Adversarial test of your own MCP server
adversarial_testTests an MCP server you own by calling non-destructive tools with command-injection and path-traversal payloads to reveal unchecked shell or filesystem access. Skips destructive tools unless enabled.
Instructions
CALLS every non-destructive tool of one configured server with command-injection payloads (each would only create an empty canary file) and path-traversal payloads, then reports which parameters reach a shell or the file system unchecked. Only for servers the user develops or operates, ideally a test instance in a container. Destructive tools are skipped unless include_destructive is true.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| server | Yes | Server name, optionally "scope:name". | |
| canary_dir | No | Writable directory as seen by the server (default: the OS temp directory). For a container, mount a host directory and pass host_canary_dir too. | |
| project_dir | No | ||
| confirm_launch | Yes | Must be true: the user agreed that the server is started and its tools are called. | |
| host_canary_dir | No | ||
| i_own_this_server | Yes | Must be true: the user confirmed they own or operate this server. | |
| include_destructive | No |