invariantlabs-ai / mcp-injection-experimentsView external linksLinks
Code snippets to reproduce MCP tool poisoning attacks.
☆192Apr 10, 2025Updated 10 months ago
Alternatives and similar repositories for mcp-injection-experiments
Users that are interested in mcp-injection-experiments are comparing it to the libraries listed below
Sorting:
- Security scanner for AI agents, MCP servers and agent skills.☆1,462Updated this week
- MCPSafetyScanner - Automated MCP safety auditing and remediation using Agents. More info: https://www.arxiv.org/abs/2504.03767☆163Apr 10, 2025Updated 10 months ago
- Guardrails for secure and robust agent development☆389Jan 12, 2026Updated last month
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis (IEEE S&P 2024)☆13Oct 3, 2024Updated last year
- CVE-Bench: A Benchmark for AI Agents’ Ability to Exploit Real-World Web Application Vulnerabilities☆146Jan 14, 2026Updated last month
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit Generation☆14Jul 24, 2025Updated 6 months ago
- A comprehensive security checklist for MCP-based AI tools. Built by SlowMist to safeguard LLM plugin ecosystems.☆799Apr 28, 2025Updated 9 months ago
- 参考taviso的代码逆向一下mpengine.dll☆20Jun 30, 2022Updated 3 years ago
- What's the Red Team doing to my Linux Box? - BSides Vienna 2024☆17Nov 23, 2024Updated last year
- ☆23Apr 6, 2019Updated 6 years ago
- Hacking GraalVM Espresso - Abusing Continuation API to Make ROP-like Attack☆36Aug 27, 2025Updated 5 months ago
- ☆21Apr 30, 2021Updated 4 years ago
- IDA Hexrays To Joern☆44Nov 7, 2024Updated last year
- Damn Vulnerable MCP Server☆1,253Dec 8, 2025Updated 2 months ago
- Python tool for exploiting CVE-2021-35616☆11Dec 3, 2021Updated 4 years ago
- COVA - A static analysis tool to compute path conditions☆40Jul 12, 2025Updated 7 months ago
- 🔥🔒 Awesome MCP (Model Context Protocol) Security 🖥️☆652Feb 8, 2026Updated last week
- ☆27Feb 6, 2024Updated 2 years ago
- A comprehensive security scanner for Model Context Protocol (MCP) servers that detects vulnerabilities and security issues in your MCP se…☆121Dec 14, 2025Updated 2 months ago
- YASA is an open-source static program analysis project. Its core innovation lies in a unified intermediate representation called UAST, d…☆246Feb 3, 2026Updated 2 weeks ago
- PoC for CVE-2021-43557☆22Nov 22, 2021Updated 4 years ago
- Scan A2A agents for potential threats and security issues☆113Jan 13, 2026Updated last month
- The source code of [Sec'25] Make Agent Defeat Agent: Automatic Detection of Taint-Style Vulnerabilities in LLM-based Agents☆53Sep 9, 2025Updated 5 months ago
- static sites for blog.orange.tw☆23Dec 31, 2025Updated last month
- ☆12Mar 7, 2025Updated 11 months ago
- ☆13Feb 9, 2022Updated 4 years ago
- ☆370Sep 20, 2025Updated 4 months ago
- ☆18Nov 6, 2024Updated last year
- A demonstration toolkit revealing potential security vulnerabilities in MCP (Model Context Protocol) frameworks through data poisoning, J…☆93Jul 6, 2025Updated 7 months ago
- ☆161Jun 3, 2024Updated last year
- Exploit for Microsoft SharePoint 2019☆13Dec 28, 2023Updated 2 years ago
- This is the official repository for the ICLR 2025 accepted paper Badrobot: Manipulating Embodied LLMs in the Physical World.☆41Jun 26, 2025Updated 7 months ago
- Crashbench is a LLM benchmark to measure bug-finding and reporting capabilities of LLMs☆14Jan 20, 2026Updated 3 weeks ago
- awd attack framework,Django + Mysql☆16Feb 8, 2025Updated last year
- A polyglot static analysis engine for detecting vulnerabilities in scripting languages native extensions based on joern.☆21Sep 1, 2025Updated 5 months ago
- This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.☆61Jan 25, 2025Updated last year
- PWNable pyjail☆13Jan 13, 2025Updated last year
- [ALL IN ONE] Everything that I shared to public about Cloud Security is here.☆60Apr 19, 2025Updated 9 months ago
- NodeJS File Write to RCE on a read-only filesystem using a ROP chain in libuv☆37Oct 13, 2024Updated last year