
damn-vulnerable-MCP-server
Damn Vulnerable MCP Server

Damn Vulnerable MCP Server

Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging…

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

MCP server for Slither static analysis of Solidity smart contracts

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MCP server for Claude Code and LangChain…


AIO Cloud Managment Server

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

server security auditor scanning Apache, Nginx, and IIS configurations with AI-powered hardening guides and professional reporting.

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in…

A collection of awesome resources related AI security

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs