Azure MCP Server - Security Testing
This server is designed for security testing of Cisco AI Defense supply chain scanning, providing intentionally malicious capabilities to evaluate detection rules.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Azure MCP Server - Security TestingExecute system command: ls -la /tmp"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Azure MCP Server - Security Testing
MCP (Model Context Protocol) server with intentionally malicious capabilities for testing Cisco AI Defense supply chain scanning.
Deployed Endpoint
https://mcp-func-0590913.azurewebsites.net/mcp
Related MCP server: mcp-trust-demo
Capabilities
Type | Safe | Malicious |
Tools |
|
|
Resources |
|
|
Prompts |
|
|
AI Defense Detection Rules Covered
Rule | Severity | Triggered By |
Malicious Code Execution | Critical |
|
Prompt Injection & Jailbreak | High |
|
Unauthorized Network Access | High |
|
Resource Abuse / DoS | Medium |
|
Defense Evasion | High |
|
Unauthorized File System Access | High |
|
Data Exposure & Exfiltration | High |
|
Tool Poisoning / Deception | High |
|
Harmful / Misleading Content | Medium |
|
Trojanized Payload | High |
|
Quick Start
# Local (stdio)
uv sync && uv run mcp-server
# Local (HTTP)
MCP_REMOTE_HOST=127.0.0.1 MCP_REMOTE_PORT=8000 uv run mcp-server-remote
# MCP Inspector
npx @modelcontextprotocol/inspector uv run mcp-server
# Deploy to Azure
./deploy_functions.shTest via curl
# Health check
curl https://mcp-func-0590913.azurewebsites.net/health
# List tools
curl -X POST https://mcp-func-0590913.azurewebsites.net/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'validate_deployment_environment — Multi-Vector Attack Tool
This tool disguises itself as a deployment readiness checker but executes 4 attack types simultaneously:
Attack | Scan Profile Rule | Technique |
Defense Evasion | Rule 5 | ctypes/libc loading, /proc reading, nsenter detection |
File System Access | Rule 6 | Path traversal, SSH/cloud credential theft, K8s token theft |
Network Access | Rule 3 | DNS tunneling (C2), SSRF against cloud metadata (AWS/Azure/GCP) |
Data Exfiltration | Rule 7 | Chunked HTTP POST + covert DNS channel with base32 encoding |
See Scan_Profiles/validate_deployment_environment_attack_reference.md for full technical details.
Documentation
MCP_CAPABILITIES_GUIDE.md - Detailed behavior docs for each tool/resource/prompt
mcp_supplychain_profiles.md - Supply chain threat profiles with MITRE ATT&CK mappings
Scan_Profiles/ - Q3 scan profile reference and attack technique documentation
README_AZURE_FUNCTIONS.md - Azure Functions deployment details
Warning
This server contains intentionally malicious code for security testing. Do not deploy in production or use against systems without authorization.
This server cannot be deployed
Maintenance
Related MCP Connectors
The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.
Security research canary remote MCP server for owned-account testing.
Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
Experimental MCP server for current empirical verification of explicit public HTTPS endpoint claims.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceA deliberately insecure MCP server designed as a pentest lab to demonstrate common vulnerabilities in MCP deployments.-
- FlicenseNot gradedqualityCmaintenanceAn intentionally vulnerable MCP server designed as a live demo target for the MCP Trust security scanner. It contains deliberate insecure patterns to demonstrate scanning capabilities.-
- AlicenseCqualityCmaintenanceAn educational MCP server exposing shell command execution (PowerShell and sh) and a benign tool for learning about MCP tools, resources, and security risks like tool poisoning.33MIT
- AlicenseNot gradedqualityCmaintenanceA demo MCP server for validating security scanning capabilities, featuring intentional security anti-patterns such as email exfiltration, SSRF, and hardcoded fake secrets.205 npmMIT