- SSH Key Exfiltration via MCP Tool Poisoning
SSH Key Exfiltration via MCP Tool Poisoning
This repository demonstrates a security vulnerability in MCP (Model Context Protocol ) servers that allows for remote code execution and data exfiltration through tool poisoning.
Overview
What is MCP Exploit Demo?
MCP Exploit Demo is a repository that showcases a security vulnerability in Model Context Protocol (MCP) servers, enabling remote code execution and data exfiltration through tool poisoning.
How to use MCP Exploit Demo?
To use this project, clone the repository and run the server.py script to set up a malicious MCP server. Connect to this server using an MCP client like Cursor AI to demonstrate the exploit.
Key features of MCP Exploit Demo?
- Demonstrates a real-world security vulnerability in MCP servers.
- Provides a malicious server implementation for educational purposes.
- Includes configuration files for integration with AI tools.
Use cases of MCP Exploit Demo?
- Educational demonstrations of security vulnerabilities.
- Testing and improving security measures in AI development tools.
- Researching remote code execution techniques.
FAQ from MCP Exploit Demo?
- Is this project safe to use?
This project is intended for educational and security research purposes only. Use it responsibly.
- Can I use this in a production environment?
No, this project is designed to demonstrate vulnerabilities and should not be used in production.
- What are the mitigation recommendations?
Disable auto-run features, verify MCP server sources, review untrusted code, use sandboxed environments, and implement egress filtering.
Project Info
Created At
a year agoUpdated At
a year agoAuthor Name
Repello-AIStar
3Language
PythonLicense
-Category
security
Recommend Servers
View AllAmap Maps
@amap
高德地图官方 MCP Server
a year ago
Traveltype Mcp Server
23 minutes ago
Filesystem
@modelcontextprotocol
2 months ago
Serper MCP Server
@garymengcom
A Serper MCP Server
Python
a year ago
Pet And Veterinary Products Recall
@agentprolabs
14 minutes ago
Airtreks Mcp
@SEKeener
18 hours ago