Welcome to Grab MCP Threat Lab. Experiment, analyze, and understand your Model Context Protocols (MCPs) with AI-powered security tools.
Experiment. Analyze. Defend.
MCP Badge
Generate a badge for any MCP. Acts like a manifest, giving details on: files it reads/writes, endpoints it connects to, permissions it needs, and more.
Run a security scan on your MCP codebase and get a detailed report.
Rogue MCP
A tool built to demonstrate the risk of running a MCP from untrusted sources. It abusues default trust and chains vulnerabilits in MacOS keychain and a python library Keyring to exfiltrate secrets used by it's peer MCP servers running along side of it.