vulnerable-mcp-servers-lab
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally consistent as a deliberately vulnerable security lab from the stated publisher, with standard GitHub/npm installation and no hidden exfiltration endpoint. However, it meaningfully enables offensive security testing, prompt-injection practice, code execution, and exposure of sensitive-pattern data, so it carries high operational risk despite not showing confirmed malicious intent.
Confidence: 94%Severity: 71%
Audit Metadata