# evil-mcp-server

> Use this tool when you need to simulate cyber attacks and test system vulnerabilities, as it generates malicious behaviors and attack vectors for security testing and educational demonstrations, accepting various input scenarios and producing actionable output for analysis. It solves problems related to security assessment and penetration testing, helping identify weaknesses in systems and networks. Ideal for use in controlled environments, such as training sessions or security audits.

Canonical page: https://skillsregistry.net/skills/promptfoo-evil-mcp-server  
JSON: https://api.skillsregistry.net/v1/skills/promptfoo-evil-mcp-server

## Description

Simulates malicious behaviors and attack vectors for security testing and educational demonstrations.

## Trust

- **Trust score (0–1):** 0.68
- **Verification tier:** scanned
- **Last scanned:** 2026-09-01

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-09-01

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/kcetmzqjsh)
- **Repository:** <https://github.com/promptfoo/evil-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "promptfoo-evil-mcp-server"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/promptfoo-evil-mcp-server` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/promptfoo-evil-mcp-server/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
