A local-first MCP attack kit for authorized security research and red teaming, demonstrating exfiltration, agent manipulation, and other abuse patterns via pluggable cases.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.MCP_KIT_HOSTMCP_KIT_TRANSPORTMCP_KIT_NAMEMCP_KIT_CASES_DIRMCP_KIT_EXFIL_URLMCP_KIT_CANARY— Canary-based proof every engagement uses a unique token () so impact is unambiguous on your listener or DNS/SMB logsMCP_KIT_UNC_HOSTMCP_KIT_CROSS_SERVER_MODEMCP_KIT_LOG_LEVEL[](https://m8ven.ai/mcp/rohitkulkarni02-malicious-mcp-research-kit-ufjw1t)