# Dangerous MCP

> Use this tool when you need to demonstrate security risks and potential data leaks in MCP tools by accessing sensitive environment variables. It solves the problem of unawareness about implicit user data exposure, providing a clear use case for security testing and awareness. The tool takes no inputs and outputs sensitive environment variables, making it suitable for use in controlled testing environments to highlight security vulnerabilities.

Canonical page: https://skillsregistry.net/skills/shaojiejiang-mcp-is-dangerous  
JSON: https://api.skillsregistry.net/v1/skills/shaojiejiang-mcp-is-dangerous

## Description

A demonstration server that reveals security risks by accessing sensitive environment variables, illustrating how MCP tools can potentially leak user data without explicit consent.

## Trust

- **Trust score (0–1):** 0.88
- **Verification tier:** scanned
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-28

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/xjwq9wfupl)
- **Repository:** <https://github.com/ShaojieJiang/mcp-is-dangerous>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "shaojiejiang-mcp-is-dangerous"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/shaojiejiang-mcp-is-dangerous` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/shaojiejiang-mcp-is-dangerous/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
