MCPGoat
About
A deliberately vulnerable MCP server for hands-on penetration-testing practice — 26 challenges, 78 capture-the-flag flags, plus a victim-agent harness that shows a real LLM agent being exploited.
Details
- Author
- sabyasachidhal
- Categories
- Other, Security, Developer Tools, AI
Jump to
Setup
Install MCPGoat in your MCP client (Claude Desktop, Cursor, Windsurf, and others).
Repository: https://github.com/sabyasachidhal/MCPGoat
Follow the installation instructions in the repository README, then restart your MCP client.
How MCPGoat compares to DVMCP and other vulnerable MCP labs
All of these labs are worth your time. MCPGoat aims to be thedeepest single target: the same flaw hardens across tiers, so you can progress from a first exploit to blind, multi-step chains — then verify the fix against the Secure level.
Thecontrol panel(http://127.0.0.1:7332) — pick a difficulty level and track progress. This is config + progress only; it isnotthe thing you attack.
The actual attack surface is theMCP server itself— its tools, resources, prompts, and sampling calls. MCP servers have no human web UI; you interact as an MCPclient. Here it is inMCP Inspector(the bundled attacker client and a real AI agent are the other two ways):
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





