Damn Vulnerable MCP Server (DVMCP)
Related Servers
Alternatives to Damn Vulnerable MCP Server (DVMCP)
No user-submitted related servers found.
Related Servers
- AlicenseBqualityCmaintenanceAn intentionally vulnerable MCP server for security training, simulating a fictional company with 28 vulnerable tools and 38 challenges to learn AI agent attack and defense.28MIT
- FlicenseNot gradedqualityFmaintenanceAn educational project that deliberately implements vulnerable MCP servers to demonstrate various security risks like prompt injection, tool poisoning, and code execution for training security researchers and AI safety professionals.1,345-
- FlicenseNot gradedqualityDmaintenanceA vulnerable MCP server designed for educational CTF challenges. It demonstrates various MCP security vulnerabilities in a controlled environment.8-
- FlicenseCqualityDmaintenanceIMCP - Insecure Model Context Protocol The DVWA for AI Security! Welcome to IMCP – a deliberately vulnerable framework that exposes 16 critical security weaknesses in AI/ML systems. Whether you're a security researcher, developer, or educator, IMCP is your playground for hands-on learning about real154JavaScript-
- FlicenseNot gradedqualityDmaintenanceAn educational MCP server demonstrating common security vulnerabilities like command injection, path traversal, SQL injection, and XXE attacks. Designed for security training purposes only, not for production use.-
- FlicenseNot gradedqualityBmaintenanceAn intentionally vulnerable MCP server for security education, demonstrating flaws like missing auth, SSRF, SQLi, and file system abuse.-
TDQS
Scored across 28 tools
Tools are grouped by domain prefixes (eng., fin., hr., it., mktg., support.), and each group has clearly distinct purposes. No two tools appear to overlap in functionality, making it easy for an agent to select the correct tool.
All tool names follow a consistent pattern: domain prefix + verb + noun, using lowercase and underscores. Verbs are predictable (manage, query, read, run, trigger, etc.), and there is no mixing of naming conventions.
With 28 tools spanning six domains, the count is on the higher side but still reasonable given the broad scope. Each domain has a focused set of tools, and none appear redundant.
The tool surface covers core CRUD and operational tasks across all domains. Minor gaps exist (e.g., no support ticket creation, no refund processing), but the major workflows for each domain are represented.