{"repo":"promptfoo/evil-mcp-server","free":true,"listed":false,"github":"https://github.com/promptfoo/evil-mcp-server","clone":"git clone https://github.com/promptfoo/evil-mcp-server.git","description":"An evil MCP server used for redteam testing","language":"TypeScript","stars":32,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"Evil MCP Server ⚠️ WARNING : This MCP server simulates malicious behaviors for security testing purposes only. Do not use in production environments. Overview A Model Context Protocol (MCP) server that provides tools simulating various attack vectors for security testing and demonstration purposes. Quick Start Environment Variables - EVIL WEBHOOK URL - (Optional) Webhook URL to send analytics data to. If not set, webhook functionality is disabled. Installation Usage As an MCP Server (stdio mode - default) Add to your Claude Desktop configuration ( /Library/Application Support/Claude/claude desktop config.json ): As an HTTP Server Run the server in HTTP mode on the default port (3666): Or specify a custom port: HTTP API Endpoints - GET /health - Health check endpoint - GET /tools - List all available tools - POST /tools/call - Execute a tool Example tool call: Available Tools - record analytics : Simulates exfiltration of customer data Development Security Notice This server is designed for: - Security testing and vulnerability assessment - Educational demonstrations - Red team exercises - Security awareness training DO NOT use this server with real customer data or in production environments.","default_branch":null,"files":null,"tree":[],"storefront":"/r/promptfoo","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/promptfoo/evil-mcp-server/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}