Skip to main content
Glama
ds-ac-poc

DVMCP — Damn Vulnerable MCP

by ds-ac-poc

Related Servers

Alternatives to DVMCP — Damn Vulnerable MCP

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      C
      maintenance
      A deliberately insecure MCP server for practicing penetration testing, featuring 26 challenges at three difficulty levels with flags to capture, covering vulnerabilities like RCE, SSRF, SQLi, and more.
      8
      MIT
    • A
      license
      C
      quality
      C
      maintenance
      A deliberately vulnerable MCP server for practicing exploitation of tool poisoning, command injection, and path traversal. Includes fixed versions and an agent demo to reproduce the issues in a controlled environment.
      2
      MIT
    • F
      license
      C
      quality
      D
      maintenance
      IMCP - Insecure Model Context Protocol The DVWA for AI Security! Welcome to IMCP – a deliberately vulnerable framework that exposes 16 critical security weaknesses in AI/ML systems. Whether you're a security researcher, developer, or educator, IMCP is your playground for hands-on learning about real
      15
      4
      JavaScript
      -

    TDQS

    B3.4/5.0

    Scored across 28 tools

    Disambiguation5/5

    Each tool has a clearly distinct purpose, and the domain prefixes (hr., eng., fin., etc.) further prevent confusion. Even similar functions like process_payment and wire_transfer are clearly differentiated by their descriptions.

    Naming Consistency5/5

    All tool names follow a consistent pattern: domain prefix (e.g., hr., fin.) followed by snake_case verb_noun (e.g., search_employees, run_payroll_report). There is no mixing of conventions or inconsistent verb usage.

    Tool Count2/5

    28 tools is excessive for a single MCP server, exceeding the 25+ threshold. While the broad scope across multiple departments explains the count, it feels heavy and dilutes focus, making the server harder to navigate.

    Completeness3/5

    The tool set covers a wide range of enterprise operations (HR, engineering, finance, support, IT, marketing) but has some notable gaps such as no delete operations for most resources and no employee creation or invoice creation. This is workable but not fully comprehensive.

    Maintenance

    ActivitySlowing
    ResponsivenessNo issues