中文
~/home / Show HN
Show HN

Mcploitable – The "Metasploitable" of the Model Context Protocol

Mcploitable – The "Metasploitable" of the Model Context Protocol is a skill AI agent for To test whether my AI agent can be deceived by context injection attacks in a safe, controlled environment. Pricing: Free. As of 2026-08-21, KanonAgent records 2 票. First indexed by KanonAgent on 2026-08-21.
Mcploitable is an experimental security tool that simulates vulnerabilities in the Model Context Protocol to help AI developers test and teach how agents can be tricked by context injection attacks.
2 upvotes
Tracked by Kanon since Aug 21, 2026
🤖 Agent teardown · skill
Job to be doneTo test whether my AI agent can be deceived by context injection attacks in a safe, controlled environment.
Who it is forB2B SaaS companies and AI security researchers
Prerequisitesopen source · self-hostable
Integrationsmcp
PricingFree
Traction · why it is risingIt's gaining attention as a foundational tool for hands-on AI security training and vulnerability testing in agent development.
Why it matters

It provides a reproducible sandbox for testing context injection risks, filling a critical gap in AI agent security testing.

Evidence quotesverbatim, from the product’s own materials

“public GitHub repository (README fetched)”— structural
“Run them only inside the bundled, network-isolated Docker containers.”— readme
“ordinary-looking [MCP](https://modelcontextprotocol.io) servers”— readme
Signal source: Show HN
Visit official site →
📛 Official badgefor your site / README
Mcploitable – The "Metasploitable" of the Model Context Protocol badge
Building Mcploitable? Pick a style above — the embed code updates live. Deep color control via URL params: bg= / fg= / accent= (hex). It links back to this page.
Share on X
On mobile tap Share for WeChat / RED (Xiaohongshu) / X; on desktop use Copy text and paste into the app.

FAQ

What is Mcploitable?

Mcploitable is an experimental security tool that simulates vulnerabilities in the Model Context Protocol to help AI developers test and teach how agents can be tricked by context injection attacks.

What does Mcploitable do?

To test whether my AI agent can be deceived by context injection attacks in a safe, controlled environment.

Why does Mcploitable matter?

It provides a reproducible sandbox for testing context injection risks, filling a critical gap in AI agent security testing.

How much does Mcploitable cost?

Free

Is Mcploitable free?

Yes — Mcploitable has a free tier. Pricing as stated on its own page: Free

Is Mcploitable open source?

Yes — Mcploitable is open source.

Can I self-host Mcploitable?

Yes — Mcploitable can be self-hosted.

What does Mcploitable integrate with?

mcp

How popular is Mcploitable?

As tracked by KanonAgent: 2 upvotes (first indexed 2026-08-21).

What are the best Mcploitable alternatives?

Similar AI agents tracked by KanonAgent: deepseek-harness, open-design, deer-flow, Agent-Reach, ruflo, oh-my-openagent.

Mcploitable – The "Metasploitable" of the Model Context Protocol alternatives — similar AI agents

deepseek-harnessopen-designdeer-flowAgent-Reachruflooh-my-openagent

Where this fits — browse the same shelf

AI Agent Skills & PluginsAI agents that work with MCP (Model Context Protocol)Self-hosted & open-source AI agents