MCPGoat

by sabyasachidhal

Not rated
GitHub

About

A deliberately vulnerable MCP server for hands-on penetration-testing practice — 26 challenges, 78 capture-the-flag flags, plus a victim-agent harness that shows a real LLM agent being exploited.

Details

Author
sabyasachidhal
Categories
Other, Security, Developer Tools, AI

Setup

Install MCPGoat in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/sabyasachidhal/MCPGoat

Follow the installation instructions in the repository README, then restart your MCP client.

How MCPGoat compares to DVMCP and other vulnerable MCP labs

All of these labs are worth your time. MCPGoat aims to be thedeepest single target: the same flaw hardens across tiers, so you can progress from a first exploit to blind, multi-step chains — then verify the fix against the Secure level.

Thecontrol panel(http://127.0.0.1:7332) — pick a difficulty level and track progress. This is config + progress only; it isnotthe thing you attack.

The actual attack surface is theMCP server itself— its tools, resources, prompts, and sampling calls. MCP servers have no human web UI; you interact as an MCPclient. Here it is inMCP Inspector(the bundled attacker client and a real AI agent are the other two ways):

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.