{"repo":"Agent-Hellboy/mcp-server-fuzzer","free":true,"listed":false,"github":"https://github.com/Agent-Hellboy/mcp-server-fuzzer","clone":"git clone https://github.com/Agent-Hellboy/mcp-server-fuzzer.git","description":"A generic mcp server fuzzer","language":"Python","stars":46,"topics":["mcp","mcp-client","mcp-tools","mcp-fuzzer","testing-tool","mcp-specification-validation","mcp-security","mcp-servers","agentic-ai","agentic-workflow"],"license":"MIT","category":"mcp-servers","readme_excerpt":"MCP Server Fuzzer Black-box security assessment for live Model Context Protocol servers. It drives an authorized target over its real transport, sends realistic and malformed input, classifies the responses, and writes findings and reproduction data to disk. Documentation Assessment workflow CLI reference Releases Authorization Use this tool only against MCP servers you own or are explicitly authorized to test. It sends attack-pattern input, can start local processes, and with --auth-audit-intrusive will register OAuth clients on the target's authorization server. The built-in safety controls reduce accidental impact; they are not a substitute for a container, a VM, or an engagement-specific network boundary. --security-audit-intrusive sends a foreign-Origin probe to test DNS-rebinding defenses and requires the same explicit authorization. What it does The fuzzer connects over stdio, HTTP, SSE, or Streamable HTTP and answers a fixed set of assessment questions: - What tools, resources, prompts, and protocol methods does the server expose? - Does it reject malformed and out-of-contract input, or accept it? - Do tool descriptions or schemas carry poisoning markers, hidden instructions, duplicate definitions, typosquatted names, or dangerous capability combinations? - Does an advertised OAuth boundary publish unsafe metadata or serve tools without the expected authentication? - What does a local stdio server execute, read, write, or connect to while the test runs? Install Requir","default_branch":null,"files":null,"tree":[],"storefront":"/r/Agent-Hellboy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Agent-Hellboy/mcp-server-fuzzer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}