IMCP - Insecure Model Context Protocol
Related Servers
Alternatives to IMCP - Insecure Model Context Protocol
No user-submitted related servers found.
Related Servers
- AlicenseAqualityCmaintenanceAn intentionally vulnerable MCP server for security training, enabling users to practice attacking and defending AI agents through realistic scenarios.2868MIT
- FlicenseNot gradedqualityFmaintenanceAn educational project that deliberately implements vulnerable MCP servers to demonstrate various security risks like prompt injection, tool poisoning, and code execution for training security researchers and AI safety professionals.1,345-
- FlicenseNot gradedqualityDmaintenanceA vulnerable MCP server designed for educational CTF challenges. It demonstrates various MCP security vulnerabilities in a controlled environment.8-
- AlicenseBqualityCmaintenanceAn intentionally vulnerable MCP server for security training, simulating a fictional company with 28 vulnerable tools and 38 challenges to learn AI agent attack and defense.28MIT
- FlicenseNot gradedqualityDmaintenanceAn educational MCP server demonstrating common security vulnerabilities like command injection, path traversal, SQL injection, and XXE attacks. Designed for security training purposes only, not for production use.-
- FlicenseNot gradedqualityDmaintenanceDamn Vulnerable MCP Server for Security Researchers.7-
TDQS
Scored across 15 tools
Several tools have overlapping or ambiguous purposes that could confuse an agent. For example, 'enterprise-document-manager' and 'search-documents' both handle documents, 'enterprise-security-vault' and 'security-compliance-scanner' both relate to security, and 'ai-executive-assistant' and 'productivity-assistant' both assist with tasks. The descriptions don't clearly differentiate these tools, leading to potential misselection.
The naming is inconsistent with mixed conventions: some use snake_case (e.g., 'session-info'), others use hyphenated phrases (e.g., 'customer-data-processor'), and some are single words (e.g., 'code-analyzer'). There's no predictable verb_noun pattern, and the styles vary chaotically across the set, making it hard for an agent to infer functionality from names alone.
With 15 tools, the count is reasonable for an enterprise-focused server covering domains like security, customer data, and productivity. It's slightly on the higher side but not excessive, as each tool appears to target a specific business function, though some overlap reduces efficiency. The scope justifies the number, but it could be streamlined.
The server covers multiple domains (e.g., security, HR, marketing) but has notable gaps within each. For instance, in security, there are scanning and vault tools but no clear update or delete operations for vulnerabilities. In customer data, processing and portal tools exist but lack full CRUD lifecycle coverage. Agents might encounter dead ends when trying to perform comprehensive workflows.