vulnerable mcp fs-server

Created By
0pstecha year ago
vulnerable MCP server example
Overview

what is vuln-fs?

vuln-fs is a vulnerable MCP (Multi-Channel Protocol) server example designed for educational and testing purposes in security research.

how to use vuln-fs?

To use vuln-fs, clone the repository from GitHub, activate the virtual environment, and run the server using the provided command.

key features of vuln-fs?

  • Example of a vulnerable server for security testing
  • Educational resource for understanding server vulnerabilities
  • Open-source and available for modification

use cases of vuln-fs?

  1. Testing security tools and techniques against a known vulnerable server.
  2. Educational purposes for students learning about cybersecurity.
  3. Developing and testing patches for vulnerabilities.

FAQ from vuln-fs?

  • Is vuln-fs safe to use?

Yes, vuln-fs is intended for educational use in a controlled environment.

  • Can I modify the code?

Yes! As an open-source project, you are free to modify and enhance the code.

  • Where can I find the documentation?

Documentation can be found in the GitHub repository.

Project Info
Created At
a year ago
Updated At
a year ago
Author Name
0pstech
Star
0
Language
JavaScript
License
-
Category
security
Tags

Recommend Servers

View All
AI Work Market — USDC settlement rails for AI labor on Base Mainnet)
@Dario (DME)

AI Work Market is a USDC escrow protocol on Base Mainnet, designed for autonomous AI agents to find work, post jobs, and settle payments without humans in the loop. This MCP server exposes 10 tools: **Escrow lifecycle** - `create_intent_quote` — get calldata + gas estimate for funding a new escrow intent - `submit_proof_quote` — get calldata for the seller to submit a proof URI - `release_funds_quote` — get calldata for the buyer to release payment (or claim/refund) **x402 single-call binding** - `x402_consume` — replaces the 5-step x402 flow with one HMAC-signed POST that returns a delivery URL **Onboarding & discovery** - `agent_onboard` — generate a signed agent card with marketplace attestation - `agent_search` — tf-idf search over the live agent catalog - `agent_reputation` — server-side reputation from on-chain Released/Refunded/Disputed events **Live state** - `system_status` — live on-chain state (nextIntentId, accumulatedFees, contract balance, owner) - `escrow_rules` — contract semantics, lifecycle, call guides, failure modes - `events_subscribe` — SSE stream of new on-chain intent events All endpoints are serverless (Vercel) and return their schema on GET. No browser, no wallet UI required for an agent to integrate. The protocol takes a 1% commission on every settlement; the rest goes to the seller. The full AgentCard is at `/.well-known/agent-card.json` (A2A-compatible). The OpenAPI 3.0.3 spec is at `/.well-known/openapi.json` with `components.securitySchemes` (none, hmacX402). `robots.txt` allows GPTBot, ClaudeBot, anthropic-ai, PerplexityBot, Google-Extended, Applebot-Extended, CCBot, Amazonbot.

8 hours ago