Token导航 LogoToken导航TokenDH.com
Bad MCP (Amoranio) logo
浏览器工具未说明官方级别未说明来源级核验

Bad MCP (Amoranio)

MCP Server

一个交互式教育资源,用于学习模型上下文协议(MCP)安全漏洞、攻击向量和防御最佳实践。

工具数

0

提示词数

0

GitHub Stars

0

资源数

0
HTML浏览器自动化网页抓取

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

作者 / 组织

amoranio

提供方

amoranio

最后核验

2026/5/17 20:20

快速接入

先看主来源和安装命令,再打开仓库或文档;下面只保留这个条目的关键接入事实。

详细介绍

badMCP Logo

badMCP - MCP Security Exploitation Lab

An interactive educational resource for learning about Model Context Protocol (MCP) security vulnerabilities, attack vectors, and defensive best practices.

Overview

MCP enables AI assistants to connect to external data sources and tools. This creates unique security challenges because MCP tools receive inputs that may be influenced by untrusted content processed by AI models. badMCP teaches you to recognize and prevent these vulnerabilities through:

  • Side-by-side comparisons of vulnerable vs. secure code
  • Real-world attack scenarios and threat modeling
  • Interactive quizzes to test your knowledge
  • A comprehensive security best practices checklist

Vulnerability Topics Covered

  • Path Traversal - Preventing unauthorized file access
  • Command Injection - Safe execution of system commands
  • Credential Exposure - Proper secrets management
  • Tool Description Injection - Defending against malicious MCP servers
  • Response Injection - Handling untrusted tool outputs
  • Verbose Error Disclosure - Secure error handling

Usage

Open index.html in a browser to explore the lab locally, or deploy to any static hosting service.

Disclaimer

This lab is for educational purposes only. Use the vulnerable code examples only in isolated test environments.

目录标签

目录标签

HTML浏览器自动化网页抓取本地部署安全漏洞MCP协议交互式学习攻击向量防御实践

接入字段

传输方式(transport,传输协议)

未说明

鉴权方式(authType,认证方式)

none

工具数量(toolCount,工具数)

0

资源数量(resourceCount,资源数)

0

提示词数量(promptCount,提示词数)

0

权限和风险

未说明none部署方式未说明

接入前请确认传输方式、认证方式和部署位置,并根据实际工具能力限制访问范围。

安装前确认

不要直接授予不必要的文件、网络或账号权限;先核对安装命令和配置内容。

仍需确认:installCommand

来源信息

继续浏览同类 MCP