appsecco/pentesting-mcp-servers-checklist

A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.

34
/ 100
Emerging
No Package No Dependents
Maintenance 6 / 25
Adoption 7 / 25
Maturity 9 / 25
Community 12 / 25

How are scores calculated?

Stars

27

Forks

4

Language

License

CC-BY-4.0

Last pushed

Dec 18, 2025

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/mcp/appsecco/pentesting-mcp-servers-checklist"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.