We are open sourcing the vulnerable MCP servers we coded for the Pentesting MCP Servers workshop at BSides London.
Last Saturday, I ran a 4-hour hands-on workshop at Security BSides London teaching folks how to pentest MCP servers and AI agents.
To make it practical, I built a collection of intentionally vulnerable MCP servers covering real attack scenarios
- Injection vulnerabilities
- Auth bypass paths
- Misconfigured trust boundaries
- Hidden functionality exposure
- Prompt injection surfaces
The workshop sold out and the feedback was clear - people want reproducible labs they can break, learn from, and practice on.
So we're releasing the entire collection on our Appsecco’s GitHub later this week after some bug fixes.
This is for pentesters who want to understand MCP attack surfaces, product security engineers building with MCP, AI red teamers, and anyone who learns by breaking things in a safe environment.
Real vulnerabilities. Real exploitation. Reproducible locally.
Follow Appsecco to catch the release. We'll share setup guides, attack walkthroughs, and the updated MCP Pentesting Checklist v2.0 alongside it.
My contribution on the journey from Pentester to AI Red Teamer.
#pentesting #aisecurity #mcp #mcpsecurity