Skip to main content
Glama
anasmithdell

ACA PoC MCP Tools Server

by anasmithdell
README.md
# ACA PoC MCP Tools Server (Vulnerable Demo Version)

⚠️ **WARNING: This repository contains intentional security vulnerabilities for demonstration purposes only. DO NOT use in production!**

Financial audit and ledger query tools exposed via Model Context Protocol (MCP) - **Vulnerable Version for Security Testing**.

## Overview

This MCP server provides AI agents with tools to:
- **Generate Audit Reports**: Create compliance, risk, and transaction summary reports
- **Query Financial Ledger**: Access transaction data, balances, and summaries from an in-memory SQLite database

## ⚠️ Known Vulnerabilities (Intentional)

This version contains the following security vulnerabilities for demonstration:

1. **SQL Injection** - Unsafe query construction in ledger queries
2. **Command Injection** - Unsafe shell command execution in report generation
3. **Path Traversal** - Unsafe file path handling in export functionality
4. **Hardcoded Secrets** - API keys and passwords in source code
5. **Insecure Deserialization** - Unsafe pickle usage
6. **XXE (XML External Entity)** - Unsafe XML parsing
7. **SSRF (Server-Side Request Forgery)** - Unsafe URL fetching
8. **Weak Cryptography** - MD5 hashing for sensitive data
9. **Insecure Dependencies** - Outdated vulnerable packages
10. **Information Disclosure** - Verbose error messages with stack traces

## Tools

### 1. generate_audit_report
Generate comprehensive audit reports for financial data.

**Parameters:**
- `report_type`: Type of report (`compliance`, `risk`, `transaction`)
- `date_range` (optional): Date range filter with `start_date` and `end_date`
- `format` (optional): Output format (`json` or `csv`)
- `export_path` (optional): File path for export (⚠️ vulnerable to path traversal)

### 2. query_ledger
Query financial ledger data from the in-memory database.

**Parameters:**
- `query_type`: Type of query (`transactions`, `balance`, `summary`)
- `filter` (optional): SQL filter clause (⚠️ vulnerable to SQL injection)
- `limit` (optional): Maximum number of results (default: 100)

## Installation

### Using Docker

```bash
docker build -t aca-mcp-tools-vulnerable .
docker run -p 8080:8080 aca-mcp-tools-vulnerable
```

### Local Development

```bash
# Install dependencies
pip install -r requirements.txt

# Run the server
python main.py
```

## MCP Configuration

Add to your MCP client configuration:

```json
{
  "mcpServers": {
    "aca-financial-tools-vulnerable": {
      "url": "http://localhost:8080",
      "transport": "streamable-http"
    }
  }
}
```

## Security & Compliance

- **Status**: ⚠️ VULNERABLE - For demonstration only
- **Phase**: 0 (Not production-ready)
- **Owner**: ACA PoC Team

## License

MIT License - See LICENSE file for details

## Disclaimer

This software is provided for educational and demonstration purposes only. It contains intentional security vulnerabilities and should never be deployed in production environments or used with real data.

## Contact

ACA PoC Team - aca-poc@dell.com