0
/ 100
3 days ago
glama

Damn Vulnerable MCP Server (DVMCP)

An intentionally vulnerable MCP server for security training, enabling users to practice attacking and defending AI agents through realistic scenarios.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Hardcoded credentials detected
1 live-looking API key in source: 1 Slack token
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/kyze-labs-damn-vulnerable-mcp-server-ilu0wo)](https://m8ven.ai/mcp/kyze-labs-damn-vulnerable-mcp-server-ilu0wo)
commit: b4fe0b8361f80a97815f20a3c1e37ee534655cd8
code hash: f4461b766c7ac7d22f9fff57d98bd381370fb4e24acb1dae37f326718e8ed9cc
verified: 5/31/2026, 9:25:26 AM
view raw JSON →