driven vulnerability discovery and live validation☆341May 5, 2026Updated 3 months ago
- Security preflight and guardrails for OpenClaw/Moltbot☆19Jan 30, 2026Updated 6 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆27Dec 5, 2025Updated 8 months ago
- SecureMCP is a security auditing tool designed to detect vulnerabilities and misconfigurations in applications using the [Model Context P…☆140Jun 7, 2025Updated last year
- Semgrep Pro Rules to ensure code using LLMs is following best practices☆73Mar 25, 2026Updated 5 months ago
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆39Aug 9, 2026Updated 3 weeks ago
- A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.☆178Jul 29, 2026Updated last month
- OS-level monitor for AI agents: observes processes, file access, and network activity on the local machine and attributes each event to a…☆145Updated this week
- A universal MCP client with proxying feature to interact with MCP Servers which support STDIO transport.☆23Apr 17, 2026Updated 4 months ago
- A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.☆771Apr 8, 2026Updated 4 months ago
- Scan A2A agents for potential threats and security issues☆164Apr 16, 2026Updated 4 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Audit content (pdfs, media files, images) sensitivity on urls☆45Jun 2, 2026Updated 2 months ago
- A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.☆375Aug 6, 2026Updated 3 weeks ago
- PayloadsAllTheThings Skills Plugin for Claude Code☆21Jan 3, 2026Updated 7 months ago
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.☆32May 23, 2026Updated 3 months ago
- A security tool that detects malicious packages from external vulnerability feeds and searches for them in your package registries or art…☆72Nov 27, 2025Updated 9 months ago
- Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents,…☆3,679Updated this week
- A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS ac…☆161Jun 10, 2026Updated 2 months ago
- Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems☆130Updated this week
- AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.☆2,052Feb 13, 2026Updated 6 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Gixy-Next: NGINX Configuration Security Scanner & Performance Checker☆188Aug 15, 2026Updated 2 weeks ago
- High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential v…☆684Updated this week
- MCP to help Defenders Detection Engineer Harder and Smarter☆477Jun 16, 2026Updated 2 months ago
- A comprehensive database of Model Context Protocol vulnerabilities, security research, and exploits