general MCP Server
An AI-driven dynamic protocol fuzzer for the Model Context Protocol (MCP). Prove runtime exploitability by discovering state violations, transport crashes, and application-layer logic flaws (SSRF, LFI) before your AI agents do.
Discovered via github-seeds:mcp-hot and last synced 3mo ago.
1. Install the package
pip install mcpsec
~60
Languages
Description
LLM manipulation via descriptions
Insecure Direct Object Reference detection
105
SQL Injection (Error, Time, Boolean, Stacked)
~80
OS command injection with 138 payloads
Undeclared capability abuse
[Issue #1765](https://github.com/modelcontextprotocol/typescript-sdk/issues/1765)
Pickle, XXE, and unsafe YAML parsing
~45
Missing authentication, dangerous tool combos
Identifies dangerous Write→Read data flows
~25
Server-Side Request Forgery with 81 payloads
Detects `eval()`, `exec()`, and `compile()` sinks
Vulnerability
Directory traversal with 104 payloads
Dangerous tool combination detection
Python, JS/TS, Go, Rust, Java, C, C#, Ruby, PHP
Hidden instructions in tool descriptions
SSRF via MCP resource URIs
Environment variable and credential disclosure
Targets SSTI and string formatting vulnerabilities
[Issue #52](https://github.com/radareorg/radare2-mcp/issues/52)
[Issue #45](https://github.com/radareorg/radare2-mcp/issues/45) - Fixed in [commit 482cde6](https://github.com/radareorg/radare2-mcp/commit/482cde6)
61 crash cases, exception handling DoS
61 crash cases
Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.
Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.
Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
Flexible and powerful framework for managing multiple AI agents and handling complex conversations
为独立开发者准备的精选技术栈和工具仓库来了!这里有你最需要的工具,帮你提升开发效率、节约成本,最重要的是——这些工具都是市场上热门的,经过验证的。🚀A curated collection of tech stacks and tools tailored for independent developers is here! these are proven, popular tools widely used in the industry. 🚀
Learn Cloud Applied Generative AI Engineering (GenEng) using OpenAI, Gemini, Streamlit, Containers, Serverless, Postgres, LangChain, Pinecone, and Next.js
The secure gateway connecting AI agents to enterprise systems.
Learn how to use the cloud-aws Claude skill. Complete guide with installation instructions and examples.
Learn how to use the detecting-aws-iam-privilege-escalation Claude skill. Complete guide with installation instructions and examples.
Learn how to use the detecting-aws-guardduty-findings-automation Claude skill. Complete guide with installation instructions and examples.