mcp-security-sandbox
@SirAppSec
About mcp-security-sandbox
MCP Security Playground - Hack with MCP Servers, MCP Clients. Try out different vulnerabilities and abuse LLMs and agents in a UI friendly experimentation lab
Config
No standard config provided
This server doesn't expose a parseable MCP config block in its README. See the repository for install instructions.
RepositoryTools
No tools detected
We auto-extract tools from the README. The maintainer can list them under a ## Tools heading to populate this section.
Overview
What is mcp-security-sandbox?
It is an experimental sandbox and lab for exploring MCP hosts, clients, and servers. It can perform attacks against MCP servers and abuse LLMs.
How to use mcp-security-sandbox?
Install dependencies using uv install, create a virtual environment with uv venv, activate it, then run the server with uv run -- src/mcp-security-sandbox/mcp/github/server.py and launch the Streamlit frontend with streamlit run src/mcp-security-sandbox/frontend/MCP_Chat.py. Ensure Ollama is installed and its URL is set in the client initializations.
Key features of mcp-security-sandbox?
- Experimental sandbox for MCP exploration and attacks
- Integrates a GitHub retrieval MCP server into a chat agent
- Supports chaining with Burp Suite MCP Server
- Provides a Streamlit-based chat interface
- Allows abuse of LLMs for attack scenarios
- Uses Ollama for local LLM integration
Use cases of mcp-security-sandbox?
- Test security of MCP servers against attacks
- Simulate malicious MCP server behavior
- Experiment with chaining multiple MCP servers
- Educate on MCP security vulnerabilities
FAQ from mcp-security-sandbox
What dependencies are required?
Ollama must be installed and its URL configured in the client initializations. The project uses uv for package and environment management.
How do I start the frontend?
Run uv install, uv venv, source .venv/bin/activate, then uv run -- src/mcp-security-sandbox/mcp/github/server.py and streamlit run src/mcp-security-sandbox/frontend/MCP_Chat.py.
Does the sandbox support dynamic loading of MCP servers?
No, dynamic loading is on the roadmap but not yet implemented; currently servers are statically defined.
What is the purpose of this project?
It is an experimental sandbox for exploring MCP hosts, clients, and servers, and for performing attacks against MCP servers and abusing LLMs.
Can I integrate Burp Suite?
Yes, the README shows using Burp Suite MCP Server to
Frequently asked questions
What dependencies are required?
Ollama must be installed and its URL configured in the client initializations. The project uses `uv` for package and environment management.
How do I start the frontend?
Run `uv install`, `uv venv`, `source .venv/bin/activate`, then `uv run -- src/mcp-security-sandbox/mcp/github/server.py` and `streamlit run src/mcp-security-sandbox/frontend/MCP_Chat.py`.
Does the sandbox support dynamic loading of MCP servers?
No, dynamic loading is on the roadmap but not yet implemented; currently servers are statically defined.
What is the purpose of this project?
It is an experimental sandbox for exploring MCP hosts, clients, and servers, and for performing attacks against MCP servers and abusing LLMs.
Can I integrate Burp Suite?
Yes, the README shows using Burp Suite MCP Server to
Basic information
More Developer Tools MCP servers
Unity MCP (Server + Plugin)
IvanMurzakAI Skills, MCP Tools, and CLI for Unity Engine. Full AI develop and test loop. Use cli for quick setup. Efficient token usage, advanced tools. Any C# method may be turned into a tool by a single line. Works with Claude Code, Gemini, Copilot, Cursor and any other absolutely for fr
Hello World MCP Server (Reference Extension)
anthropicsDesktop Extensions: One-click local MCP server installation in desktop apps
DevDocs by CyberAGI 🚀
cyberagiincCompletely free, private, UI based Tech Documentation MCP server. Designed for coders and software developers in mind. Easily integrate into Cursor, Windsurf, Cline, Roo Code, Claude Desktop App
MCP Unity Editor (Game Engine)
CoderGamesterModel Context Protocol (MCP) plugin to connect with Unity Editor — designed for Cursor, Claude Code, Codex, Windsurf and other IDEs
TalkToFigma
sonnylazuardiTalkToFigma: MCP integration between AI Agent (Cursor, Claude Code, Codex) and Figma, allowing Agentic AI to communicate with Figma for reading designs and modifying them programmatically.
Comments