MCP server security assessment with evidence¶
MCP Server Fuzzer is a black-box assessment client for security researchers, auditors, and engineers validating an authorized Model Context Protocol server.
It discovers the target's exposed surface, exercises tools and protocol messages, runs focused MCP security checks, and preserves the observations needed for a second analyst to reproduce the result.
Start with the question you need to answer¶
| Assessment question | Use | Evidence to review |
|---|---|---|
| What does the server expose? | --mode tools, resources, or prompts | Discovery metadata and negotiated protocol version |
| Does input handling match the advertised schema? | --phase realistic then --phase aggressive | Requests, responses, rejection/acceptance outcome, timing |
| Are protocol boundaries robust? | --mode protocol, optionally --stateful | Per-message outcomes and spec-guard results |
| Does the advertised security boundary hold? | --security-audit and --auth-audit | Check IDs, evidence, source references, and auth metadata |
| What does a local server do on the host? | stdio plus safety controls and optional --runtime-probe | Process, network, filesystem, credential, and privilege observations |
| Can a pipeline detect an unusable target? | --fail-if-no-tools | Non-zero exit for no tools, auth failure, or unreachable target |
The fuzzer reports observations and useful reproductions. It does not certify a server, prove exploitability in every deployment, or replace manual review of authorization, business impact, and deployment context.
The assessment loop¶
flowchart LR
S[Scope and authorize] --> I[Install and isolate]
I --> D[Discover capabilities]
D --> B[Baseline with realistic inputs]
B --> X[Exercise protocol and schemas]
X --> Q[Run focused security checks]
Q --> T[Triage evidence]
T --> H[Hand off or automate] Every stage has a task-focused guide:
- Choose an assessment path
- Run a first assessment
- Follow the audit workflow
- Use focused recipes and local fixtures
- Interpret and preserve evidence
What the assessment can cover¶
- Tool arguments, result content, and schema constraints.
- Protocol requests, notifications, stateful sequences, resources, prompts, and deterministic spec checks.
- HTTP, HTTPS, SSE, Streamable HTTP, and stdio transports.
- API-key, basic, bearer-token, custom-header, and OAuth client-credentials authentication paths, plus MCP OAuth audit checks where supported.
- Tool/schema poisoning markers, hidden or encoded instructions, ANSI/control content, duplicate or drifting definitions, dangerous capability combinations, cleartext remote transport, and evidence-backed injection oracles.
- Optional host-level observations for local stdio processes through mcpfz-probe.
For the exact flags and current defaults, use the CLI reference. For protocol-version selection, see configuration.
Safety boundary¶
Only test systems you are authorized to assess. Use dedicated credentials, bounded timeouts, low initial run counts, and a disposable target. For local stdio targets, combine --enable-safety-system with --fs-root and usually --no-network. These controls reduce accidental impact but are not an OS sandbox or a replacement for a container/VM.
Security context¶
Use this tool alongside the official MCP Security Best Practices, MCP authorization specification, and OWASP MCP Top 10. The project links applicable sources in finding evidence; a mapping is context for analyst triage, not a severity decision by itself.