{"owner":"appsecco","github":"https://github.com/appsecco","claimed":false,"inventory":[],"indexed":[{"repo":"appsecco/vulnerable-mcp-servers-lab","github":"https://github.com/appsecco/vulnerable-mcp-servers-lab","description":"A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.","language":"JavaScript","stars":276,"topics":["ai-red-teaming","ai-research","hacking","mcp","mcp-client","mcp-server","pentesting","vulnerable-labs","appsecco","bugbounty"],"license":"MIT","category":"mcp-servers"},{"repo":"appsecco/pentesting-mcp-servers-checklist","github":"https://github.com/appsecco/pentesting-mcp-servers-checklist","description":"A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.","language":null,"stars":40,"topics":["agentic-ai","ai-security","llm-security","mcp","mcp-security","mcp-server","penetration-testing","pentesting","security-checklist","appsecco"],"license":"CC-BY-4.0","category":"mcp-servers"}],"how_to_buy":"GET /r/appsecco/<repo> (Accept: application/json) for any listed repo here: tree, README, price and the checkout to pay (x402; rehearse first at its test twin, simulated money). Repos under 'indexed' are free: clone them from GitHub."}