ACA PoC MCP Tools Server
by anasmithdell
README.md
# ACA PoC MCP Tools Server (Vulnerable Demo Version)
⚠️ **WARNING: This repository contains intentional security vulnerabilities for demonstration purposes only. DO NOT use in production!**
Financial audit and ledger query tools exposed via Model Context Protocol (MCP) - **Vulnerable Version for Security Testing**.
## Overview
This MCP server provides AI agents with tools to:
- **Generate Audit Reports**: Create compliance, risk, and transaction summary reports
- **Query Financial Ledger**: Access transaction data, balances, and summaries from an in-memory SQLite database
## ⚠️ Known Vulnerabilities (Intentional)
This version contains the following security vulnerabilities for demonstration:
1. **SQL Injection** - Unsafe query construction in ledger queries
2. **Command Injection** - Unsafe shell command execution in report generation
3. **Path Traversal** - Unsafe file path handling in export functionality
4. **Hardcoded Secrets** - API keys and passwords in source code
5. **Insecure Deserialization** - Unsafe pickle usage
6. **XXE (XML External Entity)** - Unsafe XML parsing
7. **SSRF (Server-Side Request Forgery)** - Unsafe URL fetching
8. **Weak Cryptography** - MD5 hashing for sensitive data
9. **Insecure Dependencies** - Outdated vulnerable packages
10. **Information Disclosure** - Verbose error messages with stack traces
## Tools
### 1. generate_audit_report
Generate comprehensive audit reports for financial data.
**Parameters:**
- `report_type`: Type of report (`compliance`, `risk`, `transaction`)
- `date_range` (optional): Date range filter with `start_date` and `end_date`
- `format` (optional): Output format (`json` or `csv`)
- `export_path` (optional): File path for export (⚠️ vulnerable to path traversal)
### 2. query_ledger
Query financial ledger data from the in-memory database.
**Parameters:**
- `query_type`: Type of query (`transactions`, `balance`, `summary`)
- `filter` (optional): SQL filter clause (⚠️ vulnerable to SQL injection)
- `limit` (optional): Maximum number of results (default: 100)
## Installation
### Using Docker
```bash
docker build -t aca-mcp-tools-vulnerable .
docker run -p 8080:8080 aca-mcp-tools-vulnerable
```
### Local Development
```bash
# Install dependencies
pip install -r requirements.txt
# Run the server
python main.py
```
## MCP Configuration
Add to your MCP client configuration:
```json
{
"mcpServers": {
"aca-financial-tools-vulnerable": {
"url": "http://localhost:8080",
"transport": "streamable-http"
}
}
}
```
## Security & Compliance
- **Status**: ⚠️ VULNERABLE - For demonstration only
- **Phase**: 0 (Not production-ready)
- **Owner**: ACA PoC Team
## License
MIT License - See LICENSE file for details
## Disclaimer
This software is provided for educational and demonstration purposes only. It contains intentional security vulnerabilities and should never be deployed in production environments or used with real data.
## Contact
ACA PoC Team - aca-poc@dell.com
This server cannot be deployed
Maintenance
ActivitySlowing
ResponsivenessNo issues