Enables security testing of MCP guardrails and SAST scanners by exposing intentionally vulnerable code patterns that are inert by default and make no network calls.
Enables guardrail and trust testing by exposing realistic malicious tool patterns such as shell execution, credential dumping, and data exfiltration, all without network access.