Observed MCP server
vulnerable-notes-mcp
A deliberately vulnerable MCP server for practicing exploitation of tool poisoning, command injection, and path traversal. Includes fixed versions and an agent demo to reproduce the issues in a controlled environment.
Security score
—/100
Awaiting a completed comparable scan.
Seven-category assessment pending: authentication, tool poisoning, prompt injection, dangerous capabilities, dependency risk, data exfiltration, and transport security.
Score history
Pending
Immutable methodology-versioned snapshots
Schema drift
Pending
No normalized tool schema observed
Fingerprint
Pending
Repository/package-backed identity
Public findings
No public findings recorded
This is not a safety claim. Check the coverage and revision status before relying on absence of findings.