Discover MCPs & agents
Loading MCPs and agents…
Loading MCPs and agents…
This repository demonstrates a security vulnerability in MCP (Model Context Protocol ) servers that allows for remote code execution and data exfiltration through tool poisoning.
From the repo.
This repository demonstrates a security vulnerability in MCP (Model Context Protocol) servers that allows for remote code execution and data exfiltration through tool poisoning. This is intended for educational and security research purposes only.
server.py - The malicious MCP server implementation containing the poisoned tool.cursor/mcp.json - Configuration file for Cursor AI integrationThe attack demonstrates the "Rug Pull" method:
DockerCommandAnalyzer tool's documentation with malicious codeThe key elements of the attack are:
To protect against this type of attack:
Replace {MCP_ENDPOINT_URL} with this MCP’s endpoint URL (from its repo or docs above). No API key — you connect directly.
Tool
OS
Config file: ~/.cursor/mcp.json
{
"mcpServers": {
"mcp-server": {
"url": "{MCP_ENDPOINT_URL}"
}
}
}Paste into mcpServers in the config file. Restart Cursor after saving.
If this MCP is also published on mcpchannel.ai, you can subscribe from Browse and use the gateway config there instead.