Report privately via GitHub Security Advisories. Please do not open a public issue for a security bug.
Expect an acknowledgement within 72 hours and an assessment within 7 days.
If a scan reveals a genuine vulnerability in a third-party MCP server, report it to that project, not here. Follow coordinated disclosure: contact the maintainer privately, allow reasonable time to fix, and publish only after a patch is available or the deadline lapses.
Do not open an issue on this repository naming an unpatched third-party vulnerability.
This tool executes attack scenarios. Use it only against infrastructure you own or have written authorisation to test.
Running it against third-party servers without permission may be unlawful in your jurisdiction regardless of intent. Scanning anything beyond the bundled fixture requires an explicit authorisation acknowledgement, which exists to make that a conscious decision rather than an accident.
| Backend | Guarantee |
|---|---|
DockerRange (default) |
Network created internal: true; no route off-host. Only the local sinkhole is reachable. Asserted by test. |
ProcessRange (fallback) |
Subprocess isolation, loopback-only sinkhole. Weaker. A determined payload could reach the host network. Do not use against untrusted servers. |
Canary tokens are synthetic, prefixed MCPEV-CANARY-, and minted per run. Real
credentials are never used, and the tool refuses to run if a canary value collides
with anything in the environment.
A scan result is a map of your agent attack surface. Output paths are gitignored by default and environment variable values are redacted at the boundary. Review any report before sharing it.
The payload corpus contains generic prompt-injection technique classes for testing defensive posture. It deliberately excludes weaponised exploits targeting named third-party products. Contributions adding vendor-specific exploits will be declined.