MCP Goat

by satishpatnayak · security · mcp-server, glama

A deliberately vulnerable MCP application for learning MCP security through hands-on exercises covering OWASP MCP Top 10 categories.

Source: https://github.com/satishpatnayak/MCP-Goat

Install

git clone https://github.com/satishpatnayak/MCP-Goat

Tags: mcp-server, glama

Source: glama

About security MCP servers and Claude skills

Security MCP servers let agents scan dependencies, audit logs, check for vulnerabilities, and enforce policy guardrails. Critical for any agent that touches production.

MCP Goat is one of hundreds of security entries indexed on Skiln. Browse the full security category or the complete directory of Claude skills, MCP servers, agents, commands, and hooks.

Related security MCPs and skills

  • cyberpanel-mcp by elwizard33

    MCP server for CyberPanel that enables AI-driven management of web hosting servers, including websites, databases, email, and more via 200+ tools.

  • @itunified.io/mcp-oracle-ol by itunified-io

    MCP server for Oracle Linux OS operations, providing tools for package management, kernel, storage, network, and security tasks via dbxcli.

  • GPT Commander by PushPullCommitPush

    A security-first MCP server that provides LLMs with structured tools for filesystem, process, search, build/test/lint, IDE integration, and more.

  • mcp-bitsight by TheSkeenAdvantage

    Exposes BitSight Security Ratings as tools for AI assistants, enabling queries on company security scores, company search, details, vulnerabilities, portfolio, risk vectors, and alerts.

  • chaining-mcp-server by 1999AZZAR

    A unified MCP server for enterprise tool chaining, route optimization, sequential thinking, time management, monitoring, analytics, security, and compliance.

  • Safe Gmail MCP by mbaselga

    A security-hardened Gmail MCP server for Claude Code that supports reading, labeling, archiving, and drafting emails, but cannot send or delete.

  • deep-code-security by backspace-shmackspace

    Multi-language SAST and AI-powered fuzzing MCP server for Claude Code integration, enabling static and dynamic security analysis of code.

  • Security Paper Search MCP Server by songyaeji

    Enables searching and retrieving security conference papers from major venues (S&P, USENIX, CCS, NDSS, etc.) using natural language queries through the MCP protocol.

Frequently asked questions

How do I install MCP Goat?

Add the install command above to your Claude Code, Cursor, or Windsurf MCP configuration. Most servers register via npx, a local command, or a Docker image. Refer to the source repository for environment variables and credential requirements.

Which clients support MCP Goat?

Any MCP-compatible client works: Claude Desktop, Claude Code CLI, Cursor, Windsurf, Zed, and VS Code with the official MCP extension. OpenAI Codex and GitHub Copilot increasingly support MCP via adapter bridges.

Is MCP Goat free?

The server itself is typically open source. Any upstream service (API keys, paid tiers, hosted infrastructure) may have its own pricing. Check the source repository for details.