Mcp Goat — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Goat (Agent Skill) and scored it 70/100 (yellow). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 2 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 5 flagged
The text {match} is the classic direct prompt-injection phrasing. Placed in a skill body that the agent reads as trusted instructions, it tries to make the agent abandon its prior rules and follow whatever comes next — a full system-prompt override.
ignore/disregard/forget … previous instructions sentence.A bulleted imperative like {match} tells the agent to never reveal, disclose, or mention something to the user. Used adversarially it can instruct the agent to hide its tool calls or lie about what it did — stripping the transparency a user relies on to trust the agent.
The text {match} asks the agent to disclose its hidden system prompt or initial instructions. That is often the first step of a larger attack: knowing the system prompt lets an attacker craft inputs that defeat its constraints by mimicking its own voice.
repeat/reveal/print your system prompt request from the skill.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A deliberately vulnerable MCP (Model Context Protocol) application for learning MCP security through hands-on exercises. Inspired by AndroGoat, OWASP WebGoat, and other vulnerable applications. MCP Goat covers all 10 categories of the OWASP MCP Top 10.
WARNING: This application contains intentionally vulnerable servers. Do NOT expose to untrusted networks. For educational use only.
# Clone the repo
git clone https://github.com/satishpatnayak/MCP-Goat.git
cd MCP-Goat
# Create virtual environment and install
uv venv && source .venv/bin/activate && uv pip install -e .
# OR without uv:
python3 -m venv .venv && source .venv/bin/activate && pip install -e .
# List all challenges
mcp-goat list
# Start a vulnerable server
mcp-goat run mcp01-c01
# View guided exercise instructions
mcp-goat exercise mcp01-c01
# Get LLM client config snippet
mcp-goat config mcp01-c01mcp-goat list)mcp-goat exercise <id>) to understand the vulnerabilitymcp-goat run <id>)Add to claude_desktop_config.json:
{
"mcpServers": {
"mcp-goat": {
"command": "/full/path/to/mcp-goat/.venv/bin/mcp-goat",
"args": ["run", "mcp01-c01"]
}
}
}Go to Settings → Cursor Settings → MCP → Add new MCP Server, or edit ~/.cursor/mcp.json:
{
"mcpServers": {
"mcp-goat": {
"command": "/full/path/to/mcp-goat/.venv/bin/mcp-goat",
"args": ["run", "mcp01-c01"]
}
}
}Important: Use the full path tomcp-goatinside the.venv/bin/directory. LLM clients don't activate virtual environments, so the baremcp-goatcommand won't work.
>
To get your full path, run: echo "$(pwd)/.venv/bin/mcp-goat"npx @modelcontextprotocol/inspector mcp-goat run mcp01-c01| Category | ID | Title | Difficulty |
|---|---|---|---|
| MCP01 — Token Mismanagement & Secret Exposure | mcp01-c01 | Leaked API Key | Beginner |
| MCP01 — Token Mismanagement & Secret Exposure | mcp01-c02 | Plaintext OAuth Token | Intermediate |
| MCP02 — Privilege Escalation | mcp02-c01 | Path Traversal | Beginner |
| MCP02 — Privilege Escalation | mcp02-c02 | Write Escalation | Intermediate |
| MCP03 — Tool Poisoning | mcp03-c01 | Tool Shadowing | Advanced |
| MCP03 — Tool Poisoning | mcp03-c02 | Hidden Prompt Injection in Description | Intermediate |
| MCP04 — Supply Chain Attacks | mcp04-c01 | Malicious Dependency | Advanced |
| MCP04 — Supply Chain Attacks | mcp04-c02 | Backdoored Plugin | Advanced |
| MCP05 — Command Injection | mcp05-c01 | DNS Lookup Injection | Intermediate |
| MCP05 — Command Injection | mcp05-c02 | SQL Injection | Intermediate |
| MCP06 — Intent Flow Subversion | mcp06-c01 | System Prompt Override | Advanced |
| MCP06 — Intent Flow Subversion | mcp06-c02 | Fake Tool Result Injection | Advanced |
| MCP07 — Insufficient Auth & Authorization | mcp07-c01 | No Authentication | Beginner |
| MCP07 — Insufficient Auth & Authorization | mcp07-c02 | Broken Access Control / IDOR | Intermediate |
| MCP08 — Lack of Audit & Telemetry | mcp08-c01 | Silent Data Exfiltration | Intermediate |
| MCP09 — Shadow Servers | mcp09-c01 | Rogue MCP Server | Advanced |
| MCP10 — Context Injection & Over-Sharing | mcp10-c01 | Cross-Agent Context Leak | Intermediate |
| MCP10 — Context Injection & Over-Sharing | mcp10-c02 | PII Over-Sharing | Beginner |
src/mcp_goat/challenges/<category>/<challenge>/__init__.pychallenge.py — subclass Challenge with metadataserver.py — the vulnerable FastMCP serverexercise.md — guided exercise instructionsmcp-goat list — auto-discovery picks it up immediatelymcp, click, rich, pyyamlMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.