evil-mcp-server
Provides a Model Context Protocol (MCP) server (stdio or HTTP mode) with tools intended for security red-team testing. The README describes a tool, record_analytics, that simulates exfiltration/analytics behavior for security demonstrations.
Score Breakdown
⚙ Agent Friendliness
🔒 Security
Security risk profile is intentionally focused on malicious simulation. README warns against production use and real customer data. No auth is documented, increasing risk if reachable by untrusted parties. TLS/transport security is not described. An optional webhook URL environment variable exists, but the handling/validation/logging behavior is not documented.
⚡ Reliability
Best When
Used in isolated test environments with synthetic data and explicit authorization.
Avoid When
Avoid exposing it to untrusted networks/users or using real sensitive data; avoid production use entirely.
Use Cases
- • Red-team exercise tooling for demonstrating data exfiltration patterns
- • Security awareness/training simulations
- • Testing agent/tooling behavior in a controlled environment
Not For
- • Production environments
- • Handling real customer data
- • Any scenario where simulated exfiltration could be misused outside an approved test environment
Interface
Authentication
No authentication mechanism is described for either stdio MCP mode or the HTTP endpoints (/health, /tools, /tools/call).
Pricing
As an npm package, pricing is not specified; it appears to be self-hosted.
Agent Metadata
Known Gotchas
- ⚠ No authentication described for HTTP endpoints; agents may call tools without access controls if exposed.
- ⚠ Only a small set of endpoints/tools are documented; tool argument schemas and error behaviors are not fully specified in the README.
- ⚠ HTTP tool execution uses a generic /tools/call pattern; agents must supply correct tool name and argument structure.
Alternatives
Full Evaluation Report
Comprehensive deep-dive: security analysis, reliability audit, agent experience review, cost modeling, competitive positioning, and improvement roadmap for evil-mcp-server.
AI-powered analysis · PDF + markdown · Delivered within 30 minutes
Package Brief
Quick verdict, integration guide, cost projections, gotchas with workarounds, and alternatives comparison.
Delivered within 10 minutes
Score Monitoring
Get alerted when this package's AF, security, or reliability scores change significantly. Stay ahead of regressions.
Continuous monitoring
Scores are editorial opinions as of 2026-03-30.