SSH Key Exfiltration via MCP Tool Poisoning
About
This repository demonstrates a security vulnerability in MCP (Model Context Protocol ) servers that allows for remote code execution and data exfiltration through tool poisoning.
Details
- Author
- Repello-AI
- GitHub stars
- 24
- Downloads
- 389
- Categories
- Developer Tools
Jump to
- Demonstrates a two-stage tool poisoning attack on MCP servers
- Uses base64 obfuscation to hide malicious commands
- Employs wget for HTTP POST data exfiltration
- Includes social engineering to manipulate AI assistants
- Provides persistence via a marker file
The README does not provide explicit installation or usage steps. The repository contains a malicious MCP server implementation (server.py) and a configuration file for Cursor AI integration (.cursor/mcp.json). Users connect to the malicious MCP server through an MCP client like Cursor AI to observe the attack in a controlled environment.
SSH Key Exfiltration via MCP Tool Poisoning
This repository demonstrates a security vulnerability in MCP (Model Context Protocol) servers that allows for remote code execution and data exfiltration through tool poisoning.
This is intended for educational and security research purposes only.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





