{"repo":"slowmist/MasterMCP","free":true,"listed":false,"github":"https://github.com/slowmist/MasterMCP","clone":"git clone https://github.com/slowmist/MasterMCP.git","description":"A demonstration toolkit revealing potential security vulnerabilities in MCP (Model Context Protocol) frameworks through data poisoning, JSON injection, function overriding, and cross-MCP call attacks, exposing AI security issues while providing defense recommendations. For educational and research purposes only.","language":"Python","stars":99,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"MasterMCP Project Introduction MasterMCP is a demonstration tool designed to showcase various potential security attack vectors against MCP (Model Context Protocol). This project illustrates how malicious plugins can exploit weaknesses in the MCP architecture through practical examples, helping developers and security researchers understand these risks and strengthen system protection. Features - Plugin-based Malicious Payloads : Demonstrates how malicious plugins can run within the MCP architecture - Multiple Attack Techniques : Includes examples of data poisoning, cross-MCP calls, competitive malicious functions, and more - Practical Educational Value : Each attack vector comes with detailed explanations and implementation code Included Attack Vectors 1. Data Poisoning : The banana plugin demonstrates how to force users to perform specific operations 2. JSON Injection Attacks : The url json plugin shows how to retrieve data from a local malicious service 3. Competitive Malicious Functions : The remove server plugin overrides existing functionality 4. Cross-MCP Call Attacks : The Master cross call plugin guides users to perform dangerous operations Installation Instructions Usage Project Structure Security Warning ⚠️ This project is for educational and research purposes only . Do not use these techniques on any system without authorization. Malicious use of this code may violate laws and regulations. Defense Recommendations - Implement strict plugin verification mechanisms -","default_branch":null,"files":null,"tree":[],"storefront":"/r/slowmist","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/slowmist/MasterMCP/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}