{"repo":"Kyze-Labs/damn-vulnerable-MCP-Server","free":true,"listed":false,"github":"https://github.com/Kyze-Labs/damn-vulnerable-MCP-Server","clone":"git clone https://github.com/Kyze-Labs/damn-vulnerable-MCP-Server.git","description":"Damn Vulnerable MCP Server Project","language":"Python","stars":68,"topics":[],"license":null,"category":"mcp-servers","readme_excerpt":"DVMCP — Damn Vulnerable MCP An intentionally vulnerable Model Context Protocol server for security training. Think DVWA but for MCP/AI agent security. DVMCP is a self-contained training platform for learning how to attack and defend AI agents that use the Model Context Protocol. It simulates a fictional company ( NovaTech Solutions ) with 6 departments, 28 vulnerable tools, and 38 challenges across 4 difficulty levels. WARNING: This is intentionally vulnerable software. Do NOT deploy in production. All data is fake. --- Table of Contents - Prerequisites - Quick Start - Local Installation - Docker - MCP Inspector - MCP Host Configuration - Architecture - Vulnerability Categories - Challenges - Difficulty Levels - Fake Data - Project Structure - Troubleshooting - Contributing - License - Disclaimer --- Prerequisites - Python 3.11+ - pip (included with Python) - Docker & Docker Compose (optional, for containerized setup) --- Quick Start Local Installation To use the web dashboard, MCP inspector, and exfiltration listener, install with extras: Docker Build and run all services: Service URL Description --------- ----- ------------- inspector http://localhost:5173 Web-based MCP client for testing and invoking tools dashboard http://localhost:8080 Web dashboard for browsing challenges and tracking progress exfil-listener http://localhost:9999 Captures exfiltrated data from challenges Available department services: dvmcp-hr , dvmcp-engineering , dvmcp-finance , dvmcp-it , dvmcp-suppo","default_branch":null,"files":null,"tree":[],"storefront":"/r/Kyze-Labs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Kyze-Labs/damn-vulnerable-MCP-Server/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}