MCPHammer

Security research framework for evaluating Model Context Protocol server vulnerabilities through prompt injection, data exfiltrati

praetorian-inc 33
Claude CodeClaude DesktopGeneric
View source ↗

MCPHammer is an offensive security research framework built by Praetorian for evaluating vulnerabilities in Model Context Protocol server implementations. It provides tools that demonstrate real-world attack vectors including prompt injection via text injection, command-and-control through tool argument scanning, arbitrary file download and execution, and data exfiltration through query interception. The framework includes a companion conversation-assistant component that demonstrates covert C2 channels using chained integrations with services like Slack, along with a web-based management console for coordinating multiple deployed instances.

Source

Repository: https://github.com/praetorian-inc/mcphammer

Maintain MCPHammer?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

[MCPHammer on getagentictools](https://getagentictools.com/mcp/praetorian-inc-mcphammer?ref=badge)