trackmcp
Back to directory

Deliberately vulnerable MCP server (aka MCP Goat) for security training — 26 challenges across 4 difficulty levels (incl. a secure reference), a victim-agent harness, and one-command Docker deploy. Practice penetration testing against the Model Context Protocol.

7 stars TypeScriptOthers Updated Sep 2, 2026
ai-securityappsecctfllm-securitymcpmodel-context-protocolpentestingsecurity-trainingvulnerable-appcapture-the-flagmcp-securitymcp-serverprompt-injectionvulnerable-mcp

No README could be loaded. View the project on GitHub for full documentation.

Frequently asked questions

What is MCPGoat?

MCPGoat is Deliberately vulnerable MCP server (aka MCP Goat) for security training — 26 challenges across 4 difficulty levels (incl. a secure reference), a victim-agent harness, and one-command Docker deploy. Practice penetration testing against the Model Context Protocol.

How do I install MCPGoat?

Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

Is MCPGoat open source?

Yes — it is hosted on GitHub at https://github.com/SabyasachiDhal/MCPGoat and has 7 stars.

Related MCP tools

Run your own MCP server? See who uses it and what to fix.

Measure it with TrackMCP