MCPHammer
Security research framework for evaluating Model Context Protocol server vulnerabilities through prompt injection, data exfiltrati
MCPHammer is an offensive security research framework built by Praetorian for evaluating vulnerabilities in Model Context Protocol server implementations. It provides tools that demonstrate real-world attack vectors including prompt injection via text injection, command-and-control through tool argument scanning, arbitrary file download and execution, and data exfiltration through query interception. The framework includes a companion conversation-assistant component that demonstrates covert C2 channels using chained integrations with services like Slack, along with a web-based management console for coordinating multiple deployed instances.
Source
Repository: https://github.com/praetorian-inc/mcphammer
Maintain MCPHammer?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[MCPHammer on getagentictools](https://getagentictools.com/mcp/praetorian-inc-mcphammer?ref=badge)