Loading connector details…
Loading connector details…
Choose a unique username to continue using AgentHotspot
by appsecco • Uncategorized
A community-driven checklist for pentesting Model Context Protocol (MCP) servers.
Identify local MCP server security risks such as secrets exposure and dangerous functions.
Validate remote MCP server boundaries including authorization and telemetry consistency.
Analyze MCP server traffic for unexpected tool chaining and context injection.
This repository provides a practical and structured checklist designed to help security practitioners systematically assess the risks and vulnerabilities of MCP servers. It covers local and remote server checks, traffic analysis, and common attack surfaces such as file system access, tool execution, and authorization flows. The checklist is intended to support repeatable and thorough security assessments of MCP-based tools, agents, and integrations.
Scores are informational only and provided “as is” without warranty. AgentHotspot assumes no liability for actions taken based on these ratings.