# bad-mcp

> bad-mcp — canack-bad-mcp. Use this tool when you need to test the security of AI clients against malicious protocol exploits. The bad-mcp tool provides 10 intentionally malicious MCP servers that simulate attacks, allowing for defense testing and security research. It takes protocol interactions as input and outputs vulnerability assessments, helping to identify and mitigate potential threats.

Canonical page: https://skillsregistry.net/skills/canack-bad-mcp  
JSON: https://api.skillsregistry.net/v1/skills/canack-bad-mcp

## Description

10 intentionally malicious MCP servers that exploit protocol features to attack AI clients. For security research and defense testing.

## Trust

- **Trust score (0–1):** 0.76
- **Verification tier:** scanned
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **License:** MIT
- **Updated:** 2026-09-28

## Source

- **Source listing:** [GitHub](https://github.com/canack/bad-mcp)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "canack-bad-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/canack-bad-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/canack-bad-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
