mcp-security-test-servers

security MCP Server

Reference MCP security lab: toxic tool metadata, multi-server mcp.json harness for static scan, localhost AAuth fixtures, YARA (OWASP Agentic ASI01–ASI10). Stress-test MCPShark and similar tools—not for production.

VerifiedInstall Ready
securitysecurity
2 views1 stars0 forksv1.0.0MIT

Why This Matters

Discovered via github-topic:mcp and last synced 2mo ago.

VerifiedInstall Ready
Source
github-topic:mcp
Stars
1
Last synced
2mo ago
Install
Instructions detected

Install

1. Install the package

npm install mcp-security-test-servers
20
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (20)

Oversharing

3

Command

Purpose

Path

Role

ASI08

DoS / exhaustion

Script

Purpose

ASI09

Supply chain

9703

`Authorization: Bearer …` (+ `--coexist` with `Signature-Input`)

start

Combined `all-vulnerabilities` stdio server

ASI10

Misplaced trust

Area

Examples in corpus

clean

Non-vulnerable baseline

File

Focus

Approach

Command / file

ASI05

Guardrails

9701

`Signature`, `Signature-Input`, `Signature-Key`, `AAuth-Agent`, `AAuth-Mission`

Fixture

Port

sarif

html`, `--output report.html`, `--strict`, `--walkthrough`, `--refresh-rules`. 3. **What the harness exercises** (examples): insecure `http://` / `ws://` URLs; `args` with `$(…)` or `

ASI04

Privilege / identity

9702

`401` + `AAuth-Requirement`

Category

Themes