{"repo":"Teycir/Mcpwn","free":true,"listed":false,"github":"https://github.com/Teycir/Mcpwn","clone":"git clone https://github.com/Teycir/Mcpwn.git","description":"Automated security scanner for Model Context Protocol servers that detects RCE, path traversal, prompt injection, and protocol vulnerabilities.","language":"Python","stars":31,"topics":["mcp","mcp-server","security","cybersecurity"],"license":"MIT","category":"mcp-servers","readme_excerpt":"Support Development If this project helps your work, support ongoing maintenance and new features. ETH Donation Wallet 0x11282eE5726B3370c8B480e321b3B2aA13686582 Scan the QR code or copy the wallet address above. Mcpwn - MCP Security Testing Framework Automated security scanner for Model Context Protocol servers that detects RCE, path traversal, prompt injection, and protocol vulnerabilities. Why Mcpwn? MCP servers expose powerful capabilities to AI agents. One vulnerable tool = full system compromise. What Mcpwn Does: - ✅ Detects RCE via command injection in tool arguments - ✅ Finds path traversal vulnerabilities in file operations - ✅ Identifies prompt injection risks in LLM-facing tools - ✅ Tests protocol fuzzing and state desync attacks - ✅ Generates structured reports (JSON/SARIF) for AI analysis & CI/CD - ✅ Stages findings for AI - automated baseline → AI deep analysis - ✅ Zero dependencies - pure Python stdlib Quick Start: Real Impact: Mcpwn found RCE vulnerabilities in production MCP servers by testing tool argument injection patterns that manual code review missed. Installation Prerequisites - Python 3.8+ - Core framework uses stdlib only (no dependencies) Features - Semantic Detection : Pattern-based exploit detection (RCE, file read, timing attacks) - Side-Channel Detection : Timing, size, and behavioral anomaly detection - Paranoid Profile : Production security profile with enhanced thresholds - Thread-Safe : Concurrent operations with proper locking - Configurabl","default_branch":null,"files":null,"tree":[],"storefront":"/r/Teycir","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Teycir/Mcpwn/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}