AI Developer Tools

mcploitable

A collection of deliberately vulnerable MCP servers for training in agentic security, mapped to the OWASP Top 10 for Agentic Applications.

mcploitable logo

mcploitable

Visit website

What is mcploitable?

mcploitable is an open-source project that provides deliberately vulnerable Model Context Protocol (MCP) servers for security training. Each server simulates a real-world vulnerability from the OWASP Top 10 for Agentic Applications, allowing users to practice identifying and exploiting agentic security flaws in a safe, containerized environment.

mcploitable vs Similar AI Tools

Pricing ModelFreeFreeFreeFree
Free Credits
Key Features
  • Seven breakable boxes covering OWASP Agentic Top-10 vulnerabilities
  • Three guided simulations for cascading failures, human-agent trust, and rogue agents
  • Network-isolated Docker containers for safe execution
  • Code-to-runtime reasoning across cloud, Git, and Kubernetes
  • Action-gate enforces read-only policy on every API call
  • Sandboxed JavaScript execution for concurrent research
  • Append-only, SHA-256-addressed event history through Jaybase
  • AES-256-GCM encryption for stored node payloads
  • Unified RBAC for ledger, notes, snapshots, and audit reads
  • Live status polling (working, waiting, finished, errored, idle, dead)
  • Hierarchical group session tree with folding and reordering
  • Quick prompt injection into any session or group
Pros
  • Covers full OWASP Agentic Top-10 in a realistic manner
  • Docker isolation prevents accidental damage
  • Read-only by construction prevents accidental writes
  • Evidence-backed verification cross-checks every finding
  • Opinionated and secure accounting CLI with immutable audit trail
  • Designed for AI agent integration with JSON output
  • Run multiple AI coding agents side by side in one terminal
  • Agents persist in tmux sessions even after closing the manager
Cons
  • Requires Docker and technical setup
  • Not for production use; only for lab environments
  • Requires an LLM API key, incurring token costs
  • Limited to read-only operations, cannot remediate
  • Pre-1.0, limited feature set
  • No native QuickBooks import (agents must normalize data)
  • Terminal-only interface; no GUI
  • Requires tmux and compatible platforms (macOS, Linux, WSL)
Best For
  • Security researchers focusing on AI agent vulnerabilities
  • Developers building MCP-based applications
  • Security engineers
  • DevOps teams
  • Small teams needing secure, auditable accounting with AI agent support
  • Developers integrating automated bookkeeping workflows
  • Developers using multiple AI coding agents simultaneously
  • Teams needing to monitor and interact with agent sessions

How to use mcploitable?

  1. 1Clone the repository and ensure Docker is installed.
  2. 2Run 'docker compose build' to build the images.
  3. 3Use 'docker compose run --rm -T <service>' to start a vulnerable server (e.g., mail, calc).
  4. 4Register the server in an MCP client (e.g., Claude Code) using the provided configuration.
  5. 5Use the interactive ./play script to explore vulnerabilities and submit exploits in a CTF-style lab.

mcploitable Key Features

  • Seven breakable boxes covering OWASP Agentic Top-10 vulnerabilities
  • Three guided simulations for cascading failures, human-agent trust, and rogue agents
  • Network-isolated Docker containers for safe execution
  • No self-awareness or hints in servers; vulnerabilities are latent
  • CTF lab layer with level ladder (L0-L3) for each scenario
  • Comprehensive documentation and test suite

mcploitable Use Cases

  • Agentic security training for development teams
  • CTF competitions and capture-the-flag events
  • Research and analysis of OWASP Top 10 for Agentic Applications
  • Hands-on learning for AI agent developers and security professionals

mcploitable Pricing & Free Credits

mcploitable currently operates on a Free model.

This tool is completely free to use

Open Source

Free

Free and open-source project under MIT license.

mcploitable Pros & Cons

Pros

  • Covers full OWASP Agentic Top-10 in a realistic manner
  • Docker isolation prevents accidental damage
  • CTF lab provides structured learning with difficulty levels
  • Well-documented with results and simulation notes

Cons

  • Requires Docker and technical setup
  • Not for production use; only for lab environments
  • Steep learning curve for beginners without security background

What is mcploitable best for?

  • Security researchers focusing on AI agent vulnerabilities
  • Developers building MCP-based applications
  • CTF organizers and participants
  • Educators teaching agentic security

mcploitable FAQ

Top free alternatives to mcploitable

Openbase logo

A voice-controlled IDE that enables developers to initiate AI coding sessions with Codex or Claude Code, approve commands, and review diffs from their phone.

Free
SureWire logo

SureWire is a specialized QA platform that stress-tests AI agents for safety, reliability, and compliance using purpose-built testing agents.

Free
Notte logo

Browser infrastructure platform for AI agents to run on the internet at speed with cloud browser sessions, agents, and serverless functions.

Free
YAFL logo

An agent-first file transfer tool that enables secure, encrypted file sharing between AI agents via MCP calls without human involvement.

Free
Manifest logo

Manifest converts any URL into a structured JSON map of what AI agents can interact with on a page—buttons, forms, inputs, and required fields.

Free
B

Personal GitHub Pages site by Basert, currently displaying default welcome content and instructions for using GitHub Pages with Jekyll.

Free
Termaxa logo

A cooperative gate for shell commands that AI agents run, providing previews, backups, policy enforcement, and audit for tools like Claude Code and Cursor.

Free
Agentcard logo

Agentcard provides agent-friendly card issuing and payment infrastructure for AI agents, enabling 5-minute setup and autonomous purchases.

Free

Best alternatives AI Tools to mcploitable

Cynative logo

Open-source AI tool for deep infrastructure research, running frontier models across code, cloud, and runtime to deliver verified answers.

Magpie logo

Magpie is an opinionated accounting CLI for humans and AI agents, providing double-entry bookkeeping with RBAC and immutable event storage on Jaybase.

agent-manager logo

Terminal UI to manage AI coding-agent sessions (Claude Code, OpenCode, Codex, Grok Build) in tmux with live status, group tree, and diff review.

Openbase logo

A voice-controlled IDE that enables developers to initiate AI coding sessions with Codex or Claude Code, approve commands, and review diffs from their phone.

Free
OpsCat logo

Zero-config, single-binary software catalog with auto-discovery, dependency visualization, compliance scorecards, and native MCP integration for AI agents.

BrowserAct Skills logo

Browser automation CLI for AI agents to bypass anti-bot walls, hand off to humans, and run parallel tasks.

lee-ai logo

An AI-powered shopper assistant that provides a live cursor to guide website visitors, point out products, and display price calculations.