damn-vulnerable-MCP-server

MCP.Pizza Chef: harishsg993010

Ten challenges, graded easy to hard, each showing a different way a tool connection can be abused: hidden instructions buried in a tool description, tools that quietly change behavior after you install them, stolen sign-in credentials, and commands that escape onto the host machine. Written solutions are included. The whole lab runs in Docker on your own computer, and it is strictly a teaching exercise — nothing here belongs in real life.

Coding
Other

Use This MCP server To

Practice spotting a poisoned tool description Learn how prompt injection actually works Test a security scanner against known weaknesses Train my team on the risks of assistant tools Work through ten graded challenges with solutions

README

Damn Vulnerable Model Context Protocol (DVMCP)

A deliberately vulnerable implementation of the Model Context Protocol (MCP) for educational purposes.

Overview

The Damn Vulnerable Model Context Protocol (DVMCP) is an educational project designed to demonstrate security vulnerabilities in MCP implementations. It contains 10 challenges of increasing difficulty that showcase different types of vulnerabilities and attack vectors.

This project is intended for security researchers, developers, and AI safety professionals to learn about potential security issues in MCP implementations and how to mitigate them.

What is MCP?

The Model Context Protocol (MCP) is a standardized protocol that allows applications to provide context for Large Language Models (LLMs) in a structured way. It separates the concerns of providing context from the actual LLM interaction, enabling applications to expose resources, tools, and prompts to LLMs.

Recommended MCP Clients

CLINE - VSCode Extension
Refer to this Connecting to a Remote Server - Cline for connecting Cline with MCP server

Quick Start

Once you have cloned the repository, run the following commands:

docker build -t dvmcp .
docker run -p 9001-9010:9001-9010 dvmcp

Disclaimer

It's not stable in a Windows environment. If you don't want to use Docker then please use Linux environment. I recommend Docker to run the LAB and I am 100% percent sure it works well in the Docker environment

damn-vulnerable-MCP-server FAQ

Who is this for?
Security researchers, developers, and anyone who wants to see how assistant tool connections get attacked.
Is it safe to run?
Only inside the provided Docker container, and never on a machine holding anything you care about. The flaws are real.
How hard is the setup?
You build and run a Docker image, which exposes the ten practice challenges on separate ports.
Can I use this to test my own security tooling?
Yes — it hands you ten known weaknesses to check a scanner or a review process against.
Are there answers?
Yes, a solutions guide is included, though attempting the challenges first is rather the point.
Does it work on Windows?
The author says Windows is unstable and recommends Docker or Linux instead.