tryb
UnscannedpendingTemporal graph

Observed MCP server

vulnerable-notes-mcp

A deliberately vulnerable MCP server for practicing exploitation of tool poisoning, command injection, and path traversal. Includes fixed versions and an agent demo to reproduce the issues in a controlled environment.

Security score

/100

Awaiting a completed comparable scan.

Seven-category assessment pending: authentication, tool poisoning, prompt injection, dangerous capabilities, dependency risk, data exfiltration, and transport security.

Score history

Pending

Immutable methodology-versioned snapshots

Schema drift

Pending

No normalized tool schema observed

Fingerprint

Pending

Repository/package-backed identity

Public findings

No public findings recorded

This is not a safety claim. Check the coverage and revision status before relying on absence of findings.

vulnerable-notes-mcp MCP evidence | tryb.dev