Gauntlet

by studiomeyer-io

197 downloads Not rated yet MIT

About

Reliability + security testing for Model Context Protocol servers — mcp-fuzz (schema-aware fuzzer, SARIF) and mcp-storm (load tester, p50/p95/p99, CI gating) on one fast async MCP client core.

Details

License
MIT

Explore

- type confusion (string where a number is required, …)
- boundary (empty / 100k-char strings, i64::MAX, negatives, zero, huge floats)
- missing required fields, wrong-typed arguments, deep nesting
- run: mcp-fuzz run --stdio --sarif mcp.sarif --fail-on high -- node server.js
- uses: github/codeql-action/upload-sarif@v3

The README includes setup instructions such as mcp-fuzz run --stdio -- node my-server.js.

mcp-fuzz run --stdio --tool search --iterations 300 --fail-on high -- ./server


It connects, calls tools/list, and for every tool generates payloads driven by the schema:

- type confusion (string where a number is required, …)
- boundary (empty / 100k-char strings, i64::MAX, negatives, zero, huge floats)
- injection (path traversal, SQLi, command/template/format-string, prompt injection, CRLF, NUL bytes, RTL/zero-width Unicode) — sent purely as data, never executed
- missing required fields, wrong-typed arguments, deep nesting

Outcomes are classified: a dropped connection ⇒ crash (HIGH), a timeout ⇒ hang (HIGH), -32603 ⇒ internal-error (MEDIUM), success on schema-invalid input ⇒ accepted-invalid (LOW). A clean -32602 invalid params is treated as the server correctly validating — not a finding.

Runs are reproducible (--seed). After a crash the fuzzer respawns the server and continues; if the server can't be brought back, it records that once and stops cleanly, rather than blaming every later payload for the original crash.

text
mcp-fuzz report
───────────────
server my-server (protocol 2025-11-25)
tools 7
payloads sent 412
findings 2 total — 1 high, 0 medium, 1 low, 0 info

Findings (worst first):
[HIGH ] crash search::server crashed on field 'query': null-byte
stderr tail:
thread 'main' panicked at 'invalid utf-8 ...'
[LOW ] accepted-invalid search::schema-invalid input accepted without error: missing required field 'query'
``

A small family of focused, production-grade tools for building and operating MCP servers — mix and match:

- mcp-armor — runtime defense sidecar: scans tool calls, verifies signed manifests, blocks known-bad CVEs
- mcp-gauntlet (this one) — pre-deploy
mcp-fuzz (schema-aware fuzzer) + mcp-storm (load tester)
- mcp-covenant — contract & breaking-change detector (semver for your MCP interface)
- mcp-herald — static migration linter for the MCP 2026-07-28 spec
- mcp-passport — publish-readiness validator for the MCP Registry
- mcp-otel — W3C Trace Context → OpenTelemetry bridge
- mcp-cache-kit — leak-safe SEP-2549 caching (
ttlMs + cacheScope`)
- skilldoctor — linter + security scanner for agent skill files

mcp-gauntlet

mcp-fuzz
mcp-storm
CI
OpenSSF Scorecard
License: MIT

A reliability + security toolkit for Model Context Protocol servers.
Two single-binary CLIs that share one fast async MCP client core:

| Tool | What it does |
|------|--------------|
| 🔬 mcp-fuzz | Schema-aware fuzzer. Reads each tool's inputSchema and throws a battery of hostile/boundary/malformed payloads at it — finds crashes, hangs, internal errors and silent validation gaps. Emits SARIF for GitHub code scanning. |
| 🌩️ mcp-storm | Load tester ("k6 for MCP"). Drives N concurrent workers against your server, reports p50/p95/p99 latency + throughput per tool, and gates CI on latency/error-rate thresholds. |

Both are written in Rust: one static binary each, no runtime, drop into any CI. They talk MCP over stdio (subprocess) or Streamable HTTP.

> Built by StudioMeyer. Companion to mcp-armor (runtime defense) — mcp-gauntlet is the pre-deploy attacker + load generator.

---

Why

MCP servers fail silently and ship fast. Most have no tests against malformed input and no latency budget. mcp-gauntlet gives you both in two commands you can wire into CI today — without writing a single test by hand, because the payloads are derived from the server's own schema.

---

Install

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.