Documentation
README
Testing MCP Server Security
When to Use
- During authorized assessments of AI agents/IDEs (Cursor, Claude Code/Desktop, Flowise) that load MCP servers
- When reviewing third-party or marketplace MCP servers/skills before or after deployment
- When an MCP server runs locally over
stdioand inherits the user's OS credentials - When testing whether tool descriptions, schemas, or outputs can inject instructions into the model
- When assessing MCP config trust, update/supply-chain risk, and transport-layer auth gaps
Prerequisites
This is the opening of the README. Read the full README on GitHub.