mcp-hardened
Related Servers
Alternatives to mcp-hardened
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityDmaintenanceAn intentionally vulnerable MCP server designed as a live demo target for the MCP Trust security scanner. It contains deliberate insecure patterns to demonstrate scanning capabilities.-
- FlicenseNot gradedqualityDmaintenanceA deliberately insecure MCP server designed as a pentest lab to demonstrate common vulnerabilities in MCP deployments.-
- AlicenseNot gradedqualityBmaintenanceA security-first, read-only MCP server that lets clients browse and read text, PDF, and XLSX files from an explicit allowlist of local folders, with strict path and secret protections.MIT
- AlicenseAqualityDmaintenanceA compact MCP server demonstrating explicit tool boundaries, least-privilege discovery, execution-time authorization, destructive-action confirmation, and metadata-only audit logs using a local note store.3MIT
- FlicenseNot gradedqualityCmaintenanceA deliberately vulnerable MCP server that allows clients to interact with a database for educational purposes, demonstrating security vulnerabilities including SQL injection, arbitrary code execution, and sensitive data exposure.4-
- FlicenseNot gradedqualityDmaintenanceAn educational MCP server demonstrating common security vulnerabilities like command injection, path traversal, SQL injection, and XXE attacks. Designed for security training purposes only, not for production use.-
TDQS
Scored across 4 tools
Each tool has a clearly distinct purpose: ping for smoke testing, search_files for reading a note, query_records for searching records, and fetch_doc for retrieving a URL. There is no overlap or ambiguity between them.
Three tools follow a verb_noun pattern (search_files, query_records, fetch_doc), but 'ping' is a standalone command and 'search_files' is misleading since it actually reads a note rather than searching files. This mixing of conventions reduces consistency.
The four tools form a compact and well-scoped set for a lightweight server, covering a smoke test, file access, record lookup, and URL fetching without unnecessary bloat.
The toolset offers read operations for different resources but lacks discovery methods (e.g., listing notes, categories, or available URLs) and any write capabilities. This limits the ability to perform full workflows without prior external knowledge.